This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Long delays on laptop after malware expungement [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This site recently helped to get rid of malware on my computer(thanks). That was about two weeks ago. However, since then I've been experiencing progressively longer delays after typing or trying to execute commands. Sometimes now it can be two or more seconds after I type before the keystroke appears, for example, or before my computer responds. It's like I can hear the hard drive or something crank up and spin in order to do the task. I know it's probably not that, but it's what it sounds like. I can hear something inside begin to whir after I want to visit a site or open a program.

 

I was going to reset my laptop back to factory settings, since I've only had it for about a month. But as I was going through the steps I got a "Warning! This PC was recently upgraded to Windows 10. If you Reset this PC, you won’t be able to undo the upgrade and go back to the previous version of Windows.”

Problem is, there is no "previous version." I bought this laptop new - it wasn't an upgrade. So I'm worried that if I do the reset, it'll erase my OS and I'll have a brand new, non-functioning laptop on my hands. I can't determine whether Windows with also erase my operating system as well - so I don't want to risk it.

 

So now I'm suspecting that not everything malevolent is off my laptop. I don't know what else it could be.

:welcome:

 

When we finished up the last thread you stated that everything was working fine, what have you done since that thread was closed as far as downloading and installing any programs or have you added any hardware like a new printer or scanner as example.  For a brand new computer that you only had for few weeks it was pretty well infected and its possible that some may have come back.

 

Its possible that the PC manufacturer may have gotten that computer with Win 7 and upgraded it before selling it, not sure. With all the problems you having with it it must be under warranty, I would contact them and ask and see if you cant turn it it for a new one.

 

As far as resetting it, let me ask a windows guy what he would recommend. In the meantime lets run FRST again so I can see if any bad stuff returned

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • The only thing I've done since last time is move over some well-used programs from my external HD - nothing huge or unusual and certainly not file-sharing. Hmm - I don't know if I had to download any software for our new printer for wireless or not, and I'm not sure if I already had the software for our new Brother printer on here or not for my last post. I did a search for Brother, and my laptop came back with zero results.

     

    Thanks again!

     

    Here is the first scan:

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-12-2015
    Ran by [removed] (administrator) on LAPTOP-L02074TA (23-12-2015 18:52:36)
    Running from C:\Users\[removed]\Desktop
    [removed] Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
    (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
    (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
    (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    () C:\Windows\System32\igfxTray.exe
    (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
    (TOSHIBA Corporation) C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
    (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe
    (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [599384 2015-06-05] (Conexant Systems, Inc.)
    HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
    HKLM\…\Run: [TCrdMain] => C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe [511280 2015-06-23] (TOSHIBA Corporation)
    HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3946184 2015-10-29] (Synaptics Incorporated)
    HKLM-x32\…\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516976 2015-06-09] (TOSHIBA)
    HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-05] (AVAST Software)
    HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-05] (AVAST Software)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
    Tcpip\..\Interfaces\{e79ab54d-b855-47b9-b876-73cdf5a0204e}: [DhcpNameServer] [removed]
    Tcpip\..\Interfaces\{efd1cb4d-c480-4627-af71-4f51f9ea6777}: [DhcpNameServer] [removed] [removed] 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba15.msn.com/?pc=TBTE
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-05] (AVAST Software)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-12] (Oracle Corporation)
    BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-05] (AVAST Software)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-12] (Oracle Corporation)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

    Edge:
    ======
    Edge HomeButtonPage: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> hxxp://www.google.com/

    FireFox:
    ========
    FF ProfilePath: C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default
    FF DefaultSearchEngine.US: Google
    FF Homepage: hxxps://www.google.com/
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-07] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-07] ()
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-12] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-12] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VLC\npvlc.dll [2015-04-13] (VideoLAN)
    FF Extension: Adblock Plus - C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-22]
    FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [not signed]
    FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-05]
    FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
    FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-05]

