S
2015-04-22 15:22 - 2014-10-29 02:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RunLegacyCPLElevated.exe
2015-04-22 15:22 - 2014-10-29 02:39 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2015-04-22 15:22 - 2014-10-29 02:38 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoveDeviceElevated.dll
2015-04-22 15:22 - 2014-10-29 02:34 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsui.exe
2015-04-22 15:22 - 2014-10-29 02:32 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2015-04-22 15:22 - 2014-10-29 02:29 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapi.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2015-04-22 15:22 - 2014-10-29 02:28 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprmsg.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\reg.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfproc.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\icacls.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdhcinst.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltLib.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\PATHPING.EXE
2015-04-22 15:22 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nrpsrv.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2015-04-22 15:22 - 2014-10-29 02:28 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrssrv.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\whhelper.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBthProxy.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TCPSVCS.EXE
2015-04-22 15:22 - 2014-10-29 02:28 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msidle.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\backgroundTaskHost.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentprf.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\setx.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecEdit.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfdisk.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecerts.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhapi.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PING.EXE
2015-04-22 15:22 - 2014-10-29 02:27 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerClient.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\finger.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Register-CimProvider.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringIeProvider.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\pots.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityRtapiPal.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpcsvc.dll
2015-04-22 15:22 - 2014-10-29 02:25 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll
2015-04-22 15:22 - 2014-10-29 02:25 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsext.dll
2015-04-22 15:22 - 2014-10-29 02:24 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\procinst.dll
2015-04-22 15:22 - 2014-10-29 02:23 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2015-04-22 15:22 - 2014-10-29 02:23 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.ps.dll
2015-04-22 15:22 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskSchdPS.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfctrs.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipconfig.exe
2015-04-22 15:22 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragproxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHostProxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfmifsproxy.dll
2015-04-22 15:22 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2015-04-22 15:22 - 2014-10-29 02:19 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschapext.dll
2015-04-22 15:22 - 2014-10-29 02:19 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2015-04-22 15:22 - 2014-10-29 02:16 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2015-04-22 15:22 - 2014-10-29 02:14 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\nci.dll
2015-04-22 15:22 - 2014-10-29 02:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwaninst.dll
2015-04-22 15:22 - 2014-10-29 02:08 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrs.exe
2015-04-22 15:22 - 2014-10-29 02:06 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprext.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2015-04-22 15:22 - 2014-10-29 02:05 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprmsg.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unlodctr.exe
2015-04-22 15:22 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PATHPING.EXE
2015-04-22 15:22 - 2014-10-29 02:05 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TRACERT.EXE
2015-04-22 15:22 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemEventsBrokerClient.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmsgapi.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\whhelper.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2015-04-22 15:22 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrssrv.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBthProxy.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msidle.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2015-04-22 15:22 - 2014-10-29 02:04 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fltMC.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Register-CimProvider.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpcsvc.dll
2015-04-22 15:22 - 2014-10-29 02:03 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MRINFO.EXE
2015-04-22 15:22 - 2014-10-29 02:03 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityRtapiPal.dll
2015-04-22 15:22 - 2014-10-29 02:02 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TaskSchdPS.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vss_ps.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.ps.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.ps.dll
2015-04-22 15:22 - 2014-10-29 02:00 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmproxy.dll
2015-04-22 15:22 - 2014-10-29 02:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfmifsproxy.dll
2015-04-22 15:22 - 2014-10-29 01:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Startupscan.dll
