Solved Possible virus infection (slowing down of browsing, programs, etc)

dubs1987

Posts: 17   +0
I've noticed a significant slowdown on running my browser, opening programs and using Explorer the last couple months.The Recovery Scan files are below, I had to break them up because of the 50,000 character limit. Thanks in advance.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-04-2020
Ran by ubers (administrator) on DESKTOP-LQBKB2Q (08-04-2020 14:16:56)
Running from C:\Users\ubers\Downloads
Loaded Profiles: ubers (Available Profiles: ubers & Administrator)
Platform: Windows 10 Home Version 1809 17763.1098 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Cambridge Silicon Radio Ltd. -> ) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe
(LAVASOFT SOFTWARE CANADA INC -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Surfshark Ltd. -> Iain Patterson) C:\Program Files (x86)\Surfshark\Resources\x64\nssm.exe
(Surfshark Ltd. -> Surfshark) C:\Program Files (x86)\Surfshark\Surfshark.Service.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3136136 2019-01-29] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [CsrHCRPServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe [1134288 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CsrAudioguiCtrl] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe [511696 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CsrSyncMLServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe [244944 2012-03-22] (Cambridge Silicon Radio Ltd. -> )
HKLM\...\Run: [vksts] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe [25792 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [HarmonyUserStartup] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe [39128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CSRHarmonySkypePlugin] => C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe [146656 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [TrayApplication] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe [529616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [31624080 2020-03-12] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365160 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [Surfshark] => C:\Program Files (x86)\Surfshark\Surfshark.exe [3765200 2020-03-18] (Surfshark Ltd. -> Surfshark)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\ANOTHE~1.SCR [55808 2005-03-01] () [File not signed]
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-07] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{5355DA8C-FE32-49b4-A567-A67535C86592}] -> C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BLEtokenCredentialProvider.dll [2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {174239E7-F727-4138-9A08-8F458BEE6514} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1F978473-5C7D-416E-B248-A08DE3FA42F1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {2583886E-7684-46B9-B9A7-C962B30CF3F2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {2646877B-F366-45C9-8C00-594080E969E0} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1116177293-2918626760-3563952597-500 => C:\Users\ubers\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {5BF3F651-05C5-40A6-9C2A-103FDA2C7EA0} - System32\Tasks\Opera scheduled assistant Autoupdate 1569362109 => C:\Users\ubers\AppData\Local\Programs\Opera\launcher.exe
Task: {709EE3FB-2B9E-4D87-85E6-2B5956D55009} - System32\Tasks\Opera scheduled Autoupdate 1569362099 => C:\Users\ubers\AppData\Local\Programs\Opera\launcher.exe
Task: {74D8ADE8-49DA-4403-ADE8-E7D177CEA4A2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {897AC3C3-F8E0-4AD8-A80D-0514390B41DA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {A6D78204-1734-48E7-946A-C6069FBE5304} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C071F7CA-A069-4268-BD6A-A25E93756E62} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-14] (Google Inc -> Google Inc.)
Task: {EFAAE3A7-7672-4360-BE4A-634C890F105C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-14] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{186038a2-c246-434c-96d4-33c417a772d9}: [NameServer] 162.252.172.57,149.154.159.92
Tcpip\..\Interfaces\{186038a2-c246-434c-96d4-33c417a772d9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{88fd77a8-c10d-457c-b970-67ac2b6057e1}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{dac507a2-e1f0-4b3a-8e57-3361b4f6b8f2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fd53961b-5375-44b1-9bf9-5786dbd3dc7f}: [DhcpNameServer] 162.252.172.57 149.154.159.92

Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2019-01-29] (Logitech Inc -> Logitech, Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2019-01-29] (Logitech Inc -> Logitech, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-01-19] (Skype Technologies SA -> Skype Technologies)

Edge:
======
DownloadDir: C:\Users\ubers\Downloads
Edge Notifications: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002 -> hxxps://forums.playbattlegrounds.com; hxxps://www.inverse.com
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.19.0_neutral__d55gg7py3s0m0 [2020-02-18]

FireFox:
========
FF DefaultProfile: rnwyvsyl.default
FF ProfilePath: C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default [2020-04-08]
FF Homepage: Mozilla\Firefox\Profiles\rnwyvsyl.default -> hxxps://www.bing.com/
FF Notifications: Mozilla\Firefox\Profiles\rnwyvsyl.default -> hxxps://www.youtube.com; hxxps://www.facebook.com; hxxps://mail.google.com; hxxps://ew.com
FF Extension: (Facebook Container) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\@contain-facebook.xpi [2020-03-10]
FF Extension: (Dark Reader) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\addon@darkreader.org.xpi [2020-03-30]
FF Extension: (convert2mp3.net Online Video Converter) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\info@convert2mp3.net.xpi [2019-04-24]
FF Extension: (AdBlock) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2020-02-05]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2019-04-29] [not signed]
FF HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\ubers\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
FF Extension: (Ace Script) - C:\Users\ubers\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2018-01-24]
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default [2020-04-07]
CHR Extension: (Slides) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-14]
CHR Extension: (Docs) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-14]
CHR Extension: (Google Drive) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-14]
CHR Extension: (YouTube) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-14]
CHR Extension: (Sheets) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-14]
CHR Extension: (Google Docs Offline) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-10-29]
CHR Extension: (Ace Script) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2019-10-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-29]
CHR Extension: (Gmail) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-10-29]
CHR Extension: (Chrome Media Router) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-29]
CHR HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6998536 2017-12-08] (BattlEye Innovations e.K. -> )
R2 BtSwitcherService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe [64216 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CSRBtAudioService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe [465624 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CsrBtOBEXService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe [1041616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CsrBtService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe [825032 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4506728 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [784512 2019-05-27] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-03-11] (Malwarebytes Inc -> Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2466608 2019-11-19] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3344176 2019-11-19] (Electronic Arts, Inc. -> Electronic Arts)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 Surfshark Service; C:\Program Files (x86)\Surfshark\Resources\x64\nssm.exe [436688 2020-02-17] (Surfshark Ltd. -> Iain Patterson)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-09-24] (LAVASOFT SOFTWARE CANADA INC -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [45832 2019-10-01] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [24424 2016-08-13] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [137496 2018-09-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-18] (ASUSTeK Computer Inc. -> )
R3 athur; C:\WINDOWS\System32\drivers\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 csravrcp; C:\WINDOWS\System32\drivers\csravrcp.sys [26304 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 CsrBthAudioHF; C:\WINDOWS\system32\DRIVERS\CsrBthAudioHF.sys [39120 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 CsrBtPort; C:\WINDOWS\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrhfgcc; C:\WINDOWS\System32\drivers\csrhfgcc.sys [38080 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrpan; C:\WINDOWS\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrserial; C:\WINDOWS\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrusb; C:\WINDOWS\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrusbfilter; C:\WINDOWS\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csr_bthav; C:\WINDOWS\system32\drivers\csrbthav.sys [99520 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-07] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-07] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-08] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2020-04-08] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-08] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [119960 2020-04-08] (Malwarebytes Inc -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\nvlddmkm.sys [23439288 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [947712 2017-02-20] (Realtek Semiconductor Corp. -> Realtek )
S3 SurfsharkSplitTunnelDriver; C:\Program Files (x86)\Surfshark\Resources\x64\SurfsharkSplitTunnelCalloutDriver.sys [39648 2020-02-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 tapsurfshark; C:\WINDOWS\System32\drivers\tapsurfshark.sys [38728 2019-05-22] (WDKTestCert Lenovo,131775874531219913 -> The OpenVPN Project)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2019-12-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2019-12-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-10] (Microsoft Windows -> Microsoft Corporation)
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-04-08 14:16 - 2020-04-08 14:18 - 000026329 _____ C:\Users\ubers\Downloads\FRST.txt
2020-04-08 14:14 - 2020-04-08 14:17 - 000000000 ____D C:\FRST
2020-04-08 14:14 - 2020-04-08 14:14 - 002281472 _____ (Farbar) C:\Users\ubers\Downloads\FRST64.exe
2020-04-08 12:06 - 2020-04-08 12:06 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-08 12:06 - 2020-04-08 12:06 - 000119960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-08 12:06 - 2020-04-08 12:06 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-04-08 12:05 - 2020-04-08 12:05 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-07 21:46 - 2020-04-07 21:46 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-07 21:04 - 2020-03-31 13:05 - 000454790 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20200407-210437.backup
2020-03-31 13:05 - 2020-03-04 12:33 - 000454790 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20200331-130545.backup
2020-03-30 21:29 - 2020-03-30 21:29 - 000000000 ____D C:\Users\ubers\AppData\Local\NVIDIA
2020-03-30 18:16 - 2020-03-30 18:16 - 000001455 _____ C:\Users\Public\Desktop\DOOM Eternal.lnk
2020-03-30 18:16 - 2020-03-30 18:16 - 000001455 _____ C:\ProgramData\Desktop\DOOM Eternal.lnk
2020-03-26 11:16 - 2020-04-08 12:02 - 000000000 ____D C:\Users\ubers\AppData\Local\Spotify
2020-03-26 11:16 - 2020-03-26 11:16 - 000001881 _____ C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2020-03-25 18:22 - 2020-03-25 18:22 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2020-03-25 18:20 - 2020-03-18 05:39 - 000222112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-03-25 18:20 - 2020-03-18 05:39 - 000039824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2020-03-25 18:17 - 2020-03-18 19:23 - 005589224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-03-25 18:16 - 2020-03-18 22:22 - 004927048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-03-25 18:16 - 2020-03-18 22:22 - 004196160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001078992 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 001078992 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000450464 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000348048 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-03-25 18:16 - 2020-03-18 19:25 - 011944864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2020-03-25 18:16 - 2020-03-18 19:25 - 010285472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 002073200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001565136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001481144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001351776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001142384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001022560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000817264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000680048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000676240 _____ C:\WINDOWS\system32\nvofapi64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000573024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2020-03-25 18:16 - 2020-03-18 19:24 - 000546928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000544144 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 017601120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 015157664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 005856864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 005158512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 001049696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000849848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2020-03-25 18:16 - 2020-03-18 19:23 - 000811632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000655472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000445024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2020-03-25 18:16 - 2020-03-18 05:39 - 000111058 _____ C:\WINDOWS\system32\nvidia-smi.1.pdf
2020-03-25 18:16 - 2020-03-18 05:39 - 000077314 _____ C:\WINDOWS\system32\nvinfo.pb
2020-03-22 20:32 - 2020-03-22 20:57 - 000000000 ____D C:\Users\ubers\Downloads\Knives Out (2019) [720p] [BluRay] [YTS.MX]
2020-03-22 20:21 - 2020-03-22 20:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Surfshark
2020-03-11 01:32 - 2020-03-11 01:32 - 011723776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 003550624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 002469432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 002323688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001707208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001605000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001288648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001076040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 019020288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 013013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 012306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 008907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 007870976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 005436904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004664320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004066816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003952760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003909632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002751336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002273296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002182456 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002150912 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002100056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001876960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001750528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001430880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001296360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001229824 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001201128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 001062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000946688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000796160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000763032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
 
