Thanks! I've done the scan with the Farbar Recovery Tool and here are the logs.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-12-2017
Ran by cacaR (administrator) on DESKTOP-TVF40JE (31-12-2017 11:06:49)
Running from C:\Users\cacaR\Downloads
Loaded Profiles: cacaR (Available Profiles: cacaR)
Platform: Windows 10 Home Version 1709 16299.64 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(f.lux Software LLC) C:\Users\cacaR\AppData\Local\FluxSoftware\Flux\flux.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-31] (AVAST Software)
HKU\S-1-5-21-4118052371-3421211454-4028698306-1001\...\Run: [f.lux] => C:\Users\cacaR\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{6062ffcd-d8b2-4ac2-bf41-203fdb74cad3}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKU\S-1-5-21-4118052371-3421211454-4028698306-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ca.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
FireFox:
========
FF DefaultProfile: ijwwuihp.default
FF ProfilePath: C:\Users\cacaR\AppData\Roaming\Mozilla\Firefox\Profiles\ijwwuihp.default [2017-12-31]
FF Extension: (AdBlock) - C:\Users\cacaR\AppData\Roaming\Mozilla\Firefox\Profiles\ijwwuihp.default\Extensions\
[email protected] [2017-12-31]
FF Extension: (Avast Online Security) - C:\Users\cacaR\AppData\Roaming\Mozilla\Firefox\Profiles\ijwwuihp.default\Extensions\
[email protected] [2017-12-31]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-31] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-31] (AVAST Software)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [185096 2017-12-31] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [321512 2017-12-31] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [199448 2017-12-31] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343768 2017-12-31] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57696 2017-12-31] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [149344 2017-12-31] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2017-12-31] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [146664 2017-12-31] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110336 2017-12-31] (AVAST Software)
S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84384 2017-12-31] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1025176 2017-12-31] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [457400 2017-12-31] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [204456 2017-12-31] (AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [358672 2017-12-31] (AVAST Software)
S3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [54256 2016-12-10] (Corsair)
S3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [29168 2016-12-10] (Corsair)
U1 lpsport; C:\Windows\System32\Drivers\lpsport.sys [61304 2017-12-31] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c791f781cd94491f\nvlddmkm.sys [16989296 2017-11-15] (NVIDIA Corporation)
S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [26560 2017-10-10] (Windows (R) Win 7 DDK provider)
S3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-11-14] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
S3 ssbthid; C:\WINDOWS\System32\drivers\ssbthid.sys [43824 2017-12-15] ()
S3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [46896 2017-12-15] ()
R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [46896 2017-12-15] ()
S3 STTub30; C:\WINDOWS\System32\Drivers\STTub30.sys [54104 2017-08-30] (STMicroelectronics)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-31 11:06 - 2017-12-31 11:07 - 000007661 _____ C:\Users\cacaR\Downloads\FRST.txt
2017-12-31 11:05 - 2017-12-31 11:06 - 000000000 ____D C:\FRST
2017-12-31 11:05 - 2017-12-31 11:05 - 000000000 ____D C:\Users\cacaR\Downloads\FRST-OlderVersion
2017-12-31 11:04 - 2017-12-31 11:05 - 002392064 _____ (Farbar) C:\Users\cacaR\Downloads\FRST64.exe
2017-12-31 11:00 - 2017-12-31 11:00 - 000000000 ____D C:\Users\cacaR\AppData\Local\AVAST Software
2017-12-31 10:59 - 2017-12-31 10:59 - 000000000 ____D C:\Users\cacaR\AppData\Roaming\AVAST Software
2017-12-31 10:59 - 2017-12-31 10:59 - 000000000 ____D C:\Users\cacaR\AppData\Local\CEF
2017-12-31 10:59 - 2017-12-31 10:59 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-12-31 10:58 - 2017-12-31 10:58 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-12-31 10:58 - 2017-12-31 10:58 - 000003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-12-31 10:58 - 2017-12-31 10:58 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2017-12-31 10:58 - 2017-12-31 10:58 - 000001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-12-31 10:58 - 2017-12-31 10:58 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software
