Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-06-2017 01 Ran by Don (administrator) on DON-PC (16-06-2017 17:43:15) Running from C:\Users\Don\Desktop Loaded Profiles: Don (Available Profiles: Don) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET Security\ekrn.exe (Intel Corporation) C:\Program Files (x86)\Intel\AMT\atchksrv.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (SHADOWDEFENDER.COM) C:\Program Files\Shadow Defender\DefenderDaemon.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\ProgramData\Internet Mobile\OnlineUpdate\ouc.exe (Intel) C:\Program Files (x86)\Intel\AMT\LMS.exe (Intel) C:\Program Files (x86)\Intel\AMT\UNS.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (CyberGhost S.R.L) C:\Program Files (x86)\CyberGhost\CyberGhost.Service.exe (ESET) C:\Program Files\ESET\ESET Security\egui.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Shadow Defender Daemon] => C:\Program Files\Shadow Defender\DefenderDaemon.exe [484344 2016-07-23] (SHADOWDEFENDER.COM) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4022328 2017-05-17] (Tonec Inc.) HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\MountPoints2: {314a402e-319e-11e7-af09-005056c00008} - G:\AutoRun.exe HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\MountPoints2: {bf67ea85-17d6-11e7-9c7c-005056c00008} - D:\AutoRun.exe HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\MountPoints2: {d0713615-33fc-11e7-9566-005056c00008} - G:\AutoRun.exe HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\MountPoints2: {d29ab7c4-4494-11e7-82a5-001e4f9ca9df} - D:\autorun.exe ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.) GroupPolicy: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{1D79AC72-AB39-40C7-8078-D3C5DE3E7704}: [DhcpNameServer] Tcpip\..\Interfaces\{40AE8DDF-0D88-4F1B-AB60-FC3910878AE6}: [DhcpNameServer] Tcpip\..\Interfaces\{6EE58ACB-4A43-4EAA-B932-7EF621A5E68F}: [NameServer] Tcpip\..\Interfaces\{944C45ED-444B-42F1-9294-7D6A84BB504A}: [DhcpNameServer] Internet Explorer: ================== HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp:// BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-10] (Internet Download Manager, Tonec Inc.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-16] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-16] (Oracle Corporation) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-10] (Internet Download Manager, Tonec Inc.) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: qcul5ill.default FF DefaultProfile: 1ddr7ae9.default FF ProfilePath: C:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\qcul5ill.default [2017-06-16] FF Homepage: Mozilla\Firefox\Profiles\qcul5ill.default -> FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\qcul5ill.default\Extensions\ [2017-06-02] FF Extension: (Adblock Plus) - C:\Users\Don\AppData\Roaming\Mozilla\Firefox\Profiles\qcul5ill.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-11] FF ProfilePath: C:\Users\Don\AppData\Roaming\8pecxstudios\Cyberfox\Profiles\1ddr7ae9.default [2017-05-22] FF Extension: (No Name) - C:\Program Files\Cyberfox\browser\features\ [not found] FF HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\Firefox\Extensions: [] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi FF Extension: (No Name) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2017-05-16] FF HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\SeaMonkey\Extensions: [] - C:\Users\Don\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Don\AppData\Roaming\IDM\idmmzcc5 [2017-05-23] [not signed] FF HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\...\SeaMonkey\Extensions: [] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-01-26] FF Plugin: -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_126.dll [2017-06-16] () FF Plugin:,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-16] (Oracle Corporation) FF Plugin:,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-16] (Oracle Corporation) FF Plugin: -> disabled [No File] FF Plugin:,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin:,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_126.dll [2017-06-16] () FF Plugin-x32: -> disabled [No File] FF Plugin-x32:,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-05-22] (Google Inc.) FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-05-22] (Google Inc.) Chrome: ======= CHR StartupUrls: Default -> "hxxp://" CHR Profile: C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default [2017-06-16] CHR Extension: (Google Slides) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-08] CHR Extension: (Flash Video Downloader) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2017-05-08] CHR Extension: (Google Docs) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-08] CHR Extension: (Google Sheets) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-08] CHR Extension: (Google Docs Offline) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-08] CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2017-06-02] CHR Extension: (Video Downloader Pro) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilppkoakomgpcblpemgbloapenijdcho [2017-06-02] CHR Extension: (BrowserStack Local) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfiddfehmfdojjfdpfngagldgaaafcfo [2017-05-28] CHR Extension: (IDM Integration Module) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-06-08] CHR Extension: (Chrome Web Store Payments) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-17] CHR Extension: (Chrome Media Router) - C:\Users\Don\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-20] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-17] CHR HKU\S-1-5-21-2465256179-1618623775-1583742719-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps:// CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-17] Opera: ======= OPR Extension: (Video Downloader Pro) - C:\Users\Don\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibehiiilehaakkhkigckfjfknboalpbe [2017-06-02] StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 atchksrv; C:\Program Files (x86)\Intel\AMT\atchksrv.exe [176128 2009-12-01] (Intel Corporation) [File not signed] R2 CG6Service; C:\Program Files (x86)\CyberGhost\CyberGhost.Service.exe [71728 2016-08-18] (CyberGhost S.R.L) R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2624856 2017-03-09] (ESET) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S2 Internet Mobile. RunOuc; C:\Program Files (x86)\Internet Mobile\UpdateDog\ouc.exe [655712 2017-04-02] () R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [102400 2009-12-01] (Intel) [File not signed] R2 UNS; C:\Program Files (x86)\Intel\AMT\UNS.exe [2519040 2009-12-01] (Intel) [File not signed] S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12472904 2016-10-21] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 {0CBD4F48-3751-475D-BE88-4F271385B672}; C:\Program Files\Shadow Defender\Service.exe [79056 2016-07-23] (SHADOWDEFENDER.COM) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 diskpt; C:\Windows\System32\drivers\diskpt.sys [420592 2016-07-23] (SHADOWDEFENDER.COM) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [132848 2017-03-09] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107344 2017-03-09] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [178056 2017-03-09] (ESET) R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [50752 2017-03-09] (ESET) R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [78192 2017-03-09] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [60544 2017-03-09] (ESET) R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [101648 2017-03-09] (ESET) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [229376 2017-04-02] (Huawei Technologies Co., Ltd.) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R2 VBoxDrv; C:\Program Files (x86)\YouWave Android\vb\VBoxDrv.sys [202592 2011-11-20] (Oracle Corporation) R1 vmkbd3; C:\Windows\System32\DRIVERS\vmkbd.sys [52288 2016-10-21] (VMware, Inc.) R0 vsock; C:\Windows\System32\DRIVERS\vsock.sys [93248 2016-09-30] (VMware, Inc.) R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [34520 2015-07-09] (VMware, Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-06-16 17:43 - 2017-06-16 17:44 - 00013867 _____ C:\Users\Don\Desktop\FRST.txt 2017-06-16 17:35 - 2017-06-16 17:35 - 02438656 _____ (Farbar) C:\Users\Don\Desktop\FRST64.exe 2017-06-16 04:15 - 2017-06-16 04:16 - 00005073 _____ C:\Users\Don\Desktop\ZHPCleaner.txt 2017-06-16 04:08 - 2017-06-16 04:08 - 00000790 _____ C:\Users\Don\Desktop\ZHPCleaner.lnk 2017-06-16 04:05 - 2017-06-16 04:06 - 02794880 _____ C:\Users\Don\Desktop\ZHPCleaner.exe 2017-06-16 04:03 - 2017-06-16 04:03 - 00001196 _____ C:\Users\Don\Desktop\Malwarebytes.txt 2017-06-16 03:04 - 2017-06-16 03:07 - 64232976 _____ (Malwarebytes ) C:\Users\Don\Desktop\mb3-setup-consumer- 2017-06-16 02:57 - 2017-06-16 03:01 - 00002150 _____ C:\Users\Don\Desktop\Rkill.txt 2017-06-16 02:50 - 2017-06-16 02:51 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Don\Downloads\rkill(1).com 2017-06-16 01:47 - 2017-06-16 01:47 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Don\Desktop\ 2017-06-16 00:36 - 2017-06-16 00:36 - 00119846 _____ C:\Users\Don\Desktop\ZHPDiag.txt 2017-06-16 00:20 - 2017-06-16 00:20 - 10267786 _____ C:\Users\Don\Desktop\Cheb Bilal - A Sahbi Nsani - YouTube.MP4 2017-06-16 00:17 - 2017-06-16 00:17 - 00000780 _____ C:\Users\Don\Desktop\ZHPDiag.lnk 2017-06-16 00:15 - 2017-06-16 00:15 - 02750848 _____ C:\Users\Don\Desktop\ZHPDiag3.exe 2017-06-11 17:01 - 2017-06-16 00:11 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-06-11 17:01 - 2017-06-16 00:11 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-11 17:01 - 2017-06-16 00:11 - 00004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-06-08 01:18 - 2017-06-08 01:18 - 00000000 ___HD C:\temp 2017-06-07 17:19 - 2017-06-07 17:19 - 00003494 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Don-PC-Don 2017-06-02 23:17 - 2017-06-02 23:17 - 00016778 _____ C:\Users\Don\Downloads\backupsettings.conf 2017-05-29 16:45 - 2017-05-29 16:45 - 00001985 _____ C:\Users\Public\Desktop\حماية الدفع المصرفي.lnk 2017-05-29 16:45 - 2017-05-29 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2017-05-29 16:45 - 2017-05-29 16:45 - 00000000 ____D C:\ProgramData\ESET 2017-05-29 16:37 - 2017-05-29 16:41 - 120717952 _____ (ESET) C:\Users\Don\Desktop\eis_nt64_are.exe 2017-05-29 06:42 - 2017-05-29 06:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-05-29 06:41 - 2017-05-29 06:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-05-29 06:41 - 2017-05-29 06:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-05-29 06:06 - 2015-07-30 14:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2017-05-29 06:06 - 2015-07-30 14:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-05-29 05:20 - 2017-05-29 05:20 - 00009840 ____N C:\bootsqm.dat 2017-05-29 03:42 - 2017-05-29 03:45 - 00000000 ____D C:\Windows\system32\MRT 2017-05-29 03:42 - 2017-05-29 03:42 - 132223576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-05-29 03:18 - 2012-03-01 07:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2017-05-29 03:18 - 2012-03-01 07:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2017-05-29 03:18 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2017-05-29 03:10 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2017-05-29 03:10 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2017-05-29 03:10 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2017-05-29 03:10 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2017-05-29 03:09 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2017-05-29 03:09 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2017-05-29 03:09 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2017-05-29 03:09 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2017-05-29 03:06 - 2017-04-28 02:14 - 05547240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-05-29 03:06 - 2017-04-28 02:14 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-05-29 03:06 - 2017-04-28 02:14 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-05-29 03:06 - 2017-04-28 02:14 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-05-29 03:06 - 2017-04-28 02:14 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-05-29 03:06 - 2017-04-28 02:11 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-05-29 03:06 - 2017-04-28 02:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-05-29 03:06 - 2017-04-28 01:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-05-29 03:06 - 2017-04-28 01:34 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-05-29 03:06 - 2017-04-28 01:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-05-29 03:06 - 2017-04-28 01:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-05-29 03:06 - 2017-04-28 01:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-05-29 03:06 - 2017-04-28 01:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-05-29 03:06 - 2017-04-28 01:14 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-05-29 03:06 - 2017-04-28 01:12 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-05-29 03:06 - 2017-04-28 01:11 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-05-29 03:06 - 2017-04-28 01:11 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-05-29 03:06 - 2017-04-28 01:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-05-29 03:06 - 2017-04-28 01:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-05-29 03:06 - 2017-04-28 01:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-05-29 03:06 - 2017-04-28 01:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-05-29 03:06 - 2017-04-28 01:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-05-29 03:06 - 2017-04-28 01:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-05-29 03:06 - 2017-04-28 01:08 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-05-29 03:06 - 2017-04-28 01:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-05-29 03:06 - 2017-04-28 01:07 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:07 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-05-29 03:06 - 2017-04-28 01:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-05-29 03:06 - 2017-04-26 15:59 - 03220992 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-05-29 03:06 - 2017-04-21 16:34 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2017-05-29 03:06 - 2017-04-21 16:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2017-05-29 03:06 - 2017-04-17 16:37 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-05-29 03:06 - 2017-04-17 16:37 - 00876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-05-29 03:06 - 2017-04-17 16:37 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-05-29 03:06 - 2017-04-17 16:37 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-05-29 03:06 - 2017-04-17 16:37 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-05-29 03:06 - 2017-04-17 16:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-05-29 03:06 - 2017-04-17 16:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-05-29 03:06 - 2017-04-17 16:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-05-29 03:06 - 2017-04-17 15:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-05-29 03:06 - 2017-04-12 16:32 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-05-29 03:06 - 2017-04-12 16:32 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-05-29 03:06 - 2017-04-12 16:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-05-29 03:06 - 2017-04-12 16:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-05-29 03:06 - 2017-04-12 16:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-05-29 03:06 - 2017-04-12 16:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-05-29 03:06 - 2017-04-12 16:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-05-29 03:06 - 2017-04-12 16:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-05-29 03:06 - 2017-04-07 16:34 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-05-29 03:06 - 2017-04-07 16:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-05-29 03:06 - 2017-04-07 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-05-29 03:06 - 2017-04-07 16:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-05-29 03:06 - 2017-04-07 16:22 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-05-29 03:06 - 2017-04-05 15:55 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-05-29 03:06 - 2017-04-05 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-05-29 03:06 - 2017-04-05 15:55 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-05-29 03:06 - 2017-04-04 16:34 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-05-29 03:06 - 2017-04-04 16:34 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-05-29 03:06 - 2017-04-04 16:34 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2017-05-29 03:06 - 2017-04-04 15:53 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-05-29 03:06 - 2017-04-04 15:53 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-05-29 03:06 - 2017-03-22 16:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-05-29 03:06 - 2017-03-22 16:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-05-29 03:06 - 2017-03-22 16:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-05-29 03:06 - 2017-03-22 16:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-05-29 03:06 - 2017-03-22 16:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-05-29 03:06 - 2017-03-22 16:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-05-29 03:06 - 2017-03-22 16:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-05-29 03:06 - 2017-03-22 16:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-05-29 03:06 - 2017-03-22 16:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-05-29 03:06 - 2017-03-22 16:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-05-29 03:06 - 2017-03-22 16:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-05-29 03:06 - 2017-03-22 16:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\ 2017-05-29 03:06 - 2017-03-22 16:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-05-29 03:06 - 2017-03-22 16:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-05-29 03:06 - 2017-03-22 16:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-05-29 03:06 - 2017-03-22 16:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-05-29 03:06 - 2017-03-10 17:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-05-29 03:06 - 2017-03-10 17:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll 2017-05-29 03:06 - 2017-03-10 17:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2017-05-29 03:06 - 2017-03-10 17:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-05-29 03:06 - 2017-03-10 17:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-05-29 03:06 - 2017-03-10 17:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-05-29 03:06 - 2017-03-10 17:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-05-29 03:06 - 2017-03-10 17:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-05-29 03:06 - 2017-03-10 17:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll 2017-05-29 03:06 - 2017-03-10 17:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll 2017-05-29 03:06 - 2017-03-10 17:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-05-29 03:06 - 2017-03-10 17:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-05-29 03:06 - 2017-03-10 17:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-05-29 03:06 - 2017-03-10 16:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe 2017-05-29 03:06 - 2017-03-10 16:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-05-29 03:06 - 2017-03-10 16:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2017-05-29 03:06 - 2017-03-10 16:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-05-29 03:06 - 2017-03-09 17:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-05-29 03:06 - 2017-03-09 17:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-05-29 03:06 - 2017-03-07 17:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2017-05-29 03:06 - 2017-03-07 17:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2017-05-29 03:06 - 2017-03-04 02:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-05-29 03:06 - 2017-03-04 02:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll 2017-05-29 03:06 - 2017-03-04 02:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-05-29 03:06 - 2017-03-04 02:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll 2017-05-29 03:06 - 2017-02-14 17:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-05-29 03:06 - 2017-02-14 17:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-05-29 03:06 - 2017-02-10 17:32 - 01551872 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-05-29 03:06 - 2017-02-10 17:32 - 01149440 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-05-29 03:06 - 2017-02-10 17:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-05-29 03:06 - 2017-02-10 17:17 - 01081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-05-29 03:06 - 2017-02-10 17:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-05-29 03:06 - 2017-02-09 17:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-05-29 03:06 - 2017-02-09 17:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-05-29 03:06 - 2017-02-09 17:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-05-29 03:06 - 2017-02-09 17:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-05-29 03:06 - 2017-02-09 17:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-05-29 03:06 - 2017-02-09 17:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-05-29 03:06 - 2017-02-09 17:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-05-29 03:06 - 2017-02-09 17:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-05-29 03:06 - 2017-02-09 16:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-05-29 03:06 - 2017-02-06 17:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-05-29 03:06 - 2017-01-18 16:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-05-29 03:06 - 2017-01-18 16:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-05-29 03:06 - 2017-01-13 19:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-05-29 03:06 - 2017-01-13 19:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-05-29 03:06 - 2017-01-13 18:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-05-29 03:06 - 2017-01-13 18:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-05-29 03:06 - 2017-01-11 19:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-05-29 03:06 - 2017-01-11 19:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-05-29 03:06 - 2017-01-11 18:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-05-29 03:06 - 2017-01-11 18:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-05-29 03:06 - 2016-11-21 19:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2017-05-29 03:06 - 2016-11-20 17:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2017-05-29 03:06 - 2016-11-20 15:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2017-05-29 03:06 - 2016-11-17 17:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2017-05-29 03:06 - 2016-11-10 17:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2017-05-29 03:06 - 2016-11-10 17:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2017-05-29 03:06 - 2016-11-09 17:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2017-05-29 03:06 - 2016-11-09 17:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2017-05-29 03:06 - 2016-11-09 17:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2017-05-29 03:06 - 2016-11-09 17:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2017-05-29 03:06 - 2016-11-09 17:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2017-05-29 03:06 - 2016-11-09 17:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2017-05-29 03:06 - 2016-11-09 17:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2017-05-29 03:06 - 2016-11-09 17:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2017-05-29 03:06 - 2016-11-09 17:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2017-05-29 03:06 - 2016-11-09 17:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2017-05-29 03:06 - 2016-11-09 17:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2017-05-29 03:06 - 2016-11-09 16:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2017-05-29 03:06 - 2016-10-11 16:32 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2017-05-29 03:06 - 2016-10-11 16:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2017-05-29 03:06 - 2016-10-11 16:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2017-05-29 03:06 - 2016-10-11 16:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-05-29 03:06 - 2016-10-11 16:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2017-05-29 03:06 - 2016-10-11 16:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2017-05-29 03:06 - 2016-10-11 16:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2017-05-29 03:06 - 2016-10-11 16:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME 2017-05-29 03:06 - 2016-10-11 16:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-05-29 03:06 - 2016-10-11 16:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2017-05-29 03:06 - 2016-10-11 16:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll 2017-05-29 03:06 - 2016-10-11 16:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime 2017-05-29 03:06 - 2016-10-11 16:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2017-05-29 03:06 - 2016-10-11 15:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2017-05-29 03:06 - 2016-10-11 15:53 - 00099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2017-05-29 03:06 - 2016-10-11 14:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls 2017-05-29 03:06 - 2016-10-11 14:17 - 00419648 _____ C:\Windows\system32\locale.nls 2017-05-29 03:06 - 2016-10-08 14:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2017-05-29 03:06 - 2016-10-07 16:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2017-05-29 03:06 - 2016-10-07 16:12 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll 2017-05-29 03:06 - 2016-10-05 15:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2017-05-29 03:06 - 2016-09-15 15:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2017-05-29 03:06 - 2016-09-12 22:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2017-05-29 03:06 - 2016-09-12 21:49 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll 2017-05-29 03:06 - 2016-09-08 21:34 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2017-05-29 03:06 - 2016-09-08 21:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2017-05-29 03:06 - 2016-09-08 21:34 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2017-05-29 03:06 - 2016-09-08 21:34 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2017-05-29 03:06 - 2016-09-08 15:55 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2017-05-29 03:06 - 2016-09-08 15:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2017-05-29 03:06 - 2016-08-22 17:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2017-05-29 03:06 - 2016-08-12 18:02 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2017-05-29 03:06 - 2016-08-12 18:02 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2017-05-29 03:06 - 2016-08-12 18:02 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2017-05-29 03:06 - 2016-08-12 18:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2017-05-29 03:06 - 2016-08-12 18:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2017-05-29 03:06 - 2016-08-12 17:47 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2017-05-29 03:06 - 2016-08-12 17:47 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2017-05-29 03:06 - 2016-08-12 17:31 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2017-05-29 03:06 - 2016-08-12 17:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2017-05-29 03:06 - 2016-08-12 17:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2017-05-29 03:06 - 2016-08-12 17:26 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll 2017-05-29 03:06 - 2016-08-06 16:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll 2017-05-29 03:06 - 2016-08-06 16:15 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2017-05-29 03:06 - 2016-08-06 16:15 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2017-05-29 03:06 - 2016-08-06 16:15 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2017-05-29 03:06 - 2016-08-06 16:15 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2017-05-29 03:06 - 2016-08-06 16:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll 2017-05-29 03:06 - 2016-08-06 16:01 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2017-05-29 03:06 - 2016-08-06 16:01 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe 2017-05-29 03:06 - 2016-08-06 15:53 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2017-05-29 03:06 - 2016-08-06 15:53 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe 2017-05-29 03:06 - 2016-08-06 15:53 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll 2017-05-29 03:06 - 2016-06-14 18:21 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2017-05-29 03:06 - 2016-06-14 18:16 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 02646528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2017-05-29 03:06 - 2016-06-14 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-05-29 03:06 - 2016-06-14 18:11 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2017-05-29 03:06 - 2016-06-14 16:21 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 02136064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2017-05-29 03:06 - 2016-06-14 16:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2017-05-29 03:06 - 2016-06-14 16:15 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2017-05-29 03:06 - 2016-06-14 16:15 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-05-29 03:06 - 2016-06-14 16:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-05-29 03:06 - 2016-06-14 16:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2017-05-29 03:06 - 2016-06-14 16:05 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2017-05-29 03:06 - 2016-06-14 16:00 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2017-05-29 03:06 - 2016-06-14 16:00 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2017-05-29 03:06 - 2016-05-12 14:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2017-05-29 03:06 - 2016-05-12 14:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2017-05-29 03:06 - 2016-03-23 23:43 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2017-05-29 03:06 - 2016-03-23 23:40 - 00546656 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2017-05-29 03:06 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2017-05-29 03:05 - 2016-06-26 01:27 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-05-29 03:05 - 2016-06-26 01:27 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2017-05-29 03:05 - 2016-06-26 01:27 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2017-05-29 03:05 - 2016-06-26 01:27 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2017-05-29 03:05 - 2016-06-25 20:53 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2017-05-29 03:05 - 2016-06-25 20:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2017-05-29 03:05 - 2016-06-25 20:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2017-05-29 03:05 - 2016-06-25 20:41 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2017-05-29 03:05 - 2016-01-06 20:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2017-05-29 03:05 - 2016-01-06 19:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2017-05-29 03:05 - 2015-06-02 01:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2017-05-29 03:05 - 2015-06-02 00:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll 2017-05-29 03:05 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2017-05-29 03:05 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2017-05-29 03:05 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2017-05-29 03:05 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2017-05-29 03:05 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-05-29 03:05 - 2012-11-02 06:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2017-05-29 03:05 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2017-05-29 03:05 - 2010-12-23 11:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2017-05-29 03:05 - 2010-12-23 11:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\ 2017-05-29 03:05 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2017-05-29 03:05 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ 2017-05-29 03:04 - 2016-05-11 18:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2017-05-29 03:04 - 2016-05-11 18:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2017-05-29 03:04 - 2016-05-11 18:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll 2017-05-29 03:04 - 2016-05-11 16:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2017-05-29 03:04 - 2016-05-11 16:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2017-05-29 03:04 - 2016-05-11 16:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll 2017-05-29 03:04 - 2016-05-11 16:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2017-05-29 03:04 - 2016-05-11 16:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2017-05-29 03:04 - 2016-05-11 15:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2017-05-29 03:04 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2017-05-29 03:04 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2017-05-29 03:04 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2017-05-29 03:04 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2017-05-29 03:04 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ 2017-05-29 03:04 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2017-05-29 03:04 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2017-05-29 03:04 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2017-05-29 03:04 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01393152 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2017-05-29 03:04 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2017-05-29 03:04 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2017-05-29 03:04 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ 2017-05-29 03:04 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2017-05-29 03:04 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2017-05-29 03:04 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2017-05-29 03:04 - 2015-07-15 04:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2017-05-29 03:04 - 2015-04-13 04:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2017-05-29 03:04 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2017-05-29 03:04 - 2011-06-15 11:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2017-05-29 03:04 - 2011-06-15 11:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2017-05-29 03:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2017-05-29 03:04 - 2011-06-15 11:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2017-05-29 03:04 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll 2017-05-29 03:04 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll 2017-05-29 03:04 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll 2017-05-29 03:04 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll 2017-05-29 03:04 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll 2017-05-29 03:03 - 2016-02-03 19:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2017-05-29 03:03 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll 2017-05-29 03:03 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll 2017-05-29 03:03 - 2015-11-14 00:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe 2017-05-29 03:03 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll 2017-05-29 03:03 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll 2017-05-29 03:03 - 2015-11-13 23:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe 2017-05-29 03:03 - 2015-07-30 19:06 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2017-05-29 03:03 - 2015-07-30 18:57 - 01171456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2017-05-29 03:03 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2017-05-29 03:03 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2017-05-29 03:03 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2017-05-29 03:03 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2017-05-29 03:03 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2017-05-29 03:02 - 2016-02-09 10:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll 2017-05-29 03:02 - 2015-07-15 19:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2017-05-29 03:02 - 2015-07-10 18:51 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2017-05-29 03:02 - 2015-07-10 18:51 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2017-05-29 03:02 - 2015-07-10 18:51 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2017-05-29 03:02 - 2015-07-10 18:34 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2017-05-29 03:02 - 2015-07-10 18:34 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2017-05-29 03:02 - 2015-07-10 18:33 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2017-05-29 03:02 - 2015-04-24 19:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2017-05-29 03:02 - 2015-04-24 18:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2017-05-29 03:02 - 2015-02-25 04:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2017-05-29 03:02 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2017-05-29 03:02 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2017-05-29 03:02 - 2011-03-03 07:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2017-05-29 03:02 - 2011-03-03 07:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2017-05-29 03:02 - 2011-03-03 07:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2017-05-29 03:02 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2017-05-29 03:02 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2017-05-29 02:59 - 2011-11-17 07:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2017-05-29 02:59 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2017-05-29 02:58 - 2015-08-06 19:04 - 14176768 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-05-29 02:58 - 2015-08-06 19:03 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-05-29 02:58 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-05-29 02:58 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-05-29 02:58 - 2015-06-11 18:56 - 01112576 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2017-05-29 02:58 - 2015-06-11 18:16 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-05-29 02:58 - 2015-06-11 18:15 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2017-05-29 02:58 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2017-05-29 02:58 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2017-05-29 02:58 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2017-05-29 02:58 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2017-05-29 02:58 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2017-05-29 02:58 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2017-05-29 02:58 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2017-05-29 02:58 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2017-05-29 02:58 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2017-05-29 02:58 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2017-05-29 02:56 - 2016-01-22 07:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2017-05-29 02:56 - 2016-01-22 07:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2017-05-29 02:56 - 2016-01-22 07:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2017-05-29 02:56 - 2016-01-22 07:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2017-05-29 02:56 - 2016-01-22 07:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2017-05-29 02:56 - 2016-01-22 07:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2017-05-29 02:56 - 2016-01-22 07:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2017-05-29 02:56 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2017-05-29 02:56 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2017-05-29 02:55 - 2016-05-12 18:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2017-05-29 02:55 - 2016-05-12 18:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2017-05-29 02:55 - 2016-05-12 18:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.dll 2017-05-29 02:55 - 2016-05-12 16:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll 2017-05-29 02:55 - 2016-05-12 16:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll 2017-05-29 02:55 - 2016-05-12 16:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll 2017-05-29 02:55 - 2016-05-12 16:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll 2017-05-29 02:55 - 2016-05-12 16:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll 2017-05-29 02:55 - 2016-05-12 16:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.exe 2017-05-29 02:55 - 2016-05-12 15:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll 2017-05-29 02:55 - 2016-05-12 15:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe 2017-05-29 02:55 - 2015-07-15 04:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2017-05-29 02:55 - 2015-07-15 04:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2017-05-29 02:55 - 2015-07-15 03:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2017-05-29 02:55 - 2015-07-15 03:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2017-05-29 02:55 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2017-05-29 02:55 - 2012-11-28 23:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2017-05-29 02:55 - 2012-11-28 23:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2017-05-29 02:55 - 2012-11-28 23:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2017-05-29 02:54 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2017-05-29 02:54 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2017-05-29 02:54 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2017-05-29 02:54 - 2015-07-09 18:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2017-05-29 02:54 - 2015-07-09 18:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2017-05-29 02:54 - 2015-07-09 18:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe 2017-05-29 02:54 - 2011-03-11 07:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2017-05-29 02:54 - 2011-03-11 07:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2017-05-29 02:54 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2017-05-29 02:54 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2017-05-29 02:53 - 2016-04-14 17:42 - 00573952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2017-05-29 02:53 - 2016-04-14 16:33 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2017-05-29 02:53 - 2016-04-06 16:27 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2017-05-29 02:53 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2017-05-29 02:53 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2017-05-29 02:53 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2017-05-29 02:53 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2017-05-29 02:53 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2017-05-29 02:53 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2017-05-29 02:53 - 2015-08-05 18:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2017-05-29 02:53 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2017-05-29 02:53 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2017-05-29 02:53 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2017-05-29 02:53 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2017-05-29 02:53 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2017-05-29 02:53 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2017-05-29 02:53 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2017-05-29 02:53 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2017-05-29 02:53 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2017-05-29 02:53 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2017-05-29 02:53 - 2012-09-25 23:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2017-05-29 02:53 - 2012-03-17 08:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2017-05-29 02:53 - 2011-02-12 12:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2017-05-29 02:53 - 2011-02-05 18:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2017-05-29 02:53 - 2011-02-05 18:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2017-05-29 02:53 - 2011-02-05 18:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2017-05-29 02:52 - 2015-12-10 20:05 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 12306432 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 09074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 02470400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 01539584 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00910848 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00588800 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00495616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00290304 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2017-05-29 02:52 - 2015-12-10 20:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2017-05-29 02:52 - 2015-12-10 20:03 - 01538048 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-05-29 02:52 - 2015-12-10 20:03 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-05-29 02:52 - 2015-12-10 20:03 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2017-05-29 02:52 - 2015-12-10 20:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2017-05-29 02:52 - 2015-12-10 19:30 - 00981504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 11033088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 06035968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 02088960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 01267712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00717312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00624640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00389120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00345600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00229376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00186368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00153088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-05-29 02:52 - 2015-12-10 19:29 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2017-05-29 02:52 - 2015-12-10 19:29 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\corpol.dll 2017-05-29 02:52 - 2015-12-10 19:29 - 00015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2017-05-29 02:52 - 2015-12-10 19:28 - 01466368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-05-29 02:52 - 2015-12-10 19:24 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-05-29 02:52 - 2015-12-10 19:01 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-05-29 02:52 - 2015-12-10 19:00 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-05-29 02:52 - 2015-12-10 18:45 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-05-29 02:50 - 2016-05-11 18:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2017-05-29 02:50 - 2016-05-11 16:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2017-05-29 02:50 - 2014-03-04 10:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2017-05-29 02:50 - 2014-03-04 10:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2017-05-29 