    Chrome:
    =======
    CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-05]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-05] (AVAST Software)
    R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2278152 2015-09-25] (Broadcom Corporation.)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
    R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-11-27] (Digital Wave Ltd.)
    R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-11-30] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-10-29] (Synaptics Incorporated)
    R2 TOSRMService; C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe [326960 2015-06-24] (TOSHIBA)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-05] (AVAST Software)
    R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
    R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-05] (AVAST Software)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-05] (AVAST Software)
    R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-05] (AVAST Software)
    R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
    R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-05] (AVAST Software)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-05] (AVAST Software)
    R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [199472 2015-09-25] (Broadcom Corporation.)
    R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7585280 2015-10-30] (Broadcom Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
    R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [301784 2015-06-01] (Realtek Semiconductor Corp.)
    R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-16] (Realtek                                            )
    R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-10-29] (Synaptics Incorporated)
    R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45720 2015-06-13] (Toshiba Corporation)
    S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-23 18:52 - 2015-12-23 18:53 - 00013064 _____ C:\Users\Dykes family\Desktop\FRST.txt
    2015-12-23 18:52 - 2015-12-23 18:52 - 00000000 ____D C:\FRST
    2015-12-23 18:51 - 2015-12-23 18:51 - 02370560 _____ (Farbar) C:\Users\Dykes family\Desktop\FRST64.exe
    2015-12-21 20:46 - 2015-12-21 20:46 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\OpenOffice
    2015-12-21 20:45 - 2015-12-21 20:45 - 00001128 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk
    2015-12-21 20:45 - 2015-12-21 20:45 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2
    2015-12-21 20:45 - 2015-12-21 20:45 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
    2015-12-21 20:29 - 2015-12-21 20:29 - 00000000 ____D C:\Users\Dykes family\Desktop\OpenOffice 4.1.2 (en-US) Installation Files
    2015-12-21 19:42 - 2015-12-21 19:52 - 00000000 ___HD C:\$SysReset
    2015-12-17 19:25 - 2015-12-06 23:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2015-12-17 19:25 - 2015-12-06 23:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2015-12-17 19:25 - 2015-12-06 23:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2015-12-17 19:25 - 2015-12-06 23:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2015-12-17 19:25 - 2015-12-06 23:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-12-17 19:25 - 2015-12-06 23:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-12-17 19:25 - 2015-12-06 23:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2015-12-17 19:25 - 2015-12-06 23:07 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-12-17 19:25 - 2015-12-06 23:03 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-12-17 19:25 - 2015-12-06 22:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-12-17 19:25 - 2015-12-06 22:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-12-17 19:25 - 2015-12-06 22:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2015-12-17 19:25 - 2015-12-06 22:47 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2015-12-17 19:25 - 2015-12-06 22:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-12-17 19:25 - 2015-12-06 22:43 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2015-12-17 19:25 - 2015-12-06 22:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-12-17 19:25 - 2015-12-06 22:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-12-17 19:25 - 2015-12-06 22:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-12-17 19:24 - 2015-12-06 23:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2015-12-17 19:24 - 2015-12-06 23:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2015-12-17 19:24 - 2015-12-06 23:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2015-12-17 19:24 - 2015-12-06 23:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2015-12-17 19:24 - 2015-12-06 23:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2015-12-17 19:24 - 2015-12-06 23:47 - 00116720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-12-17 19:24 - 2015-12-06 23:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2015-12-17 19:24 - 2015-12-06 23:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
    2015-12-17 19:24 - 2015-12-06 23:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
    2015-12-17 19:24 - 2015-12-06 23:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2015-12-17 19:24 - 2015-12-06 23:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
    2015-12-17 19:24 - 2015-12-06 23:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2015-12-17 19:24 - 2015-12-06 23:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2015-12-17 19:24 - 2015-12-06 23:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-12-17 19:24 - 2015-12-06 23:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2015-12-17 19:24 - 2015-12-06 23:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-12-17 19:24 - 2015-12-06 23:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-12-17 19:24 - 2015-12-06 23:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-12-17 19:24 - 2015-12-06 23:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