2015-04-22 15:22 - 2014-10-29 01:55 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\CheckNetIsolation.exe
2015-04-22 15:22 - 2014-10-29 01:46 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Startupscan.dll
2015-04-22 15:21 - 2014-10-29 04:54 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWSnapin.dll
2015-04-22 15:21 - 2014-10-29 04:54 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWWizFwk.dll
2015-04-22 15:21 - 2014-10-29 04:07 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWSnapin.dll
2015-04-22 15:21 - 2014-10-29 04:07 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWWizFwk.dll
2015-04-22 15:21 - 2014-10-29 03:50 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUxRes.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Firewall.cpl
2015-04-22 15:21 - 2014-10-29 03:49 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2help.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rnr20.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\usp10.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ktmw32.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasacd.sys
2015-04-22 15:21 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSHTCPIP.DLL
2015-04-22 15:21 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wship6.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2015-04-22 15:21 - 2014-10-29 03:48 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Locator.exe
2015-04-22 15:21 - 2014-10-29 03:48 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmi.dll
2015-04-22 15:21 - 2014-10-29 03:47 - 00098304 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbcir.sys
2015-04-22 15:21 - 2014-10-29 03:47 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\qwavedrv.sys
2015-04-22 15:21 - 2014-10-29 03:47 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiscap.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\TsUsbGD.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\OobeFldr.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mslldp.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\shimeng.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2015-04-22 15:21 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\normaliz.dll
2015-04-22 15:21 - 2014-10-29 03:44 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSchedExe.exe
2015-04-22 15:21 - 2014-10-29 03:44 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\regini.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\hh.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdkey.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dvdplay.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\help.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\plasrv.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\colorcpl.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\cliconfg.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\TapiUnattend.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomcnfg.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcNs4.dll
2015-04-22 15:21 - 2014-10-29 03:41 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcmsetup.exe
2015-04-22 15:21 - 2014-10-29 03:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrnsave.scr
2015-04-22 15:21 - 2014-10-29 03:41 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll
2015-04-22 15:21 - 2014-10-29 03:40 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.proxystub.dll
2015-04-22 15:21 - 2014-10-29 03:40 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-22 15:21 - 2014-10-29 03:38 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pstorec.dll
2015-04-22 15:21 - 2014-10-29 03:37 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\secinit.exe
2015-04-22 15:21 - 2014-10-29 03:37 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ctfmon.exe
2015-04-22 15:21 - 2014-10-29 03:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PnPutil.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winver.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialer.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\cofire.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\write.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\write.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\systray.exe
2015-04-22 15:21 - 2014-10-29 03:33 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\runas.exe
2015-04-22 15:21 - 2014-10-29 03:33 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\InfDefaultInstall.exe
2015-04-22 15:21 - 2014-10-29 03:30 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sigverif.exe
2015-04-22 15:21 - 2014-10-29 03:30 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\RmClient.exe
2015-04-22 15:21 - 2014-10-29 03:29 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsicli.exe
2015-04-22 15:21 - 2014-10-29 03:28 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcad32.exe
2015-04-22 15:21 - 2014-10-29 03:25 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\resmon.exe
2015-04-22 15:21 - 2014-10-29 03:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationNotifications.exe
2015-04-22 15:21 - 2014-10-29 03:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
2015-04-22 15:21 - 2014-10-29 03:20 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\proquota.exe
2015-04-22 15:21 - 2014-10-29 03:20 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WallpaperHost.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceProperties.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesRemote.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesProtection.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesPerformance.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesHardware.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesDataExecutionPrevention.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesComputerName.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesAdvanced.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Netplwiz.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartScreenSettings.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OptionalFeatures.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Fondue.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RunLegacyCPLElevated.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2015-04-22 15:21 - 2014-10-29 03:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsui.exe