Last edited:
2020-03-11 01:31 - 2020-03-11 01:31 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000522104 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.PredictionUnit.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provsvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFIPP.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000263576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSHExtensions.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-03-11 01:31 - 2020-03-11 01:31 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactHarvesterDS.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-03-11 01:31 - 2020-03-11 01:31 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 015220224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006545096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006445056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005915936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005309080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005210896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 004344832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003873704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003429888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Controls.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003096064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002779272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002698752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002349056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002279296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002264344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001862656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001761280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001759232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001693696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001678800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001674696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001668752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001606144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001590072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001573480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001495480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001465264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001458056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001427592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001294336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001292800 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001278808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001272360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001223168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001222456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001162088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001125392 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001122304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001098128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000964984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000934912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000926056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000909624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000828728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000821760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000805504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000791864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000774968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000718944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000661304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000651264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000648392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000622632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000574864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000555440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000542536 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000515448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000492216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000473832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000461488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIso.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UiaManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000453208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000439976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2020-03-11 01:30 - 2020-03-11 01:30 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000408528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000373560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000366728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000312632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000279416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000277840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000267264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockScreenData.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000264208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000252264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\feclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000243216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchangeHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000239664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000219656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Cortana.Persona.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000205312 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\feclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000176112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000175928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpcsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddisplay.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000157536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.OneCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Sockets.PushEnabledApplication.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oledlg.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000140304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000139648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000124440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
 
2020-03-11 01:30 - 2020-03-11 01:30 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DSCache.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\efslsaext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000108392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Display.DisplayEnhancementOverride.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olecli32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000107008 _____ C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olethk32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000105784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000094496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvHelper.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000074752 ____R (Microsoft Corporation) C:\WINDOWS\system32\mdmpostprocessevaluator.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpussvr.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.internal.shellcommon.AccountsControlExperience.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvHelper.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olesvr32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFrameworkInternalPS.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.SystemManufacturers.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 022137120 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 009672208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 006942720 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 005575168 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004736512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004589056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 004303872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004018688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 003636736 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 003630592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 003490304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002981888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002917688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002701816 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002627088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 002074984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001962296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 001961984 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001890816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001837136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001753088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001751640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001702600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-03-11 01:29 - 2020-03-11 01:29 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001568768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001473080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001390888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001360912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001346192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-03-11 01:29 - 2020-03-11 01:29 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001287072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001262592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001183504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001169920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001001472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000998928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000930816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000872960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000745472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000736272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.ComposerFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000678376 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000655160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000641696 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000620032 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000581632 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000501760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000420352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneDataSync.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000409912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvctpSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenData.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000363320 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvrcp.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000320728 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Cortana.Persona.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000274448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposerFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000262336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ManagePhone.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000240376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeopleBand.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.DesktopHosting.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\oledlg.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.CredentialProvider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ContentDeliveryManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000168488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.SettingsExtensibility.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsExtensibilityHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000134456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000132480 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredDialogBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopShellExt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MuiUnattend.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000090608 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PersonalizationCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsCtfMonitor.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\desktopimgdownldr.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000072984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrameHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe
2020-03-11 01:28 - 2020-03-11 01:29 - 001478968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007888896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007556600 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 006058032 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005577872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005528576 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005301248 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 004853760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Controls.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 004417008 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 003361080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002848768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002634752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002620928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002611136 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002437344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002433024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002418176 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 002233856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002197504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002185216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002086192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001929728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001844456 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001830712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001796400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001794048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001768960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001720320 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001701384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001422336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001335296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001308672 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001287584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001194496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001081656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 001052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 001049600 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001038336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001035264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001021952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000987736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000984888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000938296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000903368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000890400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000882176 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000862224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 000848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000847872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000818640 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000780408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000741688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000723456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
 
2020-03-11 01:28 - 2020-03-11 01:28 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000681416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\UiaManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000650240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000622336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000605576 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2020-03-11 01:28 - 2020-03-11 01:28 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxAPDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000510504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxHAPDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000468792 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtCangjieDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtBopomofoDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtHkStrokeDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChsStrokeDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtQuickDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000451120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000446480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000443368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000439096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 000437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000418576 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000399376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000390128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000386360 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000377344 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpndecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000376784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxDecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnclient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxinputrouter.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000347784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.shareexperience.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtfDecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000314072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000312704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayServer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000293856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpnranker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000282424 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_InputPersonalization.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiCloudStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000262656 _____ C:\WINDOWS\system32\HeatCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000239120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Devices.Sensors.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000213816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddisplay.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\useractivitybroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000200720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000199680 _____ C:\WINDOWS\system32\IHDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000193552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Sockets.PushEnabledApplication.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000163448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingCSP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFFuzzyDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000152576 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\vfuprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000149240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Display.DisplayEnhancementOverride.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DSCache.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000147944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdvancedEmojiDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\StaticDictDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000133432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000125440 _____ C:\WINDOWS\system32\WindowsDefaultHeatProcessor.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000121536 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxranker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HashtagDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sihost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFSpellcheckDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000106296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFAppServiceDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000099896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuntimeBroker.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpnUserService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuleBasedDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.AccountsControlExperience.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityServicePal.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.SystemManufacturers.dll
2020-03-11 01:27 - 2020-03-11 01:28 - 000442880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 007700480 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 004997096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 003581440 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 003334496 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002707456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 002590944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002466816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002149160 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002015400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002004992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001771824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001743376 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001677312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001674752 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001519488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001496576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001387512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001293768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001258296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 001205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001049400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000988240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000904104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000902464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000902144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000871792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000863528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000769760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000680944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000667664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000652304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000650552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000532184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-03-11 01:27 - 2020-03-11 01:27 - 000461840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000438784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SDDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000407712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingASDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000385552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000367208 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000298808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000283240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000276496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000255128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmBroker.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000252944 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wosc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.OneCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000222008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000193336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Security.Attestation.DeviceAttestation.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000149488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000141728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000130872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000118472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvEmulation.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvPlatform.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000109704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialUIBroker.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000103952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingFilterDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MuiUnattend.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsCtfMonitor.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-03-10 22:44 - 2020-04-08 12:03 - 000020896 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-03-10 22:44 - 2020-04-08 12:03 - 000020373 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-03-10 22:44 - 2020-04-08 12:03 - 000014284 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-03-10 22:44 - 2020-04-07 19:32 - 000001209 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2020-03-10 17:46 - 2020-03-10 17:46 - 000000000 ____D C:\Users\ubers\OneDrive\Documents\antimicro-2.23-win32.portable
2020-03-10 17:25 - 2020-03-10 17:25 - 005317893 _____ C:\Users\ubers\OneDrive\Documents\Forward Brewing - 7bbl Combi DF w 15bbl HLT complete brewery proposal 3-22-19.pdf
2020-03-10 16:36 - 2020-03-25 00:05 - 000000000 ____D C:\Users\ubers\AppData\Roaming\qBittorrent
2020-03-10 16:36 - 2020-03-10 16:36 - 000000000 ____D C:\Users\ubers\AppData\Local\qBittorrent
2020-03-10 16:36 - 2020-03-10 16:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2020-03-10 16:36 - 2020-03-10 16:36 - 000000000 ____D C:\Program Files\qBittorrent

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2099-11-18 18:48 - 2019-02-22 02:25 - 000000000 ____D C:\Users\Administrator
2020-04-08 14:17 - 2018-09-15 03:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-08 13:57 - 2018-04-17 19:47 - 000000000 ____D C:\Users\ubers\AppData\LocalLow\Mozilla
2020-04-08 13:54 - 2019-02-22 02:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-08 12:11 - 2019-02-22 02:37 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-08 12:11 - 2018-09-15 03:31 - 000000000 ____D C:\WINDOWS\INF
2020-04-08 12:05 - 2019-07-09 11:53 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2020-04-08 12:05 - 2019-02-22 02:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-08 12:03 - 2018-09-15 02:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-08 11:29 - 2018-10-30 18:16 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Spotify
2020-04-08 11:29 - 2017-12-06 08:48 - 000000000 ____D C:\Program Files (x86)\Steam
2020-04-08 01:05 - 2018-09-15 03:33 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-08 01:05 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-07 21:46 - 2019-07-22 21:07 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-07 19:56 - 2019-06-13 03:54 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-07 19:32 - 2019-10-31 23:24 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-04-07 19:32 - 2018-04-17 19:47 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-07 14:50 - 2019-10-29 16:02 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-07 14:50 - 2019-10-29 16:02 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-07 14:50 - 2018-02-14 19:16 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-06 22:50 - 2018-04-17 19:47 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-04-04 15:36 - 2019-02-22 02:44 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-04-03 14:33 - 2019-05-31 10:50 - 000000000 ____D C:\Users\ubers\OneDrive\Documents\BeerSmith2
2020-04-01 15:35 - 2019-11-15 02:39 - 000000000 ____D C:\WINDOWS\Panther
2020-04-01 13:52 - 2019-02-22 02:42 - 000028578 _____ C:\WINDOWS\diagwrn.xml
2020-04-01 13:52 - 2019-02-22 02:42 - 000028578 _____ C:\WINDOWS\diagerr.xml
2020-04-01 10:25 - 2018-09-15 02:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-04-01 09:46 - 2019-03-19 03:02 - 000000000 ___HD C:\$WINDOWS.~BT
2020-03-30 21:26 - 2017-10-17 12:33 - 000000000 ____D C:\ProgramData\Package Cache
2020-03-30 21:22 - 2020-02-10 18:57 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2020-03-30 21:19 - 2020-02-10 18:58 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2020-03-30 18:16 - 2020-02-10 14:12 - 000000000 ____D C:\Games
2020-03-25 18:22 - 2017-10-17 12:34 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-03-25 18:12 - 2017-12-06 09:00 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-03-24 20:01 - 2017-12-05 20:08 - 000000000 ____D C:\Users\ubers\AppData\Local\Publishers
2020-03-22 21:27 - 2018-05-17 19:39 - 000000000 ____D C:\Users\ubers\AppData\Local\D3DSCache
2020-03-22 20:22 - 2020-02-12 01:13 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Surfshark
2020-03-22 20:21 - 2020-02-20 18:57 - 000001018 _____ C:\Users\Public\Desktop\Surfshark.lnk
2020-03-22 20:21 - 2020-02-20 18:57 - 000001018 _____ C:\ProgramData\Desktop\Surfshark.lnk
2020-03-22 20:21 - 2020-02-12 01:14 - 000000000 ____D C:\Program Files (x86)\Surfshark
2020-03-22 10:49 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-03-20 22:08 - 2019-02-22 02:44 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 22:08 - 2019-02-22 02:44 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-17 12:39 - 2020-03-04 11:57 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-17 12:38 - 2020-03-04 11:57 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-12 18:48 - 2019-10-29 17:28 - 000000000 ____D C:\Program Files\Epic Games
2020-03-11 10:56 - 2019-07-22 21:07 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-03-11 10:56 - 2019-07-22 21:07 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-03-11 10:53 - 2019-07-22 21:07 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-03-11 10:42 - 2017-12-06 08:36 - 000000000 ___RD C:\Users\ubers\3D Objects
2020-03-11 10:42 - 2017-10-17 12:29 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-03-11 10:39 - 2019-02-22 02:18 - 000290376 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-03-11 10:35 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\setup
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-03-11 10:34 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\Program Files\Windows Defender
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-03-11 10:33 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\servicing
2020-03-11 01:40 - 2017-12-05 21:59 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-03-11 01:37 - 2018-09-15 03:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-03-11 01:37 - 2017-12-05 21:58 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-03-10 22:45 - 2018-06-20 19:15 - 000000000 ____D C:\ProgramData\Packages
2020-03-10 22:45 - 2017-12-06 08:14 - 000000000 ____D C:\Users\ubers\AppData\Local\Packages
2020-03-10 22:36 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\Help
2020-03-10 22:36 - 2017-10-17 12:34 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2020-03-10 22:36 - 2017-10-17 12:32 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-03-10 22:35 - 2017-12-05 20:09 - 000000000 ____D C:\Users\ubers\AppData\Local\NVIDIA Corporation
2020-03-10 22:35 - 2017-10-17 12:34 - 000000000 ____D C:\ProgramData\NVIDIA
2020-03-10 22:20 - 2018-02-11 10:52 - 000000000 ____D C:\Users\ubers\AppData\Local\CrashDumps
2020-03-10 20:11 - 2019-09-24 17:54 - 000000000 ____D C:\Users\ubers\AppData\Roaming\uTorrent