    2015-12-17 19:24 - 2015-12-06 23:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2015-12-17 19:24 - 2015-12-06 23:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-12-17 19:24 - 2015-12-06 23:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2015-12-17 19:24 - 2015-12-06 23:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-12-17 19:24 - 2015-12-06 23:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-12-17 19:24 - 2015-12-06 23:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
    2015-12-17 19:24 - 2015-12-06 23:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2015-12-17 19:24 - 2015-12-06 23:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2015-12-17 19:24 - 2015-12-06 23:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
    2015-12-17 19:24 - 2015-12-06 23:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2015-12-17 19:24 - 2015-12-06 22:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2015-12-17 19:24 - 2015-12-06 22:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-12-17 19:24 - 2015-12-06 22:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-12-17 19:24 - 2015-12-06 22:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-12-17 19:24 - 2015-12-06 22:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2015-12-17 19:24 - 2015-12-06 22:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-12-17 19:24 - 2015-12-06 22:57 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
    2015-12-17 19:24 - 2015-12-06 22:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2015-12-17 19:24 - 2015-12-06 22:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2015-12-17 19:24 - 2015-12-06 22:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-12-17 19:24 - 2015-12-06 22:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2015-12-17 19:24 - 2015-12-06 22:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2015-12-17 19:24 - 2015-12-06 22:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2015-12-17 19:24 - 2015-12-06 22:54 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
    2015-12-17 19:24 - 2015-12-06 22:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-12-17 19:24 - 2015-12-06 22:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2015-12-17 19:24 - 2015-12-06 22:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2015-12-17 19:24 - 2015-12-06 22:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2015-12-17 19:24 - 2015-12-06 22:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2015-12-17 19:24 - 2015-12-06 22:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 19:24 - 2015-12-06 22:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 19:24 - 2015-12-06 22:44 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2015-12-17 19:24 - 2015-12-06 22:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
    2015-12-17 19:24 - 2015-12-06 22:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-12-17 19:24 - 2015-12-06 22:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2015-12-17 19:24 - 2015-12-06 22:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
    2015-12-17 19:24 - 2015-12-06 22:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2015-12-17 19:24 - 2015-12-06 22:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
    2015-12-16 22:32 - 2015-12-16 22:32 - 00000698 _____ C:\DelFix.txt
    2015-12-15 19:47 - 2015-12-15 19:47 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-12-14 18:02 - 2015-12-01 02:12 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2015-12-14 18:02 - 2015-11-24 07:07 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2015-12-14 18:02 - 2015-11-24 06:06 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2015-12-14 18:02 - 2015-11-24 05:26 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2015-12-14 18:02 - 2015-11-24 05:01 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-12-14 18:02 - 2015-11-24 04:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-12-14 18:02 - 2015-11-24 04:53 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-12-14 18:02 - 2015-11-24 04:45 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
    2015-12-14 18:02 - 2015-11-24 04:37 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
    2015-12-14 18:02 - 2015-11-24 04:26 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2015-12-14 18:02 - 2015-11-24 04:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
    2015-12-14 18:02 - 2015-11-24 04:12 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
    2015-12-14 18:02 - 2015-11-24 03:58 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2015-12-14 18:02 - 2015-11-24 03:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-12-14 18:02 - 2015-11-24 03:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-12-14 18:02 - 2015-11-24 03:52 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2015-12-14 18:02 - 2015-11-24 03:49 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
    2015-12-14 18:02 - 2015-11-24 03:14 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
    2015-12-14 18:02 - 2015-11-24 03:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2015-12-14 18:02 - 2015-11-24 02:59 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2015-12-14 18:02 - 2015-11-24 02:57 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
    2015-12-14 18:02 - 2015-11-24 02:35 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-12-14 18:02 - 2015-11-24 02:29 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2015-12-14 18:02 - 2015-11-24 02:23 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-12-14 18:02 - 2015-11-24 02:11 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-12-14 18:02 - 2015-11-24 02:08 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-12-14 18:02 - 2015-11-24 02:04 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2015-12-14 17:52 - 2015-12-08 22:39 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2015-12-14 07:52 - 2015-12-14 07:52 - 00000000 ____D C:\Users\Dykes family\AppData\Local\ActiveSync