2015-04-22 15:21 - 2014-10-29 03:09 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthudtask.exe
2015-04-22 15:21 - 2014-10-29 03:05 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceUxRes.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2help.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rnr20.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usp10.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ktmw32.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wship6.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSHTCPIP.DLL
2015-04-22 15:21 - 2014-10-29 03:03 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmi.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OobeFldr.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shimeng.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2015-04-22 15:21 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\normaliz.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprop.dll
2015-04-22 15:21 - 2014-10-29 02:59 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\help.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\colorcpl.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdkey.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomcnfg.exe
2015-04-22 15:21 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DDOIProxy.dll
2015-04-22 15:21 - 2014-10-29 02:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrnsave.scr
2015-04-22 15:21 - 2014-10-29 02:57 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RpcNs4.dll
2015-04-22 15:21 - 2014-10-29 02:56 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pstorec.dll
2015-04-22 15:21 - 2014-10-29 02:53 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\winhlp32.exe
2015-04-22 15:21 - 2014-10-29 02:52 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msra.exe
2015-04-22 15:21 - 2014-10-29 02:52 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\write.exe
2015-04-22 15:21 - 2014-10-29 02:51 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systray.exe
2015-04-22 15:21 - 2014-10-29 02:45 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resmon.exe
2015-04-22 15:21 - 2014-10-29 02:45 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceProperties.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesRemote.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesProtection.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesHardware.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesDataExecutionPrevention.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesComputerName.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesAdvanced.exe
2015-04-22 15:21 - 2014-10-29 02:32 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthudtask.exe
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprext.dll
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dabapi.dll
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_ISCII.DLL
2015-04-22 15:21 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mountvol.exe
2015-04-22 15:21 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TcpipSetup.dll
2015-04-22 15:21 - 2014-10-29 02:27 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\lodctr.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\unlodctr.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cacls.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltMC.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TRACERT.EXE
2015-04-22 15:21 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\HOSTNAME.EXE
2015-04-22 15:21 - 2014-10-29 02:26 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCmd.exe
2015-04-22 15:21 - 2014-10-29 02:26 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRINFO.EXE
2015-04-22 15:21 - 2014-10-29 02:23 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxStreamingDataSourcePS.dll
2015-04-22 15:21 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallButtons.ProxyStub.dll
2015-04-22 15:21 - 2014-10-29 02:21 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ROUTE.EXE
2015-04-22 15:21 - 2014-10-29 02:21 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllhst3g.exe
2015-04-22 15:21 - 2014-10-29 02:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2015-04-22 15:21 - 2014-10-29 02:06 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_ISCII.DLL
2015-04-22 15:21 - 2014-10-29 02:06 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dabapi.dll
2015-04-22 15:21 - 2014-10-29 02:05 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TCPSVCS.EXE
2015-04-22 15:21 - 2014-10-29 02:05 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\backgroundTaskHost.exe
2015-04-22 15:21 - 2014-10-29 02:03 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2015-04-22 15:21 - 2014-10-29 02:01 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll
2015-04-22 15:21 - 2014-10-29 02:00 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallButtons.ProxyStub.dll
2015-04-22 15:21 - 2014-10-29 01:58 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootim.exe
2015-04-22 15:21 - 2014-10-29 01:50 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2015-04-22 15:21 - 2014-10-11 01:10 - 00389020 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-04-22 15:21 - 2014-10-07 04:30 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00107520 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00032256 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-04-21 01:11 - 2015-04-21 21:28 - 00000000 ____D () C:\Program Files (x86)\QUIckViewer
2015-04-21 01:10 - 2015-05-18 10:40 - 00000000 ____D () C:\ProgramData\10408937475793103121
2015-04-21 01:10 - 2015-04-21 01:10 - 00000020 _____ () C:\Users\lkoul_000\AppData\Roaming\appdataFr3.bin