2017-12-31 10:58 - 2017-12-31 10:58 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2017-12-31 10:54 - 2017-12-31 10:53 - 001025176 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000457400 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000358672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000343768 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000321512 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000204456 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000199448 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000185096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000149344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000146664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000110336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000084384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000057696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-12-31 10:54 - 2017-12-31 10:53 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-12-31 10:53 - 2017-12-31 10:53 - 000365680 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-12-31 10:52 - 2017-12-31 10:40 - 000545440 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-12-31 10:51 - 2017-12-31 10:53 - 000000000 ____D C:\ProgramData\AVAST Software
2017-12-31 10:51 - 2017-12-31 10:51 - 006334848 _____ (AVAST Software) C:\Users\cacaR\Downloads\avast_free_antivirus_setup.exe
2017-12-31 10:51 - 2017-12-31 10:51 - 000000039 _____ C:\Users\cacaR\Downloads\Stats.ini
2017-12-31 10:51 - 2017-12-31 10:51 - 000000000 ____D C:\Users\cacaR\AppData\Local\Comms
2017-12-31 10:51 - 2017-12-31 10:51 - 000000000 ____D C:\Program Files\AVAST Software
2017-12-31 10:50 - 2017-12-31 10:52 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-31 10:50 - 2017-12-31 10:50 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-31 10:49 - 2017-12-31 10:49 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-31 10:39 - 2017-12-31 10:39 - 000002160 _____ C:\Users\cacaR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2017-12-31 10:39 - 2017-12-31 10:39 - 000000000 ____D C:\Users\cacaR\AppData\Local\FluxSoftware
2017-12-31 10:38 - 2017-12-31 10:39 - 000766552 _____ C:\Users\cacaR\Downloads\flux-setup.exe
2017-12-31 10:37 - 2017-12-31 10:41 - 000000000 ____D C:\Users\cacaR\AppData\Local\Mozilla
2017-12-31 10:37 - 2017-12-31 10:37 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-12-31 10:37 - 2017-12-31 10:37 - 000000993 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-12-31 10:37 - 2017-12-31 10:37 - 000000000 ____D C:\Users\cacaR\AppData\Roaming\Mozilla
2017-12-31 10:37 - 2017-12-31 10:37 - 000000000 ____D C:\Users\cacaR\AppData\LocalLow\Mozilla
2017-12-31 10:37 - 2017-12-31 10:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-12-31 10:37 - 2017-12-31 10:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-31 10:36 - 2017-12-31 10:36 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4118052371-3421211454-4028698306-1001
2017-12-31 10:36 - 2017-12-31 10:36 - 000000000 ___HD C:\OneDriveTemp
2017-12-31 10:36 - 2015-01-02 22:29 - 000000174 _____ C:\Users\cacaR\OneDrive\Documents\Passwords.txt
2017-12-31 10:35 - 2017-12-31 10:36 - 000002367 _____ C:\Users\cacaR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-12-31 10:35 - 2017-12-31 10:36 - 000000000 ___RD C:\Users\cacaR\OneDrive
2017-12-31 10:35 - 2017-12-31 10:35 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-12-31 10:33 - 2017-12-31 10:51 - 000000000 ____D C:\Users\cacaR\AppData\Local\PackageStaging
2017-12-31 10:33 - 2017-12-31 10:51 - 000000000 ____D C:\Users\cacaR\AppData\Local\Packages
2017-12-31 10:33 - 2017-12-31 10:34 - 000000000 ____D C:\Users\cacaR\AppData\Local\ConnectedDevicesPlatform
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ___RD C:\Users\cacaR\3D Objects
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ___HD C:\Users\cacaR\MicrosoftEdgeBackups
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ____D C:\Users\cacaR\AppData\Roaming\Adobe
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ____D C:\Users\cacaR\AppData\Local\VirtualStore
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ____D C:\Users\cacaR\AppData\Local\Publishers
2017-12-31 10:33 - 2017-12-31 10:33 - 000000000 ____D C:\Users\cacaR\AppData\Local\MicrosoftEdge
2017-12-31 10:31 - 2017-12-31 10:35 - 000000000 ____D C:\Users\cacaR
2017-12-31 10:31 - 2017-12-31 10:31 - 000000020 ___SH C:\Users\cacaR\ntuser.ini
2017-12-31 07:24 - 2017-12-31 07:24 - 000000000 _SHDL C:\Users\Default User
2017-12-31 07:24 - 2017-12-31 07:24 - 000000000 _SHDL C:\Users\All Users
2017-12-31 07:24 - 2017-12-31 07:24 - 000000000 _SHDL C:\Documents and Settings
2017-12-31 07:17 - 2017-12-31 10:33 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-31 07:17 - 2017-12-31 07:17 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-12-31 07:17 - 2017-12-31 07:17 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-12-31 07:17 - 2017-12-31 07:17 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-12-31 07:17 - 2017-11-14 15:15 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-12-31 07:17 - 2017-11-14 14:56 - 005960640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 002587584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 001766336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 000607352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 000449472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 000123000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-12-31 07:17 - 2017-11-14 14:56 - 000082040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-12-31 07:17 - 2017-11-10 01:09 - 007855841 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-12-31 07:14 - 2017-12-31 10:29 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-12-31 07:14 - 2017-12-31 07:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-12-31 07:14 - 2017-12-31 07:14 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-12-31 07:13 - 2017-12-31 07:14 - 000222832 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-12-31 04:34 - 2017-12-31 04:34 - 000000000 ____D C:\ProgramData\USOShared