    2015-12-14 07:51 - 2015-12-14 07:53 - 00000000 ___DC C:\WINDOWS\Panther
    2015-12-14 07:50 - 2015-12-14 07:50 - 00000020 ___SH C:\Users\Dykes family\ntuser.ini
    2015-12-14 07:46 - 2015-12-14 07:46 - 00000000 ____D C:\Windows.old
    2015-12-14 07:45 - 2015-12-14 07:45 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-12-14 07:45 - 2015-12-14 07:45 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-12-14 07:45 - 2015-12-14 07:45 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-12-14 07:45 - 2015-12-14 07:45 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-12-14 07:45 - 2015-12-14 07:45 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-12-14 07:45 - 2015-12-14 07:45 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-12-14 07:41 - 2015-12-14 07:41 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-12-14 07:38 - 2015-12-14 07:38 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-12-14 07:38 - 2015-12-14 07:38 - 00000000 ____D C:\Program Files\MSBuild
    2015-12-14 07:38 - 2015-12-14 07:38 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-12-14 07:38 - 2015-12-14 07:38 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-12-14 07:37 - 2015-10-23 20:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-12-14 07:37 - 2015-10-23 20:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-12-14 07:37 - 2015-10-23 20:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-12-14 07:37 - 2015-10-23 20:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-12-14 07:37 - 2015-10-23 20:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-12-14 07:37 - 2015-10-23 20:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-12-14 05:21 - 2015-12-14 05:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-12-14 05:15 - 2015-12-19 03:33 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-12-14 05:15 - 2015-12-14 05:15 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-12-14 05:07 - 2015-12-14 05:07 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-12-14 05:05 - 2015-12-14 05:09 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-12-14 05:03 - 2015-12-19 08:35 - 00000000 ____D C:\Users\Dykes family
    2015-12-14 05:03 - 2015-12-14 05:03 - 00000000 _SHDL C:\Users\Dykes family\My Documents
    2015-12-14 05:03 - 2015-12-14 05:03 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Videos
    2015-12-14 05:03 - 2015-12-14 05:03 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Pictures
    2015-12-14 05:03 - 2015-12-14 05:03 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Music
    2015-12-14 04:58 - 2015-12-14 05:05 - 00000000 ____D C:\ProgramData\Conexant
    2015-12-14 04:58 - 2015-12-14 05:05 - 00000000 ____D C:\Program Files\CONEXANT
    2015-12-14 04:58 - 2015-12-14 04:58 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
    2015-12-14 04:57 - 2015-12-19 08:35 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2015-12-14 04:57 - 2015-12-14 05:05 - 00000000 ____D C:\Program Files\Intel
    2015-12-14 04:57 - 2015-12-14 04:57 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
    2015-12-14 04:57 - 2015-12-14 04:57 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
    2015-12-14 04:57 - 2015-11-30 21:39 - 00086528 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
    2015-12-14 04:57 - 2015-11-30 21:39 - 00082432 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
    2015-12-14 04:56 - 2015-12-14 04:56 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
    2015-12-14 04:56 - 2015-12-14 04:56 - 00000000 ____D C:\Program Files\Synaptics
    2015-12-14 04:55 - 2015-10-30 02:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-12-14 04:51 - 2015-12-16 03:34 - 00212000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-12-13 17:20 - 2015-12-13 17:20 - 00000000 ____D C:\Users\Public\Documents\Verizon2.0_Log
    2015-12-13 17:20 - 2015-12-13 17:20 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\VERIZON
    2015-12-12 10:34 - 2015-12-12 10:34 - 00433012 _____ C:\Users\Dykes family\Desktop\CodeChickenCore-1.8.jar
    2015-12-12 09:01 - 2015-12-14 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-12-12 09:01 - 2015-12-12 09:02 - 00000000 ____D C:\ProgramData\Oracle
    2015-12-12 09:01 - 2015-12-12 09:01 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
    2015-12-12 09:01 - 2015-12-12 09:01 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Sun
    2015-12-12 09:01 - 2015-12-12 09:01 - 00000000 ____D C:\Users\Dykes family\AppData\LocalLow\Sun
    2015-12-12 09:01 - 2015-12-12 09:01 - 00000000 ____D C:\Users\Dykes family\.oracle_jre_usage
    2015-12-12 09:01 - 2015-12-12 09:01 - 00000000 ____D C:\Program Files (x86)\Java
    2015-12-12 09:00 - 2015-12-12 09:00 - 00000000 ____D C:\Users\Dykes family\AppData\LocalLow\Oracle
    2015-12-11 18:16 - 2015-12-11 18:16 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\MMFApplications
    2015-12-11 18:15 - 2015-12-11 18:19 - 00000000 ____D C:\Users\Dykes family\Documents\The Escapists
    2015-12-11 18:14 - 2015-12-11 18:14 - 00000000 ____D C:\Users\Dykes family\Desktop\The Escapists v1.0
    2015-12-11 18:14 - 2015-12-11 18:14 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Steam
    2015-12-09 22:44 - 2015-12-13 17:15 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\vlc
    2015-12-09 22:44 - 2015-12-09 22:45 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\dvdcss
    2015-12-09 22:44 - 2015-12-09 22:44 - 00001000 _____ C:\Users\Public\Desktop\VLC media player.lnk
    2015-12-09 22:43 - 2015-12-09 22:44 - 00000000 ____D C:\Program Files (x86)\VLC
    2015-12-09 22:40 - 2015-12-09 22:42 - 28849904 _____ C:\Users\Dykes family\Downloads\vlc-2.2.1-win32.exe
    2015-12-09 21:43 - 2015-12-09 21:43 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MediaShow
    2015-12-09 21:42 - 2015-12-09 21:42 - 00000000 ____D C:\Users\Dykes family\Documents\CyberLink
    2015-12-09 21:42 - 2015-12-09 21:42 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\CyberLink