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-04-2020
Ran by ubers (08-04-2020 14:19:56)
Running from C:\Users\ubers\Downloads
Windows 10 Home Version 1809 17763.1098 (X64) (2019-02-22 06:45:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1116177293-2918626760-3563952597-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-1116177293-2918626760-3563952597-503 - Limited - Disabled)
Guest (S-1-5-21-1116177293-2918626760-3563952597-501 - Limited - Disabled)
ubers (S-1-5-21-1116177293-2918626760-3563952597-1002 - Administrator - Enabled) => C:\Users\ubers
WDAGUtilityAccount (S-1-5-21-1116177293-2918626760-3563952597-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Spybot - Search and Destroy (Disabled - Out of date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
Another Matrix Screen Saver (HKLM-x32\...\Another Matrix Screen Saver_is1) (Version: - NicheScreenSavers.com)
BeerSmith 2 (HKLM-x32\...\BeerSmith 2) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
CSR Harmony Wireless Software Stack (HKLM\...\{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}) (Version: 2.1.63.0 - Cambridge Silicon Radio Limited.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.12.0.1114 - Disc Soft Ltd)
Deezloader Remix 4.2.1 (HKLM\...\5eed4b40-1ed5-51be-ab52-56cdb94a998f) (Version: 4.2.1 - RemixDevs)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Disco Elysium (HKLM-x32\...\Disco Elysium_is1) (Version: - )
DOOM Eternal (HKLM-x32\...\DOOM Eternal_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech SetPoint 6.69 (HKLM\...\sp6) (Version: 6.69.123 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Mozilla Firefox 74.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 74.0.1 (x64 en-US)) (Version: 74.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla)
My Game Long Name (HKLM\...\UDK-91b9687a-b04d-4016-b6d0-f3cb44f9625d) (Version: - Epic Games, Inc.)
NVIDIA Graphics Driver 445.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 445.75 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.26 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OpenOffice 4.1.5 (HKLM-x32\...\{ABCAD346-4F4B-49E9-9AA1-28EF8C26059D}) (Version: 4.15.9789 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.56.33908 - Electronic Arts, Inc.)
qBittorrent 4.2.1 (HKLM-x32\...\qBittorrent) (Version: 4.2.1 - The qBittorrent project)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.13.1223.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
Spotify (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Spotify) (Version: 1.1.29.592.gf0779179 - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Surfshark (HKLM-x32\...\{97BF3003-CFBB-472E-A316-EF81E56A680B}) (Version: 2.6.2000 - Surfshark) Hidden
Surfshark (HKLM-x32\...\Surfshark 2.6.2000) (Version: 2.6.2000 - Surfshark)
Surfshark TAP Driver Windows (HKLM-x32\...\{20E69C09-F752-4594-A030-CB8A63C8834B}) (Version: 1.0 - Surfshark)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Web Companion (HKLM-x32\...\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}) (Version: 4.8.2078.3950 - Lavasoft)

Packages:
=========
Adblock Plus -> C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.19.0_neutral__d55gg7py3s0m0 [2020-02-18] (eyeo GmbH)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Beautiful Norway -> C:\Program Files\WindowsApps\Microsoft.BeautifulNorway_1.0.0.0_neutral__8wekyb3d8bbwe [2018-09-09] (Microsoft Corporation)
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_6.5.9.0_x86__kgqvnymyfvs32 [2020-03-03] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.165.800.0_x86__kgqvnymyfvs32 [2020-04-02] (king.com)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.9.0.6_x86__h6adky7gbf63m [2020-03-10] (Gameloft SE)
Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.34.3400.0_x86__ytsefhwckbdv6 [2020-03-27] (G5 Entertainment AB)
Illusions by Josh Sommers -> C:\Program Files\WindowsApps\Microsoft.IllusionsbyJoshSommers_1.0.0.0_neutral__8wekyb3d8bbwe [2018-08-01] (Microsoft Corporation)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa [2020-03-27] (Apple Inc.) [Startup Task]
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.33.0_x64__kejf07qmg0jnm [2019-07-30] (Keeper Security Inc)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.7.0.11_x86__h6adky7gbf63m [2020-03-31] (Gameloft SE)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.14.3002.0_x64__8wekyb3d8bbwe [2020-02-18] (Microsoft Studios)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.956.0_x64__56jybvy8sckqj [2020-03-10] (NVIDIA Corp.)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-12-05] (Plex)
The Forest Floor by Bojan Šeguljev -> C:\Program Files\WindowsApps\Microsoft.TheForestFloorbyBojaneguljev_1.0.0.0_neutral__8wekyb3d8bbwe [2018-08-01] (Microsoft Corporation)
The Northern Lights -> C:\Program Files\WindowsApps\Microsoft.TheNorthernLights_1.0.0.0_neutral__8wekyb3d8bbwe [2017-12-13] (Microsoft Corporation)
Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2019-06-24] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\nvshext.dll [2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-02-05 08:24 - 2020-02-05 08:24 - 000270848 _____ () [File not signed] C:\Program Files (x86)\Surfshark\Resources\x32\Surfshark.Firewall.dll
2017-12-12 22:06 - 2019-02-21 12:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\ubers\OneDrive:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity [130]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\BeerSmith2:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\desktop.ini:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\Forward Brewing Cover Letter.doc:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\League of Legends:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\TunesKit Spotify Converter:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.

IE trusted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\webcompanion.com -> hxxp://webcompanion.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 17:03 - 2020-04-07 21:04 - 000454790 ____R C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com

There are 15610 more lines.


==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 162.252.172.57 - 149.154.159.92
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: EasyAntiCheat => 3
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "Surfshark"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{5A301D1A-39F0-432B-B5B1-A87ED789FE07}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{91059B9F-332C-43C0-B6F5-F3AD594F4E4A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{169F56A6-68EB-4B80-BF80-9EB42E70CB1B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DISTRAINT\distraint.exe () [File not signed]
FirewallRules: [{CD7712A4-0872-4D27-BC3C-FE966BE55B85}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DISTRAINT\distraint.exe () [File not signed]
FirewallRules: [{DA2227C6-48BC-4B2B-B51B-6117C9F4C727}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{F63C87C1-AFD1-4A7F-9AE8-6C937C6DAA16}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{B4F31C62-8410-4DCF-9695-ECB27D35E72F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{336C9374-387E-4970-BA14-328CCB4901F1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{31A8AE11-7D93-45B2-A557-E3FAEC431BBF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{779AA47D-9CB5-4888-A13D-B6D68C5904AF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{37E7B5F6-B2E7-44A0-A36D-99A1AAD6ECE7}C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{245F2172-0E63-47D0-AA2E-FDE0E67F0744}C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{F43AE5FC-D27B-453C-AFC2-6C6F10D67025}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A8806773-9CE0-4CA5-A8CB-A92ECE4D98CD}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{77A902DC-6F9C-4DCE-B537-8B77BBE0482C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{B3AD0F01-F091-4E7F-BD5A-58DF208D8E9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{4539AD93-7D50-4B54-BD25-A08376E4C45D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe (Epic Games, Inc. and Tripwire Interactive) [File not signed]
FirewallRules: [{DD99955C-6B57-49B8-B6E2-792335648C6F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe (Epic Games, Inc. and Tripwire Interactive) [File not signed]
FirewallRules: [TCP Query User{56839ED8-9DC0-40A2-86C1-7F4A2C1D6845}C:\program files\deezloader remix\deezloader remix.exe] => (Allow) C:\program files\deezloader remix\deezloader remix.exe (RemixDevs) [File not signed]
FirewallRules: [UDP Query User{BC1FF7FA-B4F0-477A-8DF2-F6E3C3569B9B}C:\program files\deezloader remix\deezloader remix.exe] => (Allow) C:\program files\deezloader remix\deezloader remix.exe (RemixDevs) [File not signed]
FirewallRules: [{5C93EC5E-4034-4261-BFEF-83F1B377F71D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{92238D05-BC6A-474D-B8CC-E0CC46F8DA74}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [TCP Query User{7742E5F6-2F9E-488F-9E73-70ABB0398576}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{1430E8C0-7A08-4CBF-A331-ACC923962FF7}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F1914876-5A4D-433E-AB01-8F13EC8CC6E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nidhogg\Nidhogg.exe (Messhof LLC ) [File not signed]
FirewallRules: [{E38FDE0D-9E1A-4729-8743-B8AAF298B444}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nidhogg\Nidhogg.exe (Messhof LLC ) [File not signed]
FirewallRules: [{EC4DE410-B7D4-4177-9116-9ACAD907B456}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{C011C904-5B19-4A84-80A7-C454EF321F9B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{6BF52733-A45F-48E7-BE80-695F8F57860D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{BD149176-20D3-4B66-B41E-EAAA0E60F86E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{32188358-ADFD-409F-9EEF-41CC90F94369}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{145D4A71-8211-456E-8299-1F2567227B95}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{FF3CCA2A-3421-446A-966A-1342579D5830}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E779AA15-6094-4D5E-841D-AB9C7B75A030}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{91CDBA59-736D-4D83-B909-DFF07A036701}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{579324C4-1D11-416E-9AD4-6C4D2FDB947C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{B868668C-D543-48B0-B7E5-DF1EE9BB07C4}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{16AF6D74-35CE-4B49-94FF-45813722E560}C:\users\ubers\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ubers\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{6000E1F0-5A51-467B-857E-6792D5DE940F}C:\users\ubers\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ubers\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{84EBDB2B-F301-4D3D-BE79-3B134283443D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{84770ECD-4D23-4AFB-9EC0-94EFC5286432}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{939DA58C-B2BF-4344-B5C3-697E94C1ED8F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{64750DFC-2F4D-4430-85DB-549CAE57026C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A2D96B6F-FBBF-4923-9186-2B98BF76BFA7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F5CF28C8-3656-485F-8429-79768504525F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{35A615BB-C72F-457E-8563-95AED041A636}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1E0B6663-2785-4039-B172-3B298F9DFE33}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B311BB8F-9992-4090-9E88-EDB27AD98280}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{4E469167-6284-4473-A900-93E589CB8F01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{EC21A512-8F0B-44EE-9964-6E2EC689CAC4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (04/07/2020 09:05:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SystemSettings.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1d2c

Start Time: 01d60d417fd3fada

Termination Time: 4294967295

Application Path: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

Report Id: 145d36c1-3145-4c72-9573-6afd33d1ad2d

Faulting package full name: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy

Faulting package-relative application ID: microsoft.windows.immersivecontrolpanel

Hang type: Quiesce

Error: (04/07/2020 07:35:16 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 01:19:10 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 12:28:53 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 11:39:50 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/30/2020 09:26:29 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.


Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet

Error: (03/30/2020 09:25:51 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.


Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet

Error: (03/30/2020 09:25:11 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.


Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet


System errors:
=============
Error: (04/08/2020 02:21:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 02:21:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 02:17:59 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 02:17:59 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 01:57:46 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 01:57:45 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/08/2020 12:05:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Origin Web Helper Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (04/08/2020 12:05:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect.