2017-12-31 04:28 - 2017-12-31 04:28 - 000886066 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-12-31 04:26 - 2017-09-29 08:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-12-31 02:20 - 2017-12-31 02:20 - 000000000 ____D C:\WINDOWS\InfusedApps
2017-12-31 02:19 - 2017-12-31 02:33 - 000000000 ____D C:\Windows.old
2017-12-31 02:19 - 2017-12-31 02:19 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2017-12-31 02:18 - 2017-12-31 02:18 - 000000000 ____D C:\WINDOWS\Setup
2017-12-31 02:18 - 2017-12-31 02:18 - 000000000 ____D C:\Program Files (x86)\Razer
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\te-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\si-LK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\or-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\km-KH
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\is-IS
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\id-ID
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\be-BY
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\as-IN
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\am-ET
2017-12-31 02:16 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\OCR
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\Program Files\MSBuild
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-12-31 02:16 - 2017-12-31 02:16 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\winrm
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\WCN
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\slmgr
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\0409
2017-12-31 02:14 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\DigitalLocker
2017-12-31 02:11 - 2017-12-03 17:38 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-12-31 02:11 - 2017-12-03 17:38 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-12-31 02:09 - 2017-12-31 11:07 - 000000000 ___HD C:\Program Files\WindowsApps
2017-12-31 02:09 - 2017-12-31 11:07 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-12-31 02:09 - 2017-12-31 11:06 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2017-12-31 02:09 - 2017-12-31 10:37 - 000000000 ___RD C:\Program Files (x86)
2017-12-31 02:09 - 2017-12-31 07:22 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2017-12-31 02:09 - 2017-12-31 07:22 - 000000000 ____D C:\WINDOWS\appcompat
2017-12-31 02:09 - 2017-12-31 07:18 - 000000000 ___RD C:\WINDOWS\PrintDialog
2017-12-31 02:09 - 2017-12-31 07:18 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-12-31 02:09 - 2017-12-31 04:34 - 000000000 ____D C:\ProgramData\USOPrivate
2017-12-31 02:09 - 2017-12-31 04:27 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-12-31 02:09 - 2017-12-31 04:27 - 000000000 ____D C:\WINDOWS\rescache
2017-12-31 02:09 - 2017-12-31 04:26 - 000000000 ____D C:\WINDOWS\system32\spool
2017-12-31 02:09 - 2017-12-31 04:26 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-12-31 02:09 - 2017-12-31 02:19 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\TextInput
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\Dism
2017-12-31 02:09 - 2017-12-31 02:17 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-12-31 02:09 - 2017-12-31 02:16 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\com
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\setup
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\system32\com
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\IME
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\Help
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files\Windows Defender
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files\Common Files\system
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-12-31 02:09 - 2017-12-31 02:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 __SHD C:\Program Files\Windows Sidebar
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 __RSD C:\WINDOWS\media
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 __RHD C:\Users\Public\Libraries
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\system32\UNP
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\system32\Nui
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Web
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Vss
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\tracing
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\TAPI
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SystemResources
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SystemApps
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\winevt