2015-04-19 02:46 - 2015-04-19 20:53 - 00000000 ____D () C:\Users\lkoul_000\Downloads\A Song of Ice and Fire (Audio Books 1-5 - Complete)
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-19 23:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-19 22:53 - 2013-09-06 00:23 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-19 22:53 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-19 09:07 - 2013-11-28 02:42 - 00000000 ___DO () C:\Users\lkoul_000\SkyDrive
2015-05-18 23:44 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\Offline Web Pages
2015-05-18 22:09 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-18 21:54 - 2013-08-26 20:28 - 00345600 ___SH () C:\Users\lkoul_000\Desktop\Thumbs.db
2015-05-18 21:46 - 2014-08-10 14:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-18 21:46 - 2013-11-27 16:12 - 00000000 ___DC () C:\WINDOWS\Panther
2015-05-18 21:46 - 2013-09-05 18:04 - 00000000 ____D () C:\Users\lkoul_000\AppData\Roaming\uTorrent
2015-05-18 21:24 - 2013-08-16 00:40 - 00000000 ____D () C:\Users\lkoul_000\AppData\Local\Google
2015-05-18 15:31 - 2014-01-16 19:15 - 00003114 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update
2015-05-18 15:31 - 2013-08-16 00:38 - 00003056 _____ () C:\WINDOWS\System32\Tasks\ASUS P4G
2015-05-18 15:31 - 2013-08-15 11:25 - 00000401 _____ () C:\Users\lkoul_000\AppData\Roaming\sp_data.sys
2015-05-18 15:31 - 2012-12-12 18:44 - 00003260 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel
2015-05-18 15:31 - 2012-12-12 18:15 - 00003028 _____ () C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus
2015-05-18 15:31 - 2012-12-12 18:06 - 00003222 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for VIA Audio
2015-05-18 15:29 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-18 15:28 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-18 12:43 - 2014-09-14 20:05 - 00000000 ____D () C:\Users\lkoul_000\Downloads\Top 200 90's Alternative Songs
2015-05-14 23:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-05-14 10:30 - 2013-09-30 05:11 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-14 10:01 - 2013-08-22 15:44 - 02432288 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-13 15:51 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-13 15:48 - 2013-08-16 02:51 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-13 15:41 - 2013-08-16 02:51 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-13 15:36 - 2013-09-30 04:59 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-11 20:05 - 2013-09-03 22:12 - 00000000 ____D () C:\Users\lkoul_000\AppData\Roaming\PrimoPDF
2015-05-09 18:39 - 2014-12-13 18:21 - 00824008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2015-05-09 18:39 - 2014-08-19 12:31 - 00056008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kldisk.sys
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\sppui
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\oobe
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\servicing
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sppui
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\en-GB
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Com
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\IME
2015-05-09 17:27 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2015-05-09 17:27 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ___SD () C:\WINDOWS\system32\dsc
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\SystemResetPlatform
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\migwiz
2015-05-09 17:26 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2015-05-09 17:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-05-09 17:03 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-05-09 17:02 - 2012-07-26 09:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-05-09 17:02 - 2012-07-26 06:37 - 00000000 ____D () C:\Users\Default.migrated
2015-05-05 18:59 - 2014-05-21 13:14 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-05-05 18:59 - 2014-05-21 13:14 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-22 19:16 - 2013-08-22 16:36 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-04-22 19:16 - 2013-08-22 16:36 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-04-21 17:29 - 2013-08-16 00:41 - 00000000 ____D () C:\Program Files (x86)\Google
==================== Files in the root of some directories =======
2015-04-21 01:10 - 2015-04-21 01:10 - 0000020 _____ () C:\Users\lkoul_000\AppData\Roaming\appdataFr3.bin
2014-03-12 19:33 - 2014-03-12 19:33 - 0000021 _____ () C:\Users\lkoul_000\AppData\Roaming\my_intel.sys
2013-08-15 11:25 - 2015-05-18 15:31 - 0000401 _____ () C:\Users\lkoul_000\AppData\Roaming\sp_data.sys
2014-02-20 15:07 - 2014-02-20 15:07 - 0003584 _____ () C:\Users\lkoul_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-21 17:36 - 2015-05-09 16:49 - 0000806 _____ () C:\Users\lkoul_000\AppData\Local\Temp-log.txt
2012-08-17 01:52 - 2012-07-30 07:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2012-08-17 01:52 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-19 09:20
==================== End Of Log ============================
2015-04-22 15:22 - 2014-10-29 02:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RunLegacyCPLElevated.exe
2015-04-22 15:22 - 2014-10-29 02:39 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2015-04-22 15:22 - 2014-10-29 02:38 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoveDeviceElevated.dll
2015-04-22 15:22 - 2014-10-29 02:34 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsui.exe
2015-04-22 15:22 - 2014-10-29 02:32 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2015-04-22 15:22 - 2014-10-29 02:29 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapi.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2015-04-22 15:22 - 2014-10-29 02:28 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprmsg.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\reg.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfproc.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\icacls.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdhcinst.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltLib.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\PATHPING.EXE