Windows Defender:
===================================
Date: 2020-01-14 23:19:40.354
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {1149D45B-5660-4430-88B3-8FCC3A882F0D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 19:05:49.955
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {E3E7A707-C081-4DB1-B61A-9C8FB4E3985C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 18:57:18.176
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {41004036-9630-4537-AD44-9150DABD924C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 18:51:01.318
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {D6CE9B43-5D94-4415-BAF3-63BEA402EC59}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-10-24 21:28:40.268
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {41B6329B-B645-4C25-A1E5-E11DE561A37C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.666
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.658
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

CodeIntegrity:
===================================

Date: 2020-04-08 12:05:17.135
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-08 12:05:13.075
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-07 19:33:06.458
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-07 19:33:06.451
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-31 13:18:36.040
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-31 13:18:36.033
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-30 15:49:34.089
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-30 15:49:34.080
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0609 05/15/2017
Motherboard: ASUSTeK COMPUTER INC. PRIME A320M-K
Processor: AMD Ryzen 5 1400 Quad-Core Processor
Percentage of memory in use: 61%
Total physical RAM: 8122.77 MB
Available physical RAM: 3120.43 MB
Total Virtual: 17850.77 MB
Available Virtual: 9773.48 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.5 GB) (Free:641.1 GB) NTFS

\\?\Volume{a7b33a88-146d-4340-88f7-5aa1609383d7}\ () (Fixed) (Total:0 GB) (Free:0 GB)
\\?\Volume{6a53ea90-c5ba-40c9-9917-900b2442ad0c}\ () (Fixed) (Total:0.45 GB) (Free:0.06 GB) NTFS
\\?\Volume{456da56b-2c91-439e-8839-5691bf5afabf}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
 
Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

===========================================

redtarget.gif
Download RogueKiller from one of the following links and save it to your Desktop:

Link 1
Link 2
  • Close all the running programs
  • Double click on downloaded setup.exe file to install the program.
  • Click on Start Scan button.
  • Click on another Start Scan button.
  • Wait until the Status box shows Scan Finished
  • Click on Remove Selected.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If more than one log is produced post all logs.
redtarget.gif
Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
  • The Scan log is available throughout History ->Application logs. Please post it contents in your next reply.
redtarget.gif
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8/10 users right-click and select Run As Administrator
  • The tool will start to update the database if one is required.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button.
  • A window will open which lists the logs of your scans.
  • Click on the Scan tab.
  • Double-click the most recent scan which will be at the top of the list....the log will appear.
  • Review the results...see note below
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[CX].txt) will open automatically (where the largest value of X represents the most recent report).
  • To open a Cleaning log, launch AdwareClearer, click on the Logfile button, click on the Cleaning tab and double-click the log at the top of the list.
  • Copy and paste the contents of AdwCleaner[CX].txt in your next reply.
  • A copy of all logfiles are saved to C:\AdwCleaner.
-- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name or entry that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on and uncheck any items you want to keep.
 
Thanks for the quick response Broni. I've pasted the logs below:

RogueKiller Anti-Malware V14.4.0.0 (x64) [Apr 1 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17763) 64 bits
Started in : Normal mode
User : ubers [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200408_101105, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2020/04/08 21:53:43 (Duration : 00:15:39)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.WebCompanion|PUP.Gen1 (Potentially Malicious)] Lavasoft.WCAssistant.WinService.exe (3600) -- (LAVASOFT SOFTWARE CANADA INC) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen0 (Potentially Malicious)] WCAssistantService (3600) -- (LAVASOFT SOFTWARE CANADA INC) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O23 - Services
[PUP.Gen0 (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WCAssistantService -- (LAVASOFT SOFTWARE CANADA INC) "C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe" -> Found
>>>>>> XX - System Policies
[PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found
>>>>>> XX - Screensaver
[Suspicious.Path (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop|SCRNSAVE.EXE -- C:\WINDOWS\ANOTHE~1.SCR -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Hosts file is too big

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen1 (Potentially Malicious)] (folder) ACEStream -- C:\Users\ubers\AppData\Roaming\ACEStream -> Found
[PUP.Gen1 (Potentially Malicious)] (folder) Web Companion -- C:\Users\ubers\AppData\Roaming\Lavasoft\Web Companion -> Found
[PUP.Gen1 (Potentially Malicious)] (folder) Web Companion -- C:\ProgramData\Lavasoft\Web Companion -> Found
[PUP.WebCompanion|PUP.Gen1 (Potentially Malicious)] (folder) Web Companion -- C:\Program Files (x86)\Lavasoft\Web Companion -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Firefox Addon
[PUP.Gen1 (Potentially Malicious)] Ace Script (C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\extensions\acewebextension_unlisted@acestream.org) -- acewebextension_unlisted@acestream.org -> Found

RogueKiller Anti-Malware V14.4.0.0 (x64) [Apr 1 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17763) 64 bits
Started in : Normal mode
User : ubers [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20200408_101105, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/04/09 10:18:41 (Duration : 00:15:39)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.WebCompanion|PUP.Gen1 (Potentially Malicious)] Lavasoft.WCAssistant.WinService.exe [LAVASOFT SOFTWARE CANADA INC] -- %programfiles(x86)%\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe -> Killed [Tree]
[PUP.Gen0 (Potentially Malicious)] WCAssistantService [LAVASOFT SOFTWARE CANADA INC] -- %programfiles(x86)%\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe -> ERROR [6D]
[PUP.Gen0 (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WCAssistantService -- [%programfiles(x86)%\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe] -> Deleted
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- -> Replaced (2)
[Suspicious.Path (Potentially Malicious)] HKEY_USERS\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop|SCRNSAVE.EXE -- [%SystemRoot%\Another Matrix Screen Saver.scr] -> Replaced (C:\WINDOWS\system32\logon.scr)
[PUP.Gen1 (Potentially Malicious)] ACEStream -- %_ubers_appdata%\ACEStream -> Deleted
=> acewebextension_unlisted.xpi -- C:\Users\ubers\AppData\Roaming\ACESTR~1\EXTENS~1\awe\firefox\ACEWEB~1.XPI [1]
=> firefox -- C:\Users\ubers\AppData\Roaming\ACESTR~1\EXTENS~1\awe\firefox [1]
=> awe -- C:\Users\ubers\AppData\Roaming\ACESTR~1\EXTENS~1\awe [1]
=> extensions -- C:\Users\ubers\AppData\Roaming\ACESTR~1\EXTENS~1 [1]
[PUP.Gen1 (Potentially Malicious)] Web Companion -- %_ubers_appdata%\Lavasoft\Web Companion -> Deleted
=> Language.txt -- C:\Users\ubers\AppData\Roaming\Lavasoft\WEBCOM~1\Options\Language.txt [1]
=> Options -- C:\Users\ubers\AppData\Roaming\Lavasoft\WEBCOM~1\Options [1]
[PUP.Gen1 (Potentially Malicious)] Web Companion -- %programdata%\Lavasoft\Web Companion -> Deleted
=> bing.ico -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Icons\bing.ico [1]
=> Icons -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Icons [1]
=> webcompanion.log -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Logs\WEBCOM~1\WEBCOM~1.LOG [1]
=> Webcompanion -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Logs\WEBCOM~1 [1]
=> WCAssistantServiceLog.log -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Logs\WINDOW~1\WCASSI~1.LOG [1]
=> WindowsService -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Logs\WINDOW~1 [1]
=> Logs -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Logs [1]
=> ActiveFeatures.zip -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\ACTIVE~1.ZIP [1]
=> AppSettings.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\APPSET~1.TXT [1]
=> b_search.json -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\B_SEAR~1.JSO [1]
=> ChannelInfo.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\CHANNE~1.TXT [1]
=> comresponse.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\COMRES~1.TXT [1]
=> com_ff_messaging.json -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\COM_FF~1.JSO [1]
=> CurrentReleaseNotes.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\CURREN~1.TXT [1]
=> EventSafeguard.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\EVENTS~1.TXT [1]
=> install.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\install.txt [1]
=> LatestReleaseNotes.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\LATEST~1.TXT [1]
=> partner.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\partner.txt [1]
=> ProfileInfo.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\PROFIL~1.TXT [1]
=> SearchInfo.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\SEARCH~1.TXT [1]
=> ServicePartnerInfo.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\SERVIC~1.TXT [1]
=> Statistics.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\STATIS~1.TXT [1]
=> UpdateServer.txt -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options\UPDATE~1.TXT [1]
=> Options -- C:\PROGRA~3\Lavasoft\WEBCOM~1\Options [1]
[PUP.WebCompanion|PUP.Gen1 (Potentially Malicious)] Web Companion -- %programfiles(x86)%\Lavasoft\Web Companion -> Deleted
=> Ad-Aware Web Companion.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\AD-AWA~1.EXE [1]
=> BCUEngineS.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\BCUENG~1.DLL [1]
=> BCUSDK.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\BCUSDK.dll [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\de-DE\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\de-DE\WEBCOM~2.DLL [1]
=> de-DE -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\de-DE [1]
=> DotNetZip.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\DOTNET~1.DLL [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\en-US\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\en-US\WEBCOM~2.DLL [1]
=> en-US -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\en-US [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\es-ES\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\es-ES\WEBCOM~2.DLL [1]
=> es-ES -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\es-ES [1]
=> Esent.Interop.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ESENTI~1.DLL [1]
=> @wcextensionff.xpi -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\EXTENS~1\@WCEXT~1.XPI [1]
=> Extension -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\EXTENS~1 [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\fr-CA\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\fr-CA\WEBCOM~2.DLL [1]
=> fr-CA -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\fr-CA [1]
=> ICSharpCode.SharpZipLib.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ICSHAR~1.DLL [1]
=> Interop.IWshRuntimeLibrary.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\INTERO~1.DLL [1]
=> Interop.LavasoftTcpServiceLib.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\INTERO~2.DLL [1]
=> Interop.SHDocVw.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\INTERO~3.DLL [1]
=> Interop.Shell32.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\INTERO~4.DLL [1]
=> Ionic.Zip.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\IONICZ~1.DLL [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\it-IT\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\it-IT\WEBCOM~2.DLL [1]
=> it-IT -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\it-IT [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ja-JP\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ja-JP\WEBCOM~2.DLL [1]
=> ja-JP -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ja-JP [1]
=> Lavasoft.adblocker.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~1.DLL [1]
=> Lavasoft.AppCore.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~2.DLL [1]
=> Lavasoft.Automation.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~3.DLL [1]
=> Lavasoft.Compression.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~4.DLL [1]
=> Lavasoft.CSharp.Utilities.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA56C0~1.DLL [1]
=> Lavasoft.Events.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LADD15~1.DLL [1]
=> Lavasoft.Extension.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA94E1~1.DLL [1]
=> Lavasoft.IEController.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA21E8~1.DLL [1]
=> Lavasoft.Omni.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA0D41~1.DLL [1]
=> Lavasoft.SearchProtect.Business.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAE30D~1.DLL [1]
=> Lavasoft.SearchProtect.Repositories.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA2CAC~1.DLL [1]
=> Lavasoft.Settings.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LADDAC~1.DLL [1]
=> Lavasoft.SysInfo.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAC1FE~1.DLL [1]
=> Lavasoft.Utils.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA04CD~1.DLL [1]
=> Lavasoft.Utils.SqlLite.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA84A0~1.DLL [1]
=> Lavasoft.WCAssistant.Service.Logger.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LA8AF0~1.DLL [1]
=> Lavasoft.WCAssistant.WcfService.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LACECB~1.DLL [1]
=> Lavasoft.WCAssistant.WinService.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~1.EXE [1]
=> Lavasoft.WCAssistant.WinService.exe.config -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LAVASO~1.CON [1]
=> liblz4.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\liblz4.dll [1]
=> log4net.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\log4net.dll [1]
=> LZ4.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\LZ4.dll [1]
=> Microsoft.mshtml.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\MICROS~1.DLL [1]
=> MozCompressor.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\MOZCOM~1.DLL [1]
=> Newtonsoft.Json.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\NEWTON~1.DLL [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\pt-BR\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\pt-BR\WEBCOM~2.DLL [1]
=> pt-BR -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\pt-BR [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ru-RU\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ru-RU\WEBCOM~2.DLL [1]
=> ru-RU -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\ru-RU [1]
=> System.Data.SQLite.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\SYSTEM~1.DLL [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\tr-TR\WEBCOM~1.DLL [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\tr-TR\WEBCOM~2.DLL [1]
=> tr-TR -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\tr-TR [1]
=> ucrtbased.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\UCRTBA~1.DLL [1]
=> vcruntime140d.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\VCRUNT~1.DLL [1]
=> WcCommunication.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WCCOMM~1.EXE [1]
=> WcCommunication.exe.config -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WCCOMM~1.CON [1]
=> WebcompaionReimageIcon.ico -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~1.ICO [1]
=> WebCompanion.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~1.EXE [1]
=> WebCompanion.exe.config -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~1.CON [1]
=> WebCompanion.Loader.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~2.EXE [1]
=> WebCompanionExtensionIE.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~1.DLL [1]
=> WebCompanionIcon.ico -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~2.ICO [1]
=> WebCompanionIcon_Pro.ico -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~3.ICO [1]
=> WebCompanionInstaller.exe -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~3.EXE [1]
=> WebCompanionInstaller.exe.config -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~2.CON [1]
=> WebCompanionInstaller.pdb -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\WEBCOM~1.PDB [1]
=> SQLite.Interop.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\x64\SQLITE~1.DLL [1]
=> x64 -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\x64 [1]
=> SQLite.Interop.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\x86\SQLITE~1.DLL [1]
=> x86 -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\x86 [1]
=> WebCompanionInstaller.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\zh-CHS\WEBCOM~1.DLL [1]
=> zh-CHS -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\zh-CHS [1]
=> WebCompanion.resources.dll -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\zh-Hans\WEBCOM~1.DLL [1]
=> zh-Hans -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1\zh-Hans [1]
=> Application -- C:\PROGRA~2\Lavasoft\WEBCOM~1\APPLIC~1 [1]
[PUP.Gen1 (Potentially Malicious)] Ace Script -- acewebextension_unlisted@acestream.org -> Deleted
 