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\ras
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\IME
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\icsxml
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\ias
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\hydrogen
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\downlevel
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\DDFs
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\System
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SKB
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\security
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\schemas
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\SchCache
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Resources
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Registration
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Provisioning
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\PLA
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Performance
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\ModemLogs
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\L2Schemas
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\InputMethod
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Globalization
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Cursors
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\Branding
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\bcastdvr
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\addins
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files\Windows Security
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files\Windows Portable Devices
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files\windows nt
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files\Common Files\Services
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files (x86)\windows nt
2017-12-31 02:09 - 2017-12-31 02:09 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-12-31 02:09 - 2017-12-31 02:06 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-12-31 02:09 - 2017-12-31 02:06 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-12-31 02:09 - 2017-12-31 02:06 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2017-12-31 02:09 - 2017-12-31 02:06 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-12-31 02:09 - 2017-12-31 02:06 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-12-31 02:09 - 2017-12-31 02:06 - 000017572 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-12-31 02:09 - 2017-12-31 02:06 - 000004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-12-31 02:09 - 2017-12-31 02:06 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-12-31 02:09 - 2017-12-31 02:06 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-12-31 02:09 - 2017-12-31 02:06 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-12-31 02:09 - 2017-12-31 02:06 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-12-31 02:09 - 2017-12-31 02:06 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-12-31 02:09 - 2017-12-31 02:06 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-12-31 02:09 - 2017-12-31 02:06 - 000000219 _____ C:\WINDOWS\system.ini
2017-12-31 02:09 - 2017-12-31 02:06 - 000000092 _____ C:\WINDOWS\win.ini
2017-12-31 02:07 - 2017-12-31 10:51 - 000000000 ____D C:\WINDOWS\INF
2017-12-31 02:01 - 2017-12-31 10:48 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-12-31 01:57 - 2017-12-31 07:22 - 069730304 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-12-31 01:57 - 2017-12-31 07:22 - 011272192 _____ C:\WINDOWS\system32\config\SYSTEM
2017-12-31 01:57 - 2017-12-31 07:22 - 000524288 _____ C:\WINDOWS\system32\config\DEFAULT
2017-12-31 01:57 - 2017-12-31 07:22 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2017-12-31 01:57 - 2017-12-31 07:22 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY
2017-12-31 01:57 - 2017-12-31 07:15 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-12-31 01:57 - 2017-12-31 04:25 - 000000000 ____D C:\WINDOWS\Panther
2017-12-31 01:57 - 2017-12-31 02:14 - 000000000 ____D C:\WINDOWS\servicing
2017-12-31 01:57 - 2017-12-31 02:12 - 000065536 _____ C:\WINDOWS\system32\config\SAM
2017-12-31 01:57 - 2017-12-31 02:09 - 000000000 ____D C:\WINDOWS\system32\SMI
2017-12-30 22:48 - 2017-12-31 01:57 - 000000000 ___HD C:\$SysReset
2017-12-18 15:55 - 2017-12-07 17:13 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2017-12-13 09:49 - 2017-12-07 17:10 - 001313792 ____N (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-31 02:05 - 2017-09-29 08:40 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys
2017-12-15 14:59 - 2017-08-15 06:29 - 000046896 _____ C:\WINDOWS\system32\Drivers\sshid.sys
2017-12-15 14:59 - 2017-06-01 21:44 - 000046896 _____ C:\WINDOWS\system32\Drivers\ssdevfactory.sys
2017-12-15 14:59 - 2017-05-12 13:48 - 000043824 _____ C:\WINDOWS\system32\Drivers\ssbthid.sys
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-12-31 07:13
==================== End of FRST.txt ============================
(I couldn't upload the addition, it said that it was considered to be spam..)