2015-04-22 15:22 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nrpsrv.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2015-04-22 15:22 - 2014-10-29 02:28 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrssrv.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\whhelper.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBthProxy.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TCPSVCS.EXE
2015-04-22 15:22 - 2014-10-29 02:28 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\msidle.dll
2015-04-22 15:22 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\backgroundTaskHost.exe
2015-04-22 15:22 - 2014-10-29 02:28 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentprf.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\setx.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecEdit.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfdisk.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecerts.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhapi.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PING.EXE
2015-04-22 15:22 - 2014-10-29 02:27 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerClient.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\finger.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Register-CimProvider.exe
2015-04-22 15:22 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2015-04-22 15:22 - 2014-10-29 02:27 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringIeProvider.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\pots.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityRtapiPal.dll
2015-04-22 15:22 - 2014-10-29 02:26 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpcsvc.dll
2015-04-22 15:22 - 2014-10-29 02:25 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll
2015-04-22 15:22 - 2014-10-29 02:25 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsext.dll
2015-04-22 15:22 - 2014-10-29 02:24 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\procinst.dll
2015-04-22 15:22 - 2014-10-29 02:23 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2015-04-22 15:22 - 2014-10-29 02:23 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.ps.dll
2015-04-22 15:22 - 2014-10-29 02:22 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskSchdPS.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfctrs.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipconfig.exe
2015-04-22 15:22 - 2014-10-29 02:21 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragproxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHostProxy.dll
2015-04-22 15:22 - 2014-10-29 02:21 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfmifsproxy.dll
2015-04-22 15:22 - 2014-10-29 02:20 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2015-04-22 15:22 - 2014-10-29 02:19 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschapext.dll
2015-04-22 15:22 - 2014-10-29 02:19 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2015-04-22 15:22 - 2014-10-29 02:16 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2015-04-22 15:22 - 2014-10-29 02:14 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\nci.dll
2015-04-22 15:22 - 2014-10-29 02:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwaninst.dll
2015-04-22 15:22 - 2014-10-29 02:08 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winrs.exe
2015-04-22 15:22 - 2014-10-29 02:06 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprext.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2015-04-22 15:22 - 2014-10-29 02:05 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprmsg.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unlodctr.exe
2015-04-22 15:22 - 2014-10-29 02:05 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PATHPING.EXE
2015-04-22 15:22 - 2014-10-29 02:05 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TRACERT.EXE
2015-04-22 15:22 - 2014-10-29 02:05 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemEventsBrokerClient.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmsgapi.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\whhelper.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2015-04-22 15:22 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winrssrv.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBthProxy.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msidle.dll
2015-04-22 15:22 - 2014-10-29 02:05 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2015-04-22 15:22 - 2014-10-29 02:04 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fltMC.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Register-CimProvider.exe
2015-04-22 15:22 - 2014-10-29 02:04 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpcsvc.dll
2015-04-22 15:22 - 2014-10-29 02:03 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MRINFO.EXE
2015-04-22 15:22 - 2014-10-29 02:03 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityRtapiPal.dll
2015-04-22 15:22 - 2014-10-29 02:02 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TaskSchdPS.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vss_ps.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.ps.dll
2015-04-22 15:22 - 2014-10-29 02:01 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.ps.dll
2015-04-22 15:22 - 2014-10-29 02:00 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlmproxy.dll
2015-04-22 15:22 - 2014-10-29 02:00 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfmifsproxy.dll
2015-04-22 15:22 - 2014-10-29 01:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Startupscan.dll
2015-04-22 15:22 - 2014-10-29 01:55 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\CheckNetIsolation.exe
2015-04-22 15:22 - 2014-10-29 01:46 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Startupscan.dll
2015-04-22 15:21 - 2014-10-29 04:54 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWSnapin.dll
2015-04-22 15:21 - 2014-10-29 04:54 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWWizFwk.dll
2015-04-22 15:21 - 2014-10-29 04:07 - 05120000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWSnapin.dll