02:50 - 2014-03-04 10:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2017-05-29 02:50 - 2014-03-04 10:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2017-05-29 02:50 - 2014-03-04 10:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2017-05-29 02:50 - 2014-03-04 10:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2017-05-29 02:50 - 2014-03-04 10:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2017-05-29 02:50 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2017-05-29 02:50 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2017-05-29 02:49 - 2016-02-05 02:19 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2017-05-29 02:49 - 2016-02-04 19:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2017-05-29 02:49 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2017-05-29 02:49 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2017-05-29 02:49 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2017-05-29 02:49 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2017-05-29 02:49 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2017-05-29 02:49 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2017-05-29 02:49 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2017-05-29 02:49 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2017-05-29 02:49 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2017-05-29 02:49 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-05-29 02:49 - 2012-04-26 06:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2017-05-29 02:49 - 2012-04-26 06:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2017-05-29 02:49 - 2011-08-17 06:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2017-05-29 02:49 - 2011-08-17 06:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ 2017-05-29 02:49 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2017-05-29 02:49 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ 2017-05-29 02:48 - 2012-11-23 04:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2017-05-29 02:48 - 2011-05-24 12:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2017-05-29 02:48 - 2011-05-24 11:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2017-05-29 02:48 - 2011-05-24 11:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2017-05-29 02:48 - 2011-05-24 11:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2017-05-29 02:48 - 2011-05-24 11:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2017-05-29 02:44 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2017-05-29 02:44 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2017-05-29 02:44 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2017-05-29 02:44 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2017-05-29 02:44 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2017-05-29 02:44 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2017-05-29 02:44 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2017-05-29 02:44 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2017-05-29 02:44 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2017-05-29 02:44 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2017-05-29 02:44 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2017-05-29 02:44 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2017-05-29 02:43 - 2012-07-04 23:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2017-05-29 02:43 - 2012-07-04 23:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2017-05-29 02:43 - 2012-07-04 23:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2017-05-29 02:43 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2017-05-29 02:43 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2017-05-29 02:43 - 2011-12-16 09:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2017-05-29 02:43 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2017-05-29 02:40 - 2016-04-09 07:58 - 01190912 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2017-05-29 02:40 - 2016-04-09 07:54 - 01011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2017-05-29 02:40 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2017-05-29 02:40 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2017-05-29 02:40 - 2015-03-04 05:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2017-05-29 02:40 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2017-05-29 02:40 - 2011-08-27 06:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2017-05-29 02:40 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2017-05-29 02:39 - 2015-02-04 04:16 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2017-05-29 02:39 - 2015-02-04 03:54 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2017-05-29 02:37 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2017-05-29 02:37 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2017-05-29 02:37 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2017-05-29 02:37 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2017-05-29 02:37 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2017-05-29 02:37 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2017-05-29 02:37 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2017-05-29 02:37 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2017-05-29 02:34 - 2012-02-17 07:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-05-29 02:34 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-05-29 02:34 - 2012-02-17 05:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2017-05-28 01:28 - 2017-05-28 01:28 - 00000000 ____D C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps 2017-05-27 22:07 - 2017-05-27 22:07 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-05-27 22:07 - 2017-05-27 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-05-27 18:09 - 2017-05-27 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2017-05-27 18:09 - 2017-05-27 18:09 - 00000000 ____D C:\Program Files\Speccy 2017-05-24 22:24 - 2017-05-24 22:24 - 00002591 _____ C:\Users\Don\Desktop\µTorrent.lnk 2017-05-24 21:54 - 2017-05-24 21:54 - 00000000 ____D C:\Users\Don\Downloads\WINDOWS VISTA ULTIMATE X86 SP2 FINAL ENU APRIL 2017 {Gen2} 2017-05-24 21:25 - 2017-06-05 22:46 - 00000684 _____ C:\Windows\SysWOW64\rsatest.txt 2017-05-24 21:25 - 2017-06-05 22:46 - 00000256 _____ C:\Windows\SysWOW64\aes.txt 2017-05-24 21:25 - 2017-05-24 21:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap 2017-05-24 05:53 - 2017-05-24 05:53 - 00000000 ____D C:\Users\Don\AppData\Roaming\FastStone 2017-05-24 01:29 - 2017-05-24 01:29 - 00001866 _____ C:\Users\Public\Desktop\mkvmerge GUI.lnk 2017-05-24 01:29 - 2017-05-24 01:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix 2017-05-24 01:29 - 2017-05-24 01:29 - 00000000 ____D C:\Program Files (x86)\MKVToolNix 2017-05-24 00:59 - 2017-05-24 00:59 - 00000000 ____D C:\Users\Don\AppData\Roaming\fontconfig 2017-05-24 00:57 - 2017-05-24 01:07 - 00000000 ____D C:\Users\Don\AppData\Roaming\Aegisub 2017-05-23 23:34 - 2017-06-16 17:35 - 00000000 ____D C:\Users\Don\AppData\Roaming\IDM 2017-05-23 23:34 - 2017-05-23 23:34 - 00001013 _____ C:\Users\Don\Desktop\Internet Download Manager.lnk 2017-05-23 23:34 - 2017-05-23 23:34 - 00000000 ____D C:\Users\Don\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2017-05-23 23:34 - 2017-05-23 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2017-05-23 23:34 - 2017-05-23 23:34 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager 2017-05-23 22:54 - 2017-05-23 22:54 - 00000000 ____D C:\Users\Don\AppData\Local\ElevatedDiagnostics 2017-05-22 18:41 - 2017-06-01 13:29 - 00003830 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1495474877 2017-05-22 18:41 - 2017-05-22 18:41 - 00001097 _____ C:\Users\Public\Desktop\Opera.lnk 2017-05-22 18:41 - 2017-05-22 18:41 - 00001097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2017-05-22 18:37 - 2017-05-24 04:28 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-05-22 