    2015-12-09 21:41 - 2015-12-09 21:41 - 00000000 ____D C:\Users\Dykes family\AppData\Local\CyberLink
    2015-12-07 18:41 - 2015-12-07 18:41 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Macromedia
    2015-12-07 18:39 - 2015-12-07 18:40 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Adobe
    2015-12-06 01:45 - 2015-12-06 01:45 - 00000000 ____D C:\ProgramData\Synaptics
    2015-12-05 19:37 - 2015-12-05 19:35 - 01055560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD20D.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00450504 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD222.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00386096 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
    2015-12-05 19:37 - 2015-12-05 19:35 - 00273784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD223.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00155304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD234.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00097648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD220.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD20E.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD221.tmp
    2015-12-05 19:37 - 2015-12-05 19:35 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswD20F.tmp
    2015-12-05 19:35 - 2015-12-19 08:39 - 00451040 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
    2015-12-05 19:35 - 2015-12-19 08:39 - 00097648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
    2015-12-05 19:35 - 2015-12-14 05:15 - 00002954 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
    2015-12-05 19:35 - 2015-12-05 19:35 - 01055560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00450504 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys.1450532372343
    2015-12-05 19:35 - 2015-12-05 19:35 - 00273784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00155304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00097648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys.1450532372343
    2015-12-05 19:35 - 2015-12-05 19:35 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
    2015-12-05 19:35 - 2015-12-05 19:35 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
    2015-12-05 19:35 - 2015-12-05 19:35 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
    2015-12-05 19:35 - 2015-12-05 19:35 - 00001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
    2015-12-05 19:35 - 2015-12-05 19:35 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\AVAST Software
    2015-12-05 19:34 - 2015-12-05 19:34 - 00000000 ____D C:\Program Files\AVAST Software
    2015-12-05 19:33 - 2015-12-05 19:33 - 05084256 _____ (AVAST Software) C:\Users\Dykes family\Downloads\avast_free_antivirus_setup_online_cnet2.exe
    2015-12-05 19:33 - 2015-12-05 19:33 - 00000000 ____D C:\ProgramData\AVAST Software
    2015-12-05 19:23 - 2015-12-19 08:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2015-12-05 19:23 - 2015-12-05 19:23 - 00001224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2015-12-05 19:23 - 2015-12-05 19:23 - 00001212 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2015-12-05 19:22 - 2015-12-05 19:22 - 00243656 _____ C:\Users\Dykes family\Downloads\Firefox Setup Stub 42.0 (1).exe
    2015-12-05 17:44 - 2015-12-14 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-12-05 17:44 - 2015-12-09 18:34 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-12-05 17:44 - 2015-12-09 18:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-12-05 17:41 - 2015-10-29 09:20 - 01804696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
    2015-12-05 17:41 - 2015-10-29 09:19 - 00619208 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys
    2015-12-05 17:41 - 2015-10-29 09:19 - 00254152 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPCo33.dll
    2015-12-05 17:38 - 2015-12-11 18:08 - 00000000 ____D C:\WINDOWS\system32\MRT
    2015-12-05 17:38 - 2015-12-11 18:06 - 140158008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2015-12-05 15:54 - 2015-09-17 01:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SETC4B5.tmp
    2015-12-05 15:04 - 2015-12-05 15:04 - 22908888 _____ (Malwarebytes ) C:\Users\Dykes family\Desktop\mbam-setup-2.2.0.1024.exe
    2015-12-05 14:48 - 2015-12-05 14:48 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    2015-12-05 11:06 - 2015-12-14 05:06 - 00000000 ____D C:\WINDOWS\system32\jike
    2015-12-05 08:33 - 2015-12-14 05:15 - 00002800 _____ C:\WINDOWS\System32\Tasks\GoogleUp
    2015-12-05 08:33 - 2015-12-14 05:15 - 00002788 _____ C:\WINDOWS\System32\Tasks\import
    2015-12-05 08:33 - 2015-12-14 05:15 - 00002586 _____ C:\WINDOWS\System32\Tasks\Googleuptodate
    2015-12-05 08:33 - 2015-12-14 05:15 - 00002552 _____ C:\WINDOWS\System32\Tasks\win
    2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\uninst
    2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Simple Media Player
    2015-12-05 08:33 - 2015-12-05 08:33 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Tempfolder
    2015-12-05 08:30 - 2015-12-05 08:30 - 00009216 _____ C:\Users\Dykes family\AppData\Local\kdapll.dll
    2015-12-05 08:30 - 2015-12-05 08:30 - 00002560 _____ C:\Users\Dykes family\AppData\Local\uninstall.exe
    2015-12-05 08:29 - 2015-12-05 08:29 - 00000000 ____D C:\Users\Dykes family\AppData\Local\CEF
    2015-12-05 08:28 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\winnetuse
    2015-12-04 20:16 - 2015-12-04 20:16 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Synaptics
    2015-12-04 19:53 - 2015-12-19 11:13 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\.minecraft
    2015-12-04 19:53 - 2015-12-04 19:53 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\java
    2015-12-04 19:51 - 2015-12-14 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
    2015-12-04 19:51 - 2015-12-04 19:51 - 00001030 _____ C:\Users\Public\Desktop\Minecraft.lnk
    2015-12-04 19:51 - 2015-12-04 19:51 - 00000000 ____D C:\Program Files (x86)\Minecraft