2015-04-22 15:21 - 2014-10-29 04:07 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWWizFwk.dll
2015-04-22 15:21 - 2014-10-29 03:50 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUxRes.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Firewall.cpl
2015-04-22 15:21 - 2014-10-29 03:49 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2help.dll
2015-04-22 15:21 - 2014-10-29 03:49 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rnr20.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\usp10.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ktmw32.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasacd.sys
2015-04-22 15:21 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSHTCPIP.DLL
2015-04-22 15:21 - 2014-10-29 03:48 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wship6.dll
2015-04-22 15:21 - 2014-10-29 03:48 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2015-04-22 15:21 - 2014-10-29 03:48 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Locator.exe
2015-04-22 15:21 - 2014-10-29 03:48 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmi.dll
2015-04-22 15:21 - 2014-10-29 03:47 - 00098304 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbcir.sys
2015-04-22 15:21 - 2014-10-29 03:47 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\qwavedrv.sys
2015-04-22 15:21 - 2014-10-29 03:47 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiscap.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2015-04-22 15:21 - 2014-10-29 03:46 - 00029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\TsUsbGD.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\OobeFldr.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mslldp.sys
2015-04-22 15:21 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciwave.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mciseq.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\shimeng.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2015-04-22 15:21 - 2014-10-29 03:45 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2015-04-22 15:21 - 2014-10-29 03:45 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\normaliz.dll
2015-04-22 15:21 - 2014-10-29 03:44 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSchedExe.exe
2015-04-22 15:21 - 2014-10-29 03:44 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\regini.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\hh.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmdkey.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dvdplay.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\help.exe
2015-04-22 15:21 - 2014-10-29 03:43 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\plasrv.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\colorcpl.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\cliconfg.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\TapiUnattend.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomcnfg.exe
2015-04-22 15:21 - 2014-10-29 03:42 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcNs4.dll
2015-04-22 15:21 - 2014-10-29 03:41 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcmsetup.exe
2015-04-22 15:21 - 2014-10-29 03:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrnsave.scr
2015-04-22 15:21 - 2014-10-29 03:41 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll
2015-04-22 15:21 - 2014-10-29 03:40 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.proxystub.dll
2015-04-22 15:21 - 2014-10-29 03:40 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-22 15:21 - 2014-10-29 03:38 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\pstorec.dll
2015-04-22 15:21 - 2014-10-29 03:37 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\secinit.exe
2015-04-22 15:21 - 2014-10-29 03:37 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ctfmon.exe
2015-04-22 15:21 - 2014-10-29 03:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PnPutil.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winver.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialer.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\cofire.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\write.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\write.exe
2015-04-22 15:21 - 2014-10-29 03:34 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\systray.exe
2015-04-22 15:21 - 2014-10-29 03:33 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\runas.exe
2015-04-22 15:21 - 2014-10-29 03:33 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\InfDefaultInstall.exe
2015-04-22 15:21 - 2014-10-29 03:30 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sigverif.exe
2015-04-22 15:21 - 2014-10-29 03:30 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\RmClient.exe
2015-04-22 15:21 - 2014-10-29 03:29 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsicli.exe
2015-04-22 15:21 - 2014-10-29 03:28 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcad32.exe
2015-04-22 15:21 - 2014-10-29 03:25 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\resmon.exe
2015-04-22 15:21 - 2014-10-29 03:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationNotifications.exe
2015-04-22 15:21 - 2014-10-29 03:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
2015-04-22 15:21 - 2014-10-29 03:20 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\proquota.exe
2015-04-22 15:21 - 2014-10-29 03:20 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WallpaperHost.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceProperties.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesRemote.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesProtection.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesPerformance.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesHardware.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesDataExecutionPrevention.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesComputerName.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemPropertiesAdvanced.exe