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 4/9/20
Scan Time: 11:00 AM
Log File: c8b6846e-7a72-11ea-956e-001a7dda7113.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.867
Update Package Version: 1.0.22182
License: Premium

-System Information-
OS: Windows 10 (Build 17763.1098)
CPU: x64
File System: NTFS
User: System

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Cancelled
Objects Scanned: 100141
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 0 min, 41 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
 
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-09-2020
# Duration: 00:00:17
# OS: Windows 10 Home
# Cleaned: 21
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
Deleted C:\Users\ubers\AppData\LocalLow\.acestream
Deleted C:\Users\ubers\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG
Deleted C:\Users\ubers\AppData\Roaming\.acestream
Deleted C:\_acestream_cache_

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Classes\acestream
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
Deleted HKCU\Software\RegisteredApplications|AceStream
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|DisplayIcon
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|DisplayName
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|UninstallString
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3741 octets] - [09/04/2020 10:40:40]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 04-09-2020
# Duration: 00:00:44
# OS: Windows 10 Home
# Scanned: 31802
# Detected: 21


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy C:\Users\ubers\AppData\LocalLow\.acestream
PUP.Optional.Legacy C:\Users\ubers\AppData\Roaming\.acestream
PUP.Optional.Legacy C:\_acestream_cache_
PUP.Optional.WebCompanion C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
PUP.Optional.WebCompanion C:\Users\ubers\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Adware.Heuristic HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|DisplayIcon
PUP.Adware.Heuristic HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|DisplayName
PUP.Adware.Heuristic HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4bea32b3-85bf-4c35-a33e-c57de2256fe6}|UninstallString
PUP.Optional.ASMagicPlayer HKCU\Software\Classes\acestream
PUP.Optional.AceStream HKCU\Software\RegisteredApplications|AceStream
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\dospop.com
PUP.Optional.Legacy HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\incredibar.com
PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKLM\Software\Wow6432Node\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

  • Double click to run it.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-04-2020
Ran by ubers (10-04-2020 10:10:45)
Running from C:\Users\ubers\Downloads
Windows 10 Home Version 1809 17763.1098 (X64) (2019-02-22 06:45:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1116177293-2918626760-3563952597-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-1116177293-2918626760-3563952597-503 - Limited - Disabled)
Guest (S-1-5-21-1116177293-2918626760-3563952597-501 - Limited - Disabled)
ubers (S-1-5-21-1116177293-2918626760-3563952597-1002 - Administrator - Enabled) => C:\Users\ubers
WDAGUtilityAccount (S-1-5-21-1116177293-2918626760-3563952597-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Spybot - Search and Destroy (Enabled - Up to date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
Another Matrix Screen Saver (HKLM-x32\...\Another Matrix Screen Saver_is1) (Version: - NicheScreenSavers.com)
BeerSmith 2 (HKLM-x32\...\BeerSmith 2) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
CSR Harmony Wireless Software Stack (HKLM\...\{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}) (Version: 2.1.63.0 - Cambridge Silicon Radio Limited.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.12.0.1114 - Disc Soft Ltd)
Deezloader Remix 4.2.1 (HKLM\...\5eed4b40-1ed5-51be-ab52-56cdb94a998f) (Version: 4.2.1 - RemixDevs)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Disco Elysium (HKLM-x32\...\Disco Elysium_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech SetPoint 6.69 (HKLM\...\sp6) (Version: 6.69.123 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Mozilla Firefox 74.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 74.0.1 (x64 en-US)) (Version: 74.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla)
My Game Long Name (HKLM\...\UDK-91b9687a-b04d-4016-b6d0-f3cb44f9625d) (Version: - Epic Games, Inc.)
NVIDIA Graphics Driver 445.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 445.75 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.26 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OpenOffice 4.1.5 (HKLM-x32\...\{ABCAD346-4F4B-49E9-9AA1-28EF8C26059D}) (Version: 4.15.9789 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.56.33908 - Electronic Arts, Inc.)
qBittorrent 4.2.1 (HKLM-x32\...\qBittorrent) (Version: 4.2.1 - The qBittorrent project)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.13.1223.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
RogueKiller version 14.4.0.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 14.4.0.0 - Adlice Software)
Spotify (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Spotify) (Version: 1.1.30.658.gf13cde74 - Spotify AB)
Spotify (HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Spotify) (Version: 1.1.30.658.gf13cde74 - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Surfshark (HKLM-x32\...\{97BF3003-CFBB-472E-A316-EF81E56A680B}) (Version: 2.6.2000 - Surfshark) Hidden
Surfshark (HKLM-x32\...\Surfshark 2.6.2000) (Version: 2.6.2000 - Surfshark)
Surfshark TAP Driver Windows (HKLM-x32\...\{20E69C09-F752-4594-A030-CB8A63C8834B}) (Version: 1.0 - Surfshark)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)

Packages:
=========
Adblock Plus -> C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.19.0_neutral__d55gg7py3s0m0 [2020-02-18] (eyeo GmbH)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Beautiful Norway -> C:\Program Files\WindowsApps\Microsoft.BeautifulNorway_1.0.0.0_neutral__8wekyb3d8bbwe [2018-09-09] (Microsoft Corporation)
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_6.8.5.0_x86__kgqvnymyfvs32 [2020-04-09] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.165.800.0_x86__kgqvnymyfvs32 [2020-04-02] (king.com)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.9.0.6_x86__h6adky7gbf63m [2020-03-10] (Gameloft SE)
Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.34.3400.0_x86__ytsefhwckbdv6 [2020-03-27] (G5 Entertainment AB)
Illusions by Josh Sommers -> C:\Program Files\WindowsApps\Microsoft.IllusionsbyJoshSommers_1.0.0.0_neutral__8wekyb3d8bbwe [2018-08-01] (Microsoft Corporation)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa [2020-03-27] (Apple Inc.) [Startup Task]
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.33.0_x64__kejf07qmg0jnm [2019-07-30] (Keeper Security Inc)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.7.0.11_x86__h6adky7gbf63m [2020-03-31] (Gameloft SE)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.14.3002.0_x64__8wekyb3d8bbwe [2020-02-18] (Microsoft Studios)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.956.0_x64__56jybvy8sckqj [2020-03-10] (NVIDIA Corp.)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-12-05] (Plex)
The Forest Floor by Bojan Šeguljev -> C:\Program Files\WindowsApps\Microsoft.TheForestFloorbyBojaneguljev_1.0.0.0_neutral__8wekyb3d8bbwe [2018-08-01] (Microsoft Corporation)
The Northern Lights -> C:\Program Files\WindowsApps\Microsoft.TheNorthernLights_1.0.0.0_neutral__8wekyb3d8bbwe [2017-12-13] (Microsoft Corporation)
Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2019-06-24] (Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\nvshext.dll [2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2017-12-06 08:49 - 2014-04-09 00:25 - 000071680 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\mssmp3.asi
2017-12-06 08:49 - 2014-04-09 00:25 - 000153088 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\mssvoice.asi
2020-02-05 08:24 - 2020-02-05 08:24 - 000270848 _____ () [File not signed] C:\Program Files (x86)\Surfshark\Resources\x32\Surfshark.Firewall.dll
2017-12-12 22:06 - 2019-02-21 12:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2017-12-06 08:49 - 2014-05-02 21:16 - 000440320 _____ (RAD Game Tools, Inc.) [File not signed] C:\Program Files (x86)\Steam\bin\mss32.DLL
2017-12-06 08:49 - 2014-04-09 00:25 - 000055296 _____ (RAD Game Tools, Inc.) [File not signed] C:\Program Files (x86)\Steam\bin\mssdsp.flt

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\ubers\OneDrive:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity [130]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\BeerSmith2:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\desktop.ini:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\Forward Brewing Cover Letter.doc:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\League of Legends:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\TunesKit Spotify Converter:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7941 more sites.

IE trusted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\localhost -> localhost
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\123simsen.com -> www.123simsen.com

There are 7941 more sites.

IE trusted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\localhost -> localhost
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\123simsen.com -> www.123simsen.com

There are 7941 more sites.

IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 17:03 - 2020-04-07 21:04 - 000454790 ____R C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com

There are 15610 more lines.