    2015-12-04 19:30 - 2015-12-04 19:30 - 00000000 ____D C:\Users\Dykes family\AppData\Local\NetworkTiles
    2015-12-01 18:57 - 2015-12-05 11:04 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
    2015-12-01 02:02 - 2015-12-01 07:35 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Comms
    2015-11-30 22:31 - 2015-12-14 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001577 _____ C:\Users\Public\Desktop\Free Video to DVD Converter.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001376 _____ C:\Users\Public\Desktop\Free DVD Video Burner.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001310 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
    2015-11-30 22:28 - 2015-11-30 22:30 - 26601640 _____ (DVDVideoSoft Ltd. ) C:\Users\Dykes family\Downloads\FreeVideoToDVDConverter.exe
    2015-11-30 22:25 - 2015-12-08 19:09 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\DVDVideoSoft
    2015-11-30 22:18 - 2015-11-30 22:18 - 00000013 __RSH C:\WINDOWS\system32\Drivers\fbd.sys
    2015-11-30 22:17 - 2015-11-30 22:18 - 01388432 _____ C:\Users\Public\VOIP.dat
    2015-11-30 22:17 - 2015-11-30 22:17 - 00000000 ____D C:\Users\Dykes family\Tracing
    2015-11-30 22:10 - 2015-12-14 05:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-11-30 22:10 - 2015-12-13 22:04 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Skype
    2015-11-30 22:10 - 2015-12-07 19:02 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-11-30 22:10 - 2015-12-07 18:56 - 00000000 ____D C:\ProgramData\Skype
    2015-11-30 22:10 - 2015-11-30 22:10 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Skype
    2015-11-30 22:05 - 2015-11-30 22:05 - 01504384 _____ (Skype Technologies S.A.) C:\Users\Dykes family\Downloads\SkypeSetup.exe
    2015-11-30 22:04 - 2015-12-14 05:15 - 00002262 _____ C:\WINDOWS\System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948}
    2015-11-30 21:59 - 2015-11-30 22:00 - 00000000 ____D C:\ProgramData\KMSAuto
    2015-11-30 21:59 - 2013-08-22 03:40 - 00040664 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tap0901.sys
    2015-11-30 21:58 - 2015-11-30 22:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MSfree Inc
    2015-11-30 21:54 - 2015-12-05 14:24 - 00000000 ____D C:\Program Files\Microsoft Office
    2015-11-30 21:54 - 2015-11-30 21:54 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Microsoft Help
    2015-11-30 21:44 - 2015-12-14 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-11-30 21:44 - 2015-12-05 15:23 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-11-30 21:44 - 2015-12-05 15:22 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-11-30 21:44 - 2015-12-05 15:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-11-30 21:44 - 2015-11-30 21:44 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-11-30 21:44 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-11-30 21:44 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2015-11-30 21:44 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-11-30 21:39 - 2015-11-30 21:39 - 36681912 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 35768808 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 30404056 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 29613040 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 29084160 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 19844096 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 13727296 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 13211648 _____ (Intel Corporation) C:\WINDOWS\system32\ig8icd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 12880160 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 11276968 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 10528136 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 10032128 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig8icd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 06741482 _____ C:\WINDOWS\system32\igdclbif.bin
    2015-11-30 21:39 - 2015-11-30 21:39 - 06389688 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
    2015-11-30 21:39 - 2015-11-30 21:39 - 06305696 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05467648 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05245440 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05121136 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05092320 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 04841488 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 04443136 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 03873280 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 03801600 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 02813952 _____ C:\WINDOWS\system32\iglhxa64.cpa
    2015-11-30 21:39 - 2015-11-30 21:39 - 02028032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01858632 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01767992 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01765408 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01565696 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01456408 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01216000 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01156608 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01008016 _____ C:\WINDOWS\system32\igfxSDK.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00970752 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00927120 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00923536 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00803113 _____ C:\WINDOWS\system32\DisplayAudiox64.cab
    2015-11-30 21:39 - 2015-11-30 21:39 - 00723456 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00641530 _____ C:\WINDOWS\system32\FilmModeDetection.wmv
    2015-11-30 21:39 - 2015-11-30 21:39 - 00624128 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00589712 _____ C:\WINDOWS\system32\IntelCpHDCPSvc.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00519056 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00511260 _____ C:\WINDOWS\system32\cp_resources.bin