2015-04-22 15:21 - 2014-10-29 03:19 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Netplwiz.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartScreenSettings.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OptionalFeatures.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Fondue.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RunLegacyCPLElevated.exe
2015-04-22 15:21 - 2014-10-29 03:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2015-04-22 15:21 - 2014-10-29 03:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsui.exe
2015-04-22 15:21 - 2014-10-29 03:09 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthudtask.exe
2015-04-22 15:21 - 2014-10-29 03:05 - 02628608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceUxRes.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2help.dll
2015-04-22 15:21 - 2014-10-29 03:04 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rnr20.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usp10.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ktmw32.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wship6.dll
2015-04-22 15:21 - 2014-10-29 03:03 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSHTCPIP.DLL
2015-04-22 15:21 - 2014-10-29 03:03 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmi.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OobeFldr.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shimeng.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2015-04-22 15:21 - 2014-10-29 03:00 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\normaliz.dll
2015-04-22 15:21 - 2014-10-29 03:00 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprop.dll
2015-04-22 15:21 - 2014-10-29 02:59 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\help.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\colorcpl.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmdkey.exe
2015-04-22 15:21 - 2014-10-29 02:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomcnfg.exe
2015-04-22 15:21 - 2014-10-29 02:57 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DDOIProxy.dll
2015-04-22 15:21 - 2014-10-29 02:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrnsave.scr
2015-04-22 15:21 - 2014-10-29 02:57 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RpcNs4.dll
2015-04-22 15:21 - 2014-10-29 02:56 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pstorec.dll
2015-04-22 15:21 - 2014-10-29 02:53 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\winhlp32.exe
2015-04-22 15:21 - 2014-10-29 02:52 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msra.exe
2015-04-22 15:21 - 2014-10-29 02:52 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\write.exe
2015-04-22 15:21 - 2014-10-29 02:51 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systray.exe
2015-04-22 15:21 - 2014-10-29 02:45 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resmon.exe
2015-04-22 15:21 - 2014-10-29 02:45 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceProperties.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesRemote.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesProtection.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesHardware.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesDataExecutionPrevention.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesComputerName.exe
2015-04-22 15:21 - 2014-10-29 02:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemPropertiesAdvanced.exe
2015-04-22 15:21 - 2014-10-29 02:32 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthudtask.exe
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprext.dll
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dabapi.dll
2015-04-22 15:21 - 2014-10-29 02:29 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_ISCII.DLL
2015-04-22 15:21 - 2014-10-29 02:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mountvol.exe
2015-04-22 15:21 - 2014-10-29 02:28 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TcpipSetup.dll
2015-04-22 15:21 - 2014-10-29 02:27 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\lodctr.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\unlodctr.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cacls.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\fltMC.exe
2015-04-22 15:21 - 2014-10-29 02:27 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TRACERT.EXE
2015-04-22 15:21 - 2014-10-29 02:27 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\HOSTNAME.EXE
2015-04-22 15:21 - 2014-10-29 02:26 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCmd.exe
2015-04-22 15:21 - 2014-10-29 02:26 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRINFO.EXE
2015-04-22 15:21 - 2014-10-29 02:23 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxStreamingDataSourcePS.dll
2015-04-22 15:21 - 2014-10-29 02:21 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallButtons.ProxyStub.dll
2015-04-22 15:21 - 2014-10-29 02:21 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ROUTE.EXE
2015-04-22 15:21 - 2014-10-29 02:21 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dllhst3g.exe
2015-04-22 15:21 - 2014-10-29 02:12 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2015-04-22 15:21 - 2014-10-29 02:06 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_ISCII.DLL
2015-04-22 15:21 - 2014-10-29 02:06 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dabapi.dll
2015-04-22 15:21 - 2014-10-29 02:05 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TCPSVCS.EXE
2015-04-22 15:21 - 2014-10-29 02:05 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\backgroundTaskHost.exe
2015-04-22 15:21 - 2014-10-29 02:03 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2015-04-22 15:21 - 2014-10-29 02:01 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll
2015-04-22 15:21 - 2014-10-29 02:00 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallButtons.ProxyStub.dll
2015-04-22 15:21 - 2014-10-29 01:58 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootim.exe