==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100420721\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421348\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\Control Panel\Desktop\\Wallpaper -> C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 162.252.172.57 - 149.154.159.92
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

MSCONFIG\Services: EasyAntiCheat => 3
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "Surfshark"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\StartupApproved\Run: => "Surfshark"
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{5A301D1A-39F0-432B-B5B1-A87ED789FE07}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{91059B9F-332C-43C0-B6F5-F3AD594F4E4A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{169F56A6-68EB-4B80-BF80-9EB42E70CB1B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DISTRAINT\distraint.exe () [File not signed]
FirewallRules: [{CD7712A4-0872-4D27-BC3C-FE966BE55B85}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DISTRAINT\distraint.exe () [File not signed]
FirewallRules: [{DA2227C6-48BC-4B2B-B51B-6117C9F4C727}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{F63C87C1-AFD1-4A7F-9AE8-6C937C6DAA16}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{B4F31C62-8410-4DCF-9695-ECB27D35E72F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{336C9374-387E-4970-BA14-328CCB4901F1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{31A8AE11-7D93-45B2-A557-E3FAEC431BBF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{779AA47D-9CB5-4888-A13D-B6D68C5904AF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{37E7B5F6-B2E7-44A0-A36D-99A1AAD6ECE7}C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{245F2172-0E63-47D0-AA2E-FDE0E67F0744}C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{F43AE5FC-D27B-453C-AFC2-6C6F10D67025}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A8806773-9CE0-4CA5-A8CB-A92ECE4D98CD}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{77A902DC-6F9C-4DCE-B537-8B77BBE0482C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{B3AD0F01-F091-4E7F-BD5A-58DF208D8E9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{4539AD93-7D50-4B54-BD25-A08376E4C45D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe (Epic Games, Inc. and Tripwire Interactive) [File not signed]
FirewallRules: [{DD99955C-6B57-49B8-B6E2-792335648C6F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe (Epic Games, Inc. and Tripwire Interactive) [File not signed]
FirewallRules: [TCP Query User{56839ED8-9DC0-40A2-86C1-7F4A2C1D6845}C:\program files\deezloader remix\deezloader remix.exe] => (Allow) C:\program files\deezloader remix\deezloader remix.exe (RemixDevs) [File not signed]
FirewallRules: [UDP Query User{BC1FF7FA-B4F0-477A-8DF2-F6E3C3569B9B}C:\program files\deezloader remix\deezloader remix.exe] => (Allow) C:\program files\deezloader remix\deezloader remix.exe (RemixDevs) [File not signed]
FirewallRules: [{5C93EC5E-4034-4261-BFEF-83F1B377F71D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{92238D05-BC6A-474D-B8CC-E0CC46F8DA74}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dead by Daylight\DeadByDaylight.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [TCP Query User{7742E5F6-2F9E-488F-9E73-70ABB0398576}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [UDP Query User{1430E8C0-7A08-4CBF-A331-ACC923962FF7}C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dead by daylight\deadbydaylight\binaries\win64\deadbydaylight-win64-shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F1914876-5A4D-433E-AB01-8F13EC8CC6E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nidhogg\Nidhogg.exe (Messhof LLC ) [File not signed]
FirewallRules: [{E38FDE0D-9E1A-4729-8743-B8AAF298B444}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nidhogg\Nidhogg.exe (Messhof LLC ) [File not signed]
FirewallRules: [{EC4DE410-B7D4-4177-9116-9ACAD907B456}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{C011C904-5B19-4A84-80A7-C454EF321F9B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{6BF52733-A45F-48E7-BE80-695F8F57860D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{BD149176-20D3-4B66-B41E-EAAA0E60F86E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CastleCrashers\castle.exe () [File not signed]
FirewallRules: [{32188358-ADFD-409F-9EEF-41CC90F94369}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{145D4A71-8211-456E-8299-1F2567227B95}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{FF3CCA2A-3421-446A-966A-1342579D5830}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E779AA15-6094-4D5E-841D-AB9C7B75A030}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{91CDBA59-736D-4D83-B909-DFF07A036701}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{579324C4-1D11-416E-9AD4-6C4D2FDB947C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{B868668C-D543-48B0-B7E5-DF1EE9BB07C4}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{16AF6D74-35CE-4B49-94FF-45813722E560}C:\users\ubers\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ubers\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{6000E1F0-5A51-467B-857E-6792D5DE940F}C:\users\ubers\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ubers\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{84EBDB2B-F301-4D3D-BE79-3B134283443D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{84770ECD-4D23-4AFB-9EC0-94EFC5286432}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{939DA58C-B2BF-4344-B5C3-697E94C1ED8F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{64750DFC-2F4D-4430-85DB-549CAE57026C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A2D96B6F-FBBF-4923-9186-2B98BF76BFA7}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F5CF28C8-3656-485F-8429-79768504525F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{35A615BB-C72F-457E-8563-95AED041A636}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1E0B6663-2785-4039-B172-3B298F9DFE33}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12105.12.48001.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B311BB8F-9992-4090-9E88-EDB27AD98280}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{4E469167-6284-4473-A900-93E589CB8F01}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe (Tripwire Interactive, LLC.) [File not signed]
FirewallRules: [{EC21A512-8F0B-44EE-9964-6E2EC689CAC4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (04/09/2020 10:46:49 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (04/07/2020 09:05:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SystemSettings.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1d2c

Start Time: 01d60d417fd3fada

Termination Time: 4294967295

Application Path: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

Report Id: 145d36c1-3145-4c72-9573-6afd33d1ad2d

Faulting package full name: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy

Faulting package-relative application ID: microsoft.windows.immersivecontrolpanel

Hang type: Quiesce

Error: (04/07/2020 07:35:16 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 01:19:10 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 12:28:53 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/31/2020 11:39:50 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.

Error: (03/30/2020 09:26:29 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.


Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet

Error: (03/30/2020 09:25:51 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.


Operation:
Executing Asynchronous Operation

Context:
Current State: DoSnapshotSet


System errors:
=============
Error: (04/10/2020 10:13:30 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/10/2020 10:13:30 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/10/2020 10:02:38 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\WINDOWS\system32\athExt.dll
Error Code: 126

Error: (04/10/2020 10:02:29 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Miniport Atheros AR9271 Wireless Network Adapter #2, {186038a2-c246-434c-96d4-33c417a772d9}, had event 74

Error: (04/09/2020 11:35:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/09/2020 11:34:37 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/09/2020 11:34:37 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (04/09/2020 11:19:45 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-LQBKB2Q)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-LQBKB2Q\ubers SID (S-1-5-21-1116177293-2918626760-3563952597-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2020-01-14 23:19:40.354
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {1149D45B-5660-4430-88B3-8FCC3A882F0D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 19:05:49.955
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {E3E7A707-C081-4DB1-B61A-9C8FB4E3985C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 18:57:18.176
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {41004036-9630-4537-AD44-9150DABD924C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-11-22 18:51:01.318
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {D6CE9B43-5D94-4415-BAF3-63BEA402EC59}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-10-24 21:28:40.268
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {41B6329B-B645-4C25-A1E5-E11DE561A37C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-04-09 10:45:01.662
Description:
Windows Defender Antivirus has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted: Backup
Error Code: 0x80004004
Error description: Operation aborted
Signature version: 1.311.501.0;1.311.501.0
Engine version: 1.1.16900.4

Date: 2020-04-09 10:44:59.825
Description:
Windows Defender Antivirus has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted: Current
Error Code: 0x80508001
Error description: A problem is preventing the program from starting. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
Signature version: 1.313.431.0;1.313.431.0
Engine version: 1.1.16900.4

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2020-04-08 12:03:46.723
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.313.431.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x80072f8f
Error description: A security error occurred

CodeIntegrity:
===================================

Date: 2020-04-09 10:46:12.015
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-09 10:46:12.006
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-08 12:05:17.135
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-08 12:05:13.075
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-07 19:33:06.458
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-07 19:33:06.451
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-31 13:18:36.040
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-31 13:18:36.033
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0609 05/15/2017
Motherboard: ASUSTeK COMPUTER INC. PRIME A320M-K
Processor: AMD Ryzen 5 1400 Quad-Core Processor
Percentage of memory in use: 58%
Total physical RAM: 8122.77 MB
Available physical RAM: 3365.87 MB
Total Virtual: 18743.2 MB
Available Virtual: 10066.05 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.5 GB) (Free:679.91 GB) NTFS

\\?\Volume{a7b33a88-146d-4340-88f7-5aa1609383d7}\ () (Fixed) (Total:0 GB) (Free:0 GB)
\\?\Volume{6a53ea90-c5ba-40c9-9917-900b2442ad0c}\ () (Fixed) (Total:0.45 GB) (Free:0.06 GB) NTFS
\\?\Volume{456da56b-2c91-439e-8839-5691bf5afabf}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-04-2020
Ran by ubers (administrator) on DESKTOP-LQBKB2Q (10-04-2020 10:05:25)
Running from C:\Users\ubers\Downloads
Loaded Profiles: ubers (Available Profiles: ubers & Administrator)
Platform: Windows 10 Home Version 1809 17763.1098 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Cambridge Silicon Radio Ltd. -> ) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe
(Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited) C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Spotify AB -> Spotify Ltd) C:\Users\ubers\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\ubers\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\ubers\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\ubers\AppData\Roaming\Spotify\Spotify.exe
(Spotify AB -> Spotify Ltd) C:\Users\ubers\AppData\Roaming\Spotify\Spotify.exe
(Surfshark Ltd. -> Iain Patterson) C:\Program Files (x86)\Surfshark\Resources\x64\nssm.exe
(Surfshark Ltd. -> Surfshark) C:\Program Files (x86)\Surfshark\Surfshark.Service.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2016-08-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3136136 2019-01-29] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [CsrHCRPServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe [1134288 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CsrAudioguiCtrl] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe [511696 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CsrSyncMLServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe [244944 2012-03-22] (Cambridge Silicon Radio Ltd. -> )
HKLM\...\Run: [vksts] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe [25792 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [HarmonyUserStartup] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe [39128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [CSRHarmonySkypePlugin] => C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe [146656 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM\...\Run: [TrayApplication] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe [529616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100419998\...\Run: [] => [X]
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [31624080 2020-03-12] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365160 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Run: [Surfshark] => C:\Program Files (x86)\Surfshark\Surfshark.exe [3765200 2020-03-18] (Surfshark Ltd. -> Surfshark)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\logon.scr
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [31624080 2020-03-12] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365160 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Run: [Surfshark] => C:\Program Files (x86)\Surfshark\Surfshark.exe [3765200 2020-03-18] (Surfshark Ltd. -> Surfshark)
HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\logon.scr
HKU\S-1-5-21-1116177293-2918626760-3563952597-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100421630\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-07] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{5355DA8C-FE32-49b4-A567-A67535C86592}] -> C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BLEtokenCredentialProvider.dll [2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {174239E7-F727-4138-9A08-8F458BEE6514} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1F978473-5C7D-416E-B248-A08DE3FA42F1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {2583886E-7684-46B9-B9A7-C962B30CF3F2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {2646877B-F366-45C9-8C00-594080E969E0} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1116177293-2918626760-3563952597-500 => C:\Users\ubers\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {5BF3F651-05C5-40A6-9C2A-103FDA2C7EA0} - System32\Tasks\Opera scheduled assistant Autoupdate 1569362109 => C:\Users\ubers\AppData\Local\Programs\Opera\launcher.exe
Task: {709EE3FB-2B9E-4D87-85E6-2B5956D55009} - System32\Tasks\Opera scheduled Autoupdate 1569362099 => C:\Users\ubers\AppData\Local\Programs\Opera\launcher.exe
Task: {74D8ADE8-49DA-4403-ADE8-E7D177CEA4A2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {897AC3C3-F8E0-4AD8-A80D-0514390B41DA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {A6D78204-1734-48E7-946A-C6069FBE5304} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {C071F7CA-A069-4268-BD6A-A25E93756E62} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-14] (Google Inc -> Google Inc.)
Task: {EFAAE3A7-7672-4360-BE4A-634C890F105C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-02-14] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{186038a2-c246-434c-96d4-33c417a772d9}: [NameServer] 162.252.172.57,149.154.159.92
Tcpip\..\Interfaces\{186038a2-c246-434c-96d4-33c417a772d9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{88fd77a8-c10d-457c-b970-67ac2b6057e1}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{dac507a2-e1f0-4b3a-8e57-3361b4f6b8f2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fd53961b-5375-44b1-9bf9-5786dbd3dc7f}: [DhcpNameServer] 162.252.172.57 149.154.159.92

Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2019-01-29] (Logitech Inc -> Logitech, Inc.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2019-01-29] (Logitech Inc -> Logitech, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-01-19] (Skype Technologies SA -> Skype Technologies)

Edge:
======
DownloadDir: C:\Users\ubers\Downloads
Edge Notifications: HKU\S-1-5-21-1116177293-2918626760-3563952597-1002 -> hxxps://forums.playbattlegrounds.com; hxxps://www.inverse.com
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.19.0_neutral__d55gg7py3s0m0 [2020-02-18]