    2015-11-30 21:39 - 2015-11-30 21:39 - 00448912 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00425472 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00403671 _____ C:\WINDOWS\system32\ImageStabilization.wmv
    2015-11-30 21:39 - 2015-11-30 21:39 - 00397824 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00396688 _____ C:\WINDOWS\system32\igfxTray.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00386048 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00375173 _____ C:\WINDOWS\system32\ColorImageEnhancement.wmv
    2015-11-30 21:39 - 2015-11-30 21:39 - 00373248 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00353280 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00351120 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00331808 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00328080 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00313888 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUtils64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00300032 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00284280 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00283024 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00269360 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00256000 _____ C:\WINDOWS\system32\igfxCPL.cpl
    2015-11-30 21:39 - 2015-11-30 21:39 - 00249232 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00243200 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00220432 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00219024 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00214416 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00213904 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00206848 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4256.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00200856 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00184352 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00172032 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00163776 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00162752 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00160680 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00157072 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00153600 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00143904 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiLogServer64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00141080 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00140056 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00090112 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00086528 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00086016 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00082944 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00082432 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00073728 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00064512 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00044025 _____ C:\WINDOWS\system32\iglhxo64.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00043816 _____ C:\WINDOWS\system32\iglhxc64_dev.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00043494 _____ C:\WINDOWS\system32\iglhxc64.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00043298 _____ C:\WINDOWS\system32\iglhxg64_dev.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00043256 _____ C:\WINDOWS\system32\iglhxg64.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00042079 _____ C:\WINDOWS\system32\iglhxo64_dev.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00036616 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00035328 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00011776 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00011264 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00004682 _____ C:\WINDOWS\system32\iglhxs64.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00001125 _____ C:\WINDOWS\system32\iglhxa64.vp
    2015-11-30 21:39 - 2015-11-30 21:39 - 00000935 _____ C:\WINDOWS\system32\Gfxv4_0.exe.config
    2015-11-30 21:39 - 2015-11-30 21:39 - 00000935 _____ C:\WINDOWS\system32\DPTopologyApp.exe.config
    2015-11-30 21:39 - 2015-11-30 21:39 - 00000895 _____ C:\WINDOWS\system32\Gfxv2_0.exe.config
    2015-11-30 21:39 - 2015-11-30 21:39 - 00000895 _____ C:\WINDOWS\system32\DPTopologyAppv2_0.exe.config
    2015-11-30 21:37 - 2015-11-30 21:43 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Mozilla
    2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Mozilla
    2015-11-30 21:34 - 2015-11-30 21:34 - 00243656 _____ C:\Users\Dykes family\Downloads\Firefox Setup Stub 42.0.exe
    2015-11-30 21:28 - 2015-11-30 21:30 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MicrosoftEdge
    2015-11-30 21:28 - 2015-11-30 21:28 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Macromedia
    2015-11-30 21:27 - 2015-12-14 07:54 - 00002380 _____ C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-30 21:27 - 2015-12-14 07:54 - 00000000 ___RD C:\Users\Dykes family\OneDrive
    2015-11-30 21:27 - 2015-12-04 19:48 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Toshiba
    2015-11-30 21:25 - 2015-12-18 19:56 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Publishers
    2015-11-30 21:23 - 2015-12-19 08:35 - 00000000 __SHD C:\Users\Dykes family\IntelGraphicsProfiles
    2015-11-30 21:23 - 2015-12-18 19:56 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Packages
    2015-11-30 21:23 - 2015-12-04 19:52 - 00000000 ____D C:\Users\Dykes family\AppData\Local\VirtualStore
    2015-11-30 21:23 - 2015-11-30 21:23 - 00016148 _____ C:\WINDOWS\system32\LAPTOP-L02074TA_defaultuser0_HistoryPrediction.bin
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Adobe
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Local\TileDataLayer