18:37 - 2017-05-24 04:28 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-05-22 18:35 - 2017-05-22 18:37 - 00000000 ____D C:\Program Files (x86)\Google 2017-05-22 18:35 - 2017-05-22 18:35 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-05-22 18:35 - 2017-05-22 18:35 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-05-22 18:34 - 2017-05-22 18:34 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-05-22 18:34 - 2017-05-22 18:34 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-05-22 18:34 - 2017-05-22 18:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-05-22 18:34 - 2017-05-22 18:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-05-22 17:48 - 2017-06-16 04:19 - 00000000 ____D C:\Windows\Minidump 2017-05-19 07:07 - 2017-05-26 18:24 - 00000000 ____D C:\Users\Don\Documents\Virtual Machines 2017-05-19 06:26 - 2017-05-19 06:26 - 00000000 ____D C:\Users\Don\AppData\LocalLow\Adobe 2017-05-19 06:14 - 2017-06-07 17:19 - 00000000 ____D C:\ProgramData\ 2017-05-19 06:04 - 2017-06-07 17:22 - 00000000 ____D C:\ProgramData\Adobe 2017-05-18 23:05 - 2017-05-22 01:10 - 00000000 ____D C:\Users\Don\AppData\Roaming\8pecxstudios 2017-05-18 20:14 - 2017-05-18 20:14 - 00000000 ____D C:\Users\Don\AppData\Local\CometNetwork 2017-05-18 14:53 - 2017-05-18 14:53 - 02040414 _____ C:\Users\Don\Downloads\49A3.tmp 2017-05-18 03:48 - 2017-05-29 18:21 - 00000400 __RSH C:\ProgramData\ntuser.pol 2017-05-18 03:35 - 2017-05-22 18:28 - 00000000 ____D C:\Program Files\WinToUSB 2017-05-18 03:15 - 2017-05-18 03:15 - 00000218 _____ C:\Users\Don\.recently-used.xbel 2017-05-18 02:54 - 2017-05-18 02:54 - 00000000 ____D C:\Users\Don\AppData\Roaming\gtk-2.0 2017-05-18 02:53 - 2017-05-18 02:53 - 00000000 ____D C:\Users\Don\.Virtualbox 2017-05-18 02:52 - 2017-05-18 02:52 - 00001095 _____ C:\Users\Public\Desktop\YouWave Android.lnk 2017-05-18 02:52 - 2017-05-18 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouWave Android 2017-05-18 02:52 - 2017-05-18 02:52 - 00000000 ____D C:\Program Files (x86)\YouWave Android 2017-05-17 14:13 - 2016-10-17 16:35 - 00223464 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-06-16 17:43 - 2017-05-09 21:40 - 00000000 ____D C:\FRST 2017-06-16 17:43 - 2017-02-16 00:30 - 00000000 ____D C:\Users\Don\AppData\Roaming\DMCache 2017-06-16 17:39 - 2011-02-07 14:35 - 00739590 _____ C:\Windows\system32\perfh00C.dat 2017-06-16 17:39 - 2011-02-07 14:35 - 00481018 _____ C:\Windows\system32\perfh001.dat 2017-06-16 17:39 - 2011-02-07 14:35 - 00150044 _____ C:\Windows\system32\perfc00C.dat 2017-06-16 17:39 - 2011-02-07 14:35 - 00095362 _____ C:\Windows\system32\perfc001.dat 2017-06-16 17:39 - 2009-07-14 06:13 - 02241668 _____ C:\Windows\system32\PerfStringBackup.INI 2017-06-16 17:38 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-06-16 17:06 - 2009-07-14 05:45 - 00022944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-06-16 17:06 - 2009-07-14 05:45 - 00022944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-06-16 17:04 - 2017-02-15 18:12 - 00000000 ____D C:\Users\Don\AppData\LocalLow\Mozilla 2017-06-16 17:00 - 2017-04-01 22:38 - 00000000 ____D C:\ProgramData\VMware 2017-06-16 16:59 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-06-16 04:51 - 2017-03-17 05:41 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-16 04:50 - 2017-02-15 20:06 - 00000000 ____D C:\ProgramData\TEMP 2017-06-16 04:39 - 2017-02-15 20:13 - 00000000 ____D C:\Users\Don\AppData\Roaming\vlc 2017-06-16 04:16 - 2017-02-21 15:46 - 00000000 ____D C:\Users\Don\AppData\Roaming\ZHP 2017-06-16 00:11 - 2017-02-16 01:18 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-06-16 00:11 - 2017-02-16 01:18 - 00000000 ____D C:\Windows\system32\Macromed 2017-06-13 02:00 - 2017-02-16 01:17 - 00000000 ____D C:\Users\Don\AppData\Local\Adobe 2017-06-12 19:34 - 2017-04-01 22:45 - 00000000 ____D C:\Users\Don\AppData\Roaming\VMware 2017-06-12 19:34 - 2017-04-01 22:45 - 00000000 ____D C:\Users\Don\AppData\Local\VMware 2017-06-08 01:18 - 2017-02-21 19:46 - 00000000 ____D C:\Users\Don\AppData\Roaming\Adobe 2017-06-07 22:50 - 2017-04-24 04:17 - 00000000 ____D C:\Users\Don\Documents\Snagit Stamps 2017-06-07 18:41 - 2017-05-02 22:59 - 00009728 _____ C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-06-07 18:31 - 2017-02-16 00:43 - 00000000 ____D C:\Users\Don\AppData\Roaming\Skype 2017-06-07 17:09 - 2017-02-15 17:58 - 00000000 ____D C:\Users\Don 2017-06-07 17:08 - 2017-02-16 00:52 - 00000000 ____D C:\ProgramData\Package Cache 2017-06-05 22:55 - 2017-02-15 18:04 - 00196592 _____ C:\Users\Don\AppData\Local\GDIPFONTCACHEV1.DAT 2017-06-05 22:44 - 2009-07-14 05:45 - 05230848 _____ C:\Windows\system32\FNTCACHE.DAT 2017-06-01 13:29 - 2017-04-02 00:23 - 00000000 ____D C:\Program Files\Opera 2017-05-29 16:25 - 2017-02-15 20:15 - 00000000 ____D C:\Users\Don\AppData\Roaming\uTorrent 2017-05-29 15:59 - 2017-04-04 23:11 - 00000000 ____D C:\Users\Don\Desktop\dcc 2017-05-29 06:49 - 2017-02-15 18:59 - 02198640 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-05-29 06:14 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2017-05-29 05:37 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2017-05-29 05:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2017-05-29 05:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker 2017-05-29 05:25 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-05-29 05:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\Dism 2017-05-29 05:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\Dism 2017-05-29 05:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2017-05-29 05:23 - 2010-11-21 08:16 - 00000000 ____D C:\Program Files\Windows Journal 2017-05-29 02:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system 2017-05-29 02:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\L2Schemas 2017-05-27 22:07 - 2017-02-16 00:43 - 00002707 _____ C:\Users\Public\Desktop\Skype.lnk 2017-05-27 22:07 - 2017-02-16 00:43 - 00000000 ____D C:\ProgramData\Skype 2017-05-25 16:16 - 2017-02-21 02:47 - 00000000 ____D C:\Users\Don\AppData\Local\CrashDumps 2017-05-24 21:53 - 2017-05-07 02:01 - 00000000 ___SD C:\Users\Don\AppData\LocalLow\Temp 2017-05-24 21:25 - 2017-05-01 18:59 - 00000000 ____D C:\Program Files\WinPcap 2017-05-24 19:07 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2017-05-24 16:31 - 2017-05-02 01:12 - 00000000 ____D C:\Users\Don\AppData\Roaming\MPC-HC 2017-05-24 05:54 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2017-05-24 00:56 - 2017-02-16 00:30 - 00000000 ____D C:\Users\Don\Downloads\Compressed 2017-05-22 18:41 - 2017-04-02 00:26 - 00000000 ____D C:\Users\Don\AppData\Roaming\Opera Software 2017-05-22 18:41 - 2017-04-02 00:26 - 00000000 ____D C:\Users\Don\AppData\Local\Opera Software 2017-05-22 16:06 - 2009-07-14 06:08 - 00032570 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-05-22 01:10 - 2017-02-15 18:12 - 00000000 ____D C:\Users\Don\AppData\Local\Mozilla 2017-05-22 01:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2017-05-20 21:42 - 2017-02-16 01:48 - 00000000 ____D C:\Windows\Panther 2017-05-20 19:57 - 2017-02-15 19:32 - 00000000 ____D C:\Users\Don\AppData\Local\8pecxstudios 2017-05-19 06:08 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-05-18 03:48 - 2009-07-14 04:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2017-05-18 03:48 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-05-18 02:54 - 2017-02-20 21:21 - 00000000 ____D C:\Users\Don\youwave ==================== Files in the root of some directories ======= 2017-05-02 22:59 - 2017-06-07 18:41 - 0009728 _____ () C:\Users\Don\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-05-05 23:56 - 2017-05-05 23:56 - 0000552 _____ () C:\Users\Don\AppData\Local\TroubleshooterConfig.json ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-05-19 10:03 ==================== End of FRST.txt ============================