FireFox:
========
FF DefaultProfile: rnwyvsyl.default
FF ProfilePath: C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default [2020-04-10]
FF Homepage: Mozilla\Firefox\Profiles\rnwyvsyl.default -> hxxps://www.bing.com/
FF Notifications: Mozilla\Firefox\Profiles\rnwyvsyl.default -> hxxps://www.youtube.com; hxxps://www.facebook.com; hxxps://mail.google.com; hxxps://ew.com
FF Extension: (Facebook Container) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\@contain-facebook.xpi [2020-03-10]
FF Extension: (Dark Reader) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\addon@darkreader.org.xpi [2020-03-30]
FF Extension: (convert2mp3.net Online Video Converter) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\info@convert2mp3.net.xpi [2019-04-24]
FF Extension: (AdBlock) - C:\Users\ubers\AppData\Roaming\Mozilla\Firefox\Profiles\rnwyvsyl.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2020-02-05]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2019-04-29] [not signed]
FF HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\ubers\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\ubers\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default [2020-04-07]
CHR Extension: (Slides) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-14]
CHR Extension: (Docs) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-14]
CHR Extension: (Google Drive) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-14]
CHR Extension: (YouTube) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-14]
CHR Extension: (Sheets) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-14]
CHR Extension: (Google Docs Offline) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-10-29]
CHR Extension: (Ace Script) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2019-10-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-29]
CHR Extension: (Gmail) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-10-29]
CHR Extension: (Chrome Media Router) - C:\Users\ubers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-29]
CHR HKU\S-1-5-21-1116177293-2918626760-3563952597-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]
CHR HKU\S-1-5-21-1116177293-2918626760-3563952597-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100422936\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6998536 2017-12-08] (BattlEye Innovations e.K. -> )
R2 BtSwitcherService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe [64216 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CSRBtAudioService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe [465624 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CsrBtOBEXService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe [1041616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R2 CsrBtService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe [825032 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4506728 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [784512 2019-05-27] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-03-11] (Malwarebytes Inc -> Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2466608 2019-11-19] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3344176 2019-11-19] (Electronic Arts, Inc. -> Electronic Arts)
S2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [16766008 2020-04-01] (Adlice -> )
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 Surfshark Service; C:\Program Files (x86)\Surfshark\Resources\x64\nssm.exe [436688 2020-02-17] (Surfshark Ltd. -> Iain Patterson)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [45832 2019-10-01] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [24424 2016-08-13] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [137496 2018-09-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-18] (ASUSTeK Computer Inc. -> )
R3 athur; C:\WINDOWS\System32\drivers\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 csravrcp; C:\WINDOWS\System32\drivers\csravrcp.sys [26304 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 CsrBthAudioHF; C:\WINDOWS\system32\DRIVERS\CsrBthAudioHF.sys [39120 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 CsrBtPort; C:\WINDOWS\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrhfgcc; C:\WINDOWS\System32\drivers\csrhfgcc.sys [38080 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrpan; C:\WINDOWS\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrserial; C:\WINDOWS\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrusb; C:\WINDOWS\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csrusbfilter; C:\WINDOWS\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 csr_bthav; C:\WINDOWS\system32\drivers\csrbthav.sys [99520 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-01-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-07] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-07] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-09] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2020-04-09] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-09] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [119960 2020-04-09] (Malwarebytes Inc -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\nvlddmkm.sys [23439288 2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [947712 2017-02-20] (Realtek Semiconductor Corp. -> Realtek )
S3 SurfsharkSplitTunnelDriver; C:\Program Files (x86)\Surfshark\Resources\x64\SurfsharkSplitTunnelCalloutDriver.sys [39648 2020-02-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 tapsurfshark; C:\WINDOWS\System32\drivers\tapsurfshark.sys [38728 2019-05-22] (WDKTestCert Lenovo,131775874531219913 -> The OpenVPN Project)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2019-12-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2019-12-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-10] (Microsoft Windows -> Microsoft Corporation)
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-04-10 10:05 - 2020-04-10 10:09 - 000029300 _____ C:\Users\ubers\Downloads\FRST.txt
2020-04-09 10:47 - 2020-04-09 10:47 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-09 10:47 - 2020-04-09 10:47 - 000119960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-09 10:47 - 2020-04-09 10:47 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-04-09 10:46 - 2020-04-09 10:46 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-09 10:46 - 2020-04-09 10:46 - 000028272 _____ C:\WINDOWS\system32\Drivers\truesight.sys
2020-04-09 10:44 - 2020-04-09 10:44 - 000024066 _____ C:\Users\ubers\Desktop\as_E140.tmp.txt
2020-04-09 10:39 - 2020-04-09 10:43 - 000000000 ____D C:\AdwCleaner
2020-04-08 21:52 - 2020-04-08 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2020-04-08 21:52 - 2020-04-08 21:52 - 000000000 ____D C:\Program Files\RogueKiller
2020-04-08 21:51 - 2020-04-08 21:57 - 000000000 ____D C:\ProgramData\RogueKiller
2020-04-08 21:49 - 2020-04-08 21:49 - 047857952 _____ (Adlice Software ) C:\Users\ubers\Downloads\RogueKiller_setup_ref3.exe
2020-04-08 14:14 - 2020-04-10 10:07 - 000000000 ____D C:\FRST
2020-04-08 14:14 - 2020-04-08 14:14 - 002281472 _____ (Farbar) C:\Users\ubers\Downloads\FRST64.exe
2020-04-07 21:46 - 2020-04-07 21:46 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-07 21:04 - 2020-03-31 13:05 - 000454790 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20200407-210437.backup
2020-03-31 13:05 - 2020-03-04 12:33 - 000454790 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20200331-130545.backup
2020-03-30 21:29 - 2020-03-30 21:29 - 000000000 ____D C:\Users\ubers\AppData\Local\NVIDIA
2020-03-26 11:16 - 2020-04-10 10:02 - 000000000 ____D C:\Users\ubers\AppData\Local\Spotify
2020-03-26 11:16 - 2020-03-26 11:16 - 000001881 _____ C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2020-03-25 18:22 - 2020-03-25 18:22 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2020-03-25 18:20 - 2020-03-18 05:39 - 000222112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-03-25 18:20 - 2020-03-18 05:39 - 000039824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2020-03-25 18:17 - 2020-03-18 19:23 - 005589224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-03-25 18:16 - 2020-03-18 22:22 - 004927048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-03-25 18:16 - 2020-03-18 22:22 - 004196160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-03-25 18:16 - 2020-03-18 19:26 - 001078992 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 001078992 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000450464 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-03-25 18:16 - 2020-03-18 19:26 - 000348048 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-03-25 18:16 - 2020-03-18 19:25 - 011944864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2020-03-25 18:16 - 2020-03-18 19:25 - 010285472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 002073200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001565136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001481144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001351776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001142384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 001022560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000817264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000680048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000676240 _____ C:\WINDOWS\system32\nvofapi64.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000573024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2020-03-25 18:16 - 2020-03-18 19:24 - 000546928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2020-03-25 18:16 - 2020-03-18 19:24 - 000544144 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 017601120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 015157664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 005856864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 005158512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 001049696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000849848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2020-03-25 18:16 - 2020-03-18 19:23 - 000811632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000655472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2020-03-25 18:16 - 2020-03-18 19:23 - 000445024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2020-03-25 18:16 - 2020-03-18 05:39 - 000111058 _____ C:\WINDOWS\system32\nvidia-smi.1.pdf
2020-03-25 18:16 - 2020-03-18 05:39 - 000077314 _____ C:\WINDOWS\system32\nvinfo.pb
2020-03-22 20:21 - 2020-03-22 20:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Surfshark
2020-03-11 01:32 - 2020-03-11 01:32 - 011723776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 003550624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 002469432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 002323688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001707208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001605000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001288648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 001076040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-03-11 01:32 - 2020-03-11 01:32 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 019020288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 013013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 012306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 008907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 007870976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 005436904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004664320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 004066816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003952760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003909632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002751336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002273296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002182456 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002150912 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 002100056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001876960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001750528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001430880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001296360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001229824 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001201128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 001062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000946688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000796160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000763032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000522104 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-03-11 01:31 - 2020-03-11 01:31 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.PredictionUnit.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provsvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFIPP.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000263576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSHExtensions.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-03-11 01:31 - 2020-03-11 01:31 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactHarvesterDS.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-03-11 01:31 - 2020-03-11 01:31 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
 
2020-03-11 01:31 - 2020-03-11 01:31 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2020-03-11 01:31 - 2020-03-11 01:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 015220224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006545096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006445056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005915936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005309080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005210896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 004344832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003873704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003429888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Controls.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 003096064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002779272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002698752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002349056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002279296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 002264344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001862656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001761280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001759232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001693696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001678800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001674696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001668752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001606144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001590072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001573480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001495480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001465264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001458056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001427592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001294336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001292800 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001278808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001272360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 001223168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001222456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001162088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001125392 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001122304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001098128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000964984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000934912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000926056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000909624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000828728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000821760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000805504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000791864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000774968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000718944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000661304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000651264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000648392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000622632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000574864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000555440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000542536 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000515448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000492216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000473832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000461488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIso.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UiaManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000453208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000439976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2020-03-11 01:30 - 2020-03-11 01:30 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000408528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000373560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000366728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000312632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000279416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000277840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000267264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockScreenData.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000264208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationManager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000252264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\feclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000243216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchangeHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000239664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000219656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Cortana.Persona.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2020-03-11 01:30 - 2020-03-11 01:30 - 000205312 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\feclient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000176112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000175928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpcsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddisplay.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000157536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.OneCore.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Sockets.PushEnabledApplication.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oledlg.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000140304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000139648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000124440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DSCache.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\efslsaext.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000108392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Display.DisplayEnhancementOverride.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olecli32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000107008 _____ C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olethk32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000106048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000105784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000094496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerHost.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvHelper.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000074752 ____R (Microsoft Corporation) C:\WINDOWS\system32\mdmpostprocessevaluator.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpussvr.exe
2020-03-11 01:30 - 2020-03-11 01:30 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.internal.shellcommon.AccountsControlExperience.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvHelper.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olesvr32.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFrameworkInternalPS.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.SystemManufacturers.dll
2020-03-11 01:30 - 2020-03-11 01:30 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 022137120 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 009672208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 006942720 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 005575168 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004736512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004589056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 004303872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 004018688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 003636736 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 003630592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 003490304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002981888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002917688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002701816 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 002627088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 002074984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001962296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 001961984 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001890816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001837136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001753088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001751640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001702600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-03-11 01:29 - 2020-03-11 01:29 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001568768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001473080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001390888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001360912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001346192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-03-11 01:29 - 2020-03-11 01:29 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001287072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001262592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001183504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 001169920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 001012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
 