2015-04-22 15:21 - 2014-10-29 01:50 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2015-04-22 15:21 - 2014-10-11 01:10 - 00389020 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-04-22 15:21 - 2014-10-07 04:30 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00107520 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00032256 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-04-22 15:21 - 2014-10-07 04:29 - 00030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-04-21 01:11 - 2015-04-21 21:28 - 00000000 ____D () C:\Program Files (x86)\QUIckViewer
2015-04-21 01:10 - 2015-05-18 10:40 - 00000000 ____D () C:\ProgramData\10408937475793103121
2015-04-21 01:10 - 2015-04-21 01:10 - 00000020 _____ () C:\Users\lkoul_000\AppData\Roaming\appdataFr3.bin
2015-04-19 02:46 - 2015-04-19 20:53 - 00000000 ____D () C:\Users\lkoul_000\Downloads\A Song of Ice and Fire (Audio Books 1-5 - Complete)
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-19 23:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-19 22:53 - 2013-09-06 00:23 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-19 22:53 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-19 09:07 - 2013-11-28 02:42 - 00000000 ___DO () C:\Users\lkoul_000\SkyDrive
2015-05-18 23:44 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\Offline Web Pages
2015-05-18 22:09 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-18 21:54 - 2013-08-26 20:28 - 00345600 ___SH () C:\Users\lkoul_000\Desktop\Thumbs.db
2015-05-18 21:46 - 2014-08-10 14:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-18 21:46 - 2013-11-27 16:12 - 00000000 ___DC () C:\WINDOWS\Panther
2015-05-18 21:46 - 2013-09-05 18:04 - 00000000 ____D () C:\Users\lkoul_000\AppData\Roaming\uTorrent
2015-05-18 21:24 - 2013-08-16 00:40 - 00000000 ____D () C:\Users\lkoul_000\AppData\Local\Google
2015-05-18 15:31 - 2014-01-16 19:15 - 00003114 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update
2015-05-18 15:31 - 2013-08-16 00:38 - 00003056 _____ () C:\WINDOWS\System32\Tasks\ASUS P4G
2015-05-18 15:31 - 2013-08-15 11:25 - 00000401 _____ () C:\Users\lkoul_000\AppData\Roaming\sp_data.sys
2015-05-18 15:31 - 2012-12-12 18:44 - 00003260 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel
2015-05-18 15:31 - 2012-12-12 18:15 - 00003028 _____ () C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus
2015-05-18 15:31 - 2012-12-12 18:06 - 00003222 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for VIA Audio
2015-05-18 15:29 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-18 15:28 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-18 12:43 - 2014-09-14 20:05 - 00000000 ____D () C:\Users\lkoul_000\Downloads\Top 200 90's Alternative Songs
2015-05-14 23:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-05-14 10:30 - 2013-09-30 05:11 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-14 10:01 - 2013-08-22 15:44 - 02432288 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-13 15:51 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-13 15:48 - 2013-08-16 02:51 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-13 15:41 - 2013-08-16 02:51 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-13 15:36 - 2013-09-30 04:59 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-11 20:05 - 2013-09-03 22:12 - 00000000 ____D () C:\Users\lkoul_000\AppData\Roaming\PrimoPDF
2015-05-09 18:39 - 2014-12-13 18:21 - 00824008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2015-05-09 18:39 - 2014-08-19 12:31 - 00056008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kldisk.sys
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2015-05-09 17:33 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-05-09 17:32 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\sppui
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Com
2015-05-09 17:31 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\oobe
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2015-05-09 17:31 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\servicing
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\WinBioPlugIns
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sppui
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\en-GB
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\Com
2015-05-09 17:27 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\IME
2015-05-09 17:27 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2015-05-09 17:27 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ___SD () C:\WINDOWS\system32\dsc
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\SystemResetPlatform
2015-05-09 17:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\migwiz
2015-05-09 17:26 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-05-09 17:20 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2015-05-09 17:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-05-09 17:03 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-05-09 17:02 - 2012-07-26 09:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-05-09 17:02 - 2012-07-26 06:37 - 00000000 ____D () C:\Users\Default.migrated
2015-05-05 18:59 - 2014-05-21 13:14 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-05-05 18:59 - 2014-05-21 13:14 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-22 19:16 - 2013-08-22 16:36 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-04-22 19:16 - 2013-08-22 16:36 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-04-21 17:29 - 2013-08-16 00:41 - 00000000 ____D () C:\Program Files (x86)\Google
==================== Files in the root of some directories =======
2015-04-21 01:10 - 2015-04-21 01:10 - 0000020 _____ () C:\Users\lkoul_000\AppData\Roaming\appdataFr3.bin
2014-03-12 19:33 - 2014-03-12 19:33 - 0000021 _____ () C:\Users\lkoul_000\AppData\Roaming\my_intel.sys
2013-08-15 11:25 - 2015-05-18 15:31 - 0000401 _____ () C:\Users\lkoul_000\AppData\Roaming\sp_data.sys
2014-02-20 15:07 - 2014-02-20 15:07 - 0003584 _____ () C:\Users\lkoul_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-21 17:36 - 2015-05-09 16:49 - 0000806 _____ () C:\Users\lkoul_000\AppData\Local\Temp-log.txt
2012-08-17 01:52 - 2012-07-30 07:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2012-08-17 01:52 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-19 09:20
==================== End Of Log ============================