2020-03-11 01:29 - 2020-03-11 01:29 - 001001472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000998928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000930816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000872960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000745472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000736272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.ComposerFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000678376 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000655160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000641696 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000620032 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000581632 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000501760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000420352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneDataSync.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000409912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvctpSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenData.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000363320 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvrcp.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000320728 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Cortana.Persona.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000274448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposerFramework.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000262336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2020-03-11 01:29 - 2020-03-11 01:29 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ManagePhone.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000240376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.Desktop.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeopleBand.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.DesktopHosting.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\oledlg.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.CredentialProvider.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ContentDeliveryManager.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000168488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.SettingsExtensibility.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsExtensibilityHandlers.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000134456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000132480 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredDialogBroker.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopShellExt.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MuiUnattend.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2020-03-11 01:29 - 2020-03-11 01:29 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000090608 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PersonalizationCSP.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsCtfMonitor.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\desktopimgdownldr.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000072984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrameHost.exe
2020-03-11 01:29 - 2020-03-11 01:29 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2020-03-11 01:29 - 2020-03-11 01:29 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe
2020-03-11 01:28 - 2020-03-11 01:29 - 001478968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007888896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 007556600 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 006058032 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005577872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005528576 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 005301248 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 004853760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Controls.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 004417008 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 003361080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002848768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002634752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002620928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002611136 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002437344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002433024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002418176 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 002233856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002197504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002185216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002086192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 002050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001929728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001844456 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001830712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001796400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001794048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001768960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001720320 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001701384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001422336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001335296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001308672 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001287584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001194496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001081656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 001052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 001049600 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001038336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001035264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001021952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000987736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000984888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000938296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000903368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000890400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000882176 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000862224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 000848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000847872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000818640 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000780408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000741688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000723456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000681416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\UiaManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000650240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000622336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000605576 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2020-03-11 01:28 - 2020-03-11 01:28 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxAPDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000510504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxHAPDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000468792 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtCangjieDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtBopomofoDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtHkStrokeDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChsStrokeDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtQuickDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000451120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000446480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000443368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000439096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-03-11 01:28 - 2020-03-11 01:28 - 000437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000418576 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000399376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000390128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000386360 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000377344 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpndecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000376784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxDecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnclient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxinputrouter.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000347784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.shareexperience.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtfDecoder.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000314072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000312704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayServer.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000293856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpnranker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000282424 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_InputPersonalization.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiCloudStore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000262656 _____ C:\WINDOWS\system32\HeatCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000239120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Devices.Sensors.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000213816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddisplay.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\useractivitybroker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000200720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000199680 _____ C:\WINDOWS\system32\IHDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000193552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Sockets.PushEnabledApplication.dll
 
2020-03-11 01:28 - 2020-03-11 01:28 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000163448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingCSP.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFFuzzyDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000152576 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\vfuprov.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000149240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Display.DisplayEnhancementOverride.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DSCache.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000147944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdvancedEmojiDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\StaticDictDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000133432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000125440 _____ C:\WINDOWS\system32\WindowsDefaultHeatProcessor.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000121536 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerHost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxranker.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HashtagDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sihost.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFSpellcheckDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000106296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFAppServiceDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000099896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuntimeBroker.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpnUserService.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuleBasedDS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.AccountsControlExperience.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-03-11 01:28 - 2020-03-11 01:28 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityServicePal.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-03-11 01:28 - 2020-03-11 01:28 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.SystemManufacturers.dll
2020-03-11 01:27 - 2020-03-11 01:28 - 000442880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 007700480 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 004997096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 003581440 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 003334496 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002707456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 002590944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002466816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002149160 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002015400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 002004992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001771824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001743376 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001677312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001674752 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001519488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001496576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001387512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001293768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001258296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 001205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 001049400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000988240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000904104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000902464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000902144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000871792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000863528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000769760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000680944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000667664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000652304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000650552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000532184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-03-11 01:27 - 2020-03-11 01:27 - 000461840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000438784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SDDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000407712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingASDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000385552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000367208 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000298808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000283240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000276496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000255128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmBroker.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000252944 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wosc.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.OneCore.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000222008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000193336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Security.Attestation.DeviceAttestation.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000149488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000141728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000130872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000118472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvEmulation.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvPlatform.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000109704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialUIBroker.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000103952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-03-11 01:27 - 2020-03-11 01:27 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingFilterDS.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MuiUnattend.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2020-03-11 01:27 - 2020-03-11 01:27 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsCtfMonitor.dll
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-03-11 01:27 - 2020-03-11 01:27 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2099-11-18 18:48 - 2019-02-22 02:25 - 000000000 ____D C:\Users\Administrator
2020-04-10 10:06 - 2019-10-31 23:24 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-04-10 10:03 - 2018-04-17 19:47 - 000000000 ____D C:\Users\ubers\AppData\LocalLow\Mozilla
2020-04-10 10:02 - 2019-02-22 02:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-10 10:02 - 2018-10-30 18:16 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Spotify
2020-04-10 10:02 - 2018-09-15 03:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-10 10:02 - 2017-12-06 08:48 - 000000000 ____D C:\Program Files (x86)\Steam
2020-04-09 17:52 - 2020-02-10 14:12 - 000000000 ____D C:\Games
2020-04-09 10:54 - 2019-02-22 02:37 - 000840852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-09 10:52 - 2018-09-15 03:31 - 000000000 ____D C:\WINDOWS\INF
2020-04-09 10:49 - 2018-09-15 03:33 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-09 10:49 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-09 10:46 - 2019-07-09 11:53 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2020-04-09 10:46 - 2019-02-22 02:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-09 10:45 - 2018-09-15 02:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-09 10:44 - 2020-03-10 22:44 - 000018099 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1
2020-04-09 10:44 - 2020-03-10 22:44 - 000012311 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1
2020-04-09 10:44 - 2020-03-10 22:44 - 000011839 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1
2020-04-09 10:43 - 2020-03-10 22:44 - 000001209 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1
2020-04-09 10:43 - 2019-09-24 17:55 - 000000000 ____D C:\Users\ubers\AppData\Local\Lavasoft
2020-04-09 10:43 - 2019-09-24 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2020-04-09 10:18 - 2019-09-24 17:55 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Lavasoft
2020-04-09 10:18 - 2019-09-24 17:54 - 000000000 ____D C:\ProgramData\Lavasoft
2020-04-09 10:18 - 2019-09-24 17:54 - 000000000 ____D C:\Program Files (x86)\Lavasoft
2020-04-07 21:46 - 2019-07-22 21:07 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-07 19:56 - 2019-06-13 03:54 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-07 19:32 - 2018-04-17 19:47 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-07 14:50 - 2019-10-29 16:02 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-07 14:50 - 2019-10-29 16:02 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-07 14:50 - 2018-02-14 19:16 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-06 22:50 - 2018-04-17 19:47 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-04-04 15:36 - 2019-02-22 02:44 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-04-03 14:33 - 2019-05-31 10:50 - 000000000 ____D C:\Users\ubers\OneDrive\Documents\BeerSmith2
2020-04-01 15:35 - 2019-11-15 02:39 - 000000000 ____D C:\WINDOWS\Panther
2020-04-01 13:52 - 2019-02-22 02:42 - 000028578 _____ C:\WINDOWS\diagwrn.xml
2020-04-01 13:52 - 2019-02-22 02:42 - 000028578 _____ C:\WINDOWS\diagerr.xml
2020-04-01 10:25 - 2018-09-15 02:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-04-01 09:46 - 2019-03-19 03:02 - 000000000 ___HD C:\$WINDOWS.~BT
2020-03-30 21:26 - 2017-10-17 12:33 - 000000000 ____D C:\ProgramData\Package Cache
2020-03-30 21:22 - 2020-02-10 18:57 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2020-03-30 21:19 - 2020-02-10 18:58 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2020-03-25 18:22 - 2017-10-17 12:34 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-03-25 18:12 - 2017-12-06 09:00 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-03-25 00:05 - 2020-03-10 16:36 - 000000000 ____D C:\Users\ubers\AppData\Roaming\qBittorrent
2020-03-24 20:01 - 2017-12-05 20:08 - 000000000 ____D C:\Users\ubers\AppData\Local\Publishers
2020-03-22 21:27 - 2018-05-17 19:39 - 000000000 ____D C:\Users\ubers\AppData\Local\D3DSCache
2020-03-22 20:22 - 2020-02-12 01:13 - 000000000 ____D C:\Users\ubers\AppData\Roaming\Surfshark
2020-03-22 20:21 - 2020-02-20 18:57 - 000001018 _____ C:\Users\Public\Desktop\Surfshark.lnk
2020-03-22 20:21 - 2020-02-20 18:57 - 000001018 _____ C:\ProgramData\Desktop\Surfshark.lnk
2020-03-22 20:21 - 2020-02-12 01:14 - 000000000 ____D C:\Program Files (x86)\Surfshark
2020-03-22 10:49 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-03-20 22:08 - 2019-02-22 02:44 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 22:08 - 2019-02-22 02:44 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-17 12:39 - 2020-03-04 11:57 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-17 12:38 - 2020-03-04 11:57 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-12 18:48 - 2019-10-29 17:28 - 000000000 ____D C:\Program Files\Epic Games
2020-03-11 10:56 - 2019-07-22 21:07 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-03-11 10:56 - 2019-07-22 21:07 - 000002021 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-03-11 10:53 - 2019-07-22 21:07 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-03-11 10:42 - 2017-12-06 08:36 - 000000000 ___RD C:\Users\ubers\3D Objects
2020-03-11 10:42 - 2017-10-17 12:29 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-03-11 10:39 - 2019-02-22 02:18 - 000290376 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-03-11 10:35 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\setup
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-03-11 10:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-03-11 10:34 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ___RD C:\Program Files\Windows Defender
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-03-11 10:33 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-03-11 10:33 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\servicing
2020-03-11 01:40 - 2017-12-05 21:59 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-03-11 01:37 - 2018-09-15 03:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-03-11 01:37 - 2017-12-05 21:58 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
 
Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST(FRST64) and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
 

Attachments

  • fixlist.txt
    1.2 KB · Views: 4
Sorry for the late reply, been away from home.


Fix result of Farbar Recovery Scan Tool (x64) Version: 13-04-2020
Ran by ubers (13-04-2020 19:43:12) Run:1
Running from C:\Users\ubers\Downloads
Loaded Profiles: ubers (Available Profiles: ubers & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
AlternateDataStreams: C:\Users\ubers\OneDrive:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity [130]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\BeerSmith2:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\desktop.ini:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\Forward Brewing Cover Letter.doc:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [66]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\League of Legends:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\ubers\OneDrive\Documents\TunesKit Spotify Converter:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100419998\...\Run: [] => [X]
HKU\S-1-5-18\...\Run: [] => [X]
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]

*****************

C:\Users\ubers\OneDrive => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity" ADS could not remove.
C:\Users\ubers\OneDrive\Documents\BeerSmith2 => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\ubers\OneDrive\Documents\desktop.ini => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\ubers\OneDrive\Documents\Forward Brewing Cover Letter.doc => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\ubers\OneDrive\Documents\League of Legends => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
C:\Users\ubers\OneDrive\Documents\TunesKit Spotify Converter => ":${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata" ADS removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04102020100419998\...\Run: [] => [X] => Error ({ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}): No automatic fix found for this entry.
"HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\System\CurrentControlSet\Services\nvvad_WaveExtensible => removed successfully
nvvad_WaveExtensible => service removed successfully
HKLM\System\CurrentControlSet\Services\nvvhci => removed successfully
nvvhci => service removed successfully

==== End of Fixlog 19:43:12 ====
 
Last scans...

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
Make sure the following options are checked:
  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center
  • Windows Update
  • Windows Defender
  • Other Services

Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.


redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


redtarget.gif
Download Sophos Free Virus Removal Tool and save it to your desktop.
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
 
I tried running the Security Check program a few times, it says the check is complete but doesn't open or save a text log anywhere.

Below is the FSS log

Farbar Service Scanner Version: 14-12-2019
Ran by ubers (administrator) on 14-04-2020 at 10:45:23
Running from "C:\Users\ubers\Downloads"
Microsoft Windows 10 Home (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Security Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: ""C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe"".


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****

The Sophos tool found no viruses.
 
Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
[COLOR=#ff0000][B]This is a very crucial step so make sure you don't skip it.[/B][/COLOR]
Download [IMG]http://www.imgdumper.nl/uploads6/51a5ce45267c1/51a5ce45263de-delfix.pngDelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

5. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

6. Run Temporary File Cleaner (TFC) and AdwCleaner weekly (you need to redownload these tools since they were removed by DelFix).

7. (optional) If you want to keep all your programs up to date, download and install FileHippo App Manager.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

8. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

9. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

10. Please, let me know, how your computer is doing.
 
Back