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-23 18:52 - 2015-10-30 01:28 - 00000000 ____D C:\Windows
    2015-12-22 21:01 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-12-22 20:03 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-21 20:09 - 2015-10-30 02:21 - 00000000 ____D C:\WINDOWS\INF
    2015-12-21 20:09 - 2015-09-25 07:08 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-12-21 07:54 - 2015-10-30 02:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-12-19 03:32 - 2015-10-30 01:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
    2015-12-19 03:31 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-12-19 03:31 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-12-19 03:31 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\bcastdvr
    2015-12-16 03:32 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-12-15 17:56 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-12-14 17:41 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-12-14 07:51 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-12-14 07:51 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-12-14 07:50 - 2015-10-30 02:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-12-14 07:50 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-12-14 07:50 - 2015-09-25 07:06 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-12-14 07:46 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-12-14 07:46 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-12-14 07:46 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-12-14 05:23 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\rescache
    2015-12-14 05:23 - 2015-10-30 01:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-12-14 05:21 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-12-14 05:21 - 2015-09-25 08:25 - 00027188 _____ C:\WINDOWS\diagerr.xml
    2015-12-14 05:21 - 2015-09-25 08:25 - 00024768 _____ C:\WINDOWS\diagwrn.xml
    2015-12-14 05:19 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Registration
    2015-12-14 05:15 - 2015-09-25 07:44 - 00003096 _____ C:\WINDOWS\System32\Tasks\BTSchedulerTask
    2015-12-14 05:15 - 2015-09-25 07:33 - 00002388 _____ C:\WINDOWS\System32\Tasks\Resolution+ Setting Task
    2015-12-14 05:14 - 2015-10-30 02:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-12-14 05:07 - 2015-07-10 04:05 - 00000000 ____D C:\Users\Default.migrated
    2015-12-14 05:06 - 2015-10-30 04:02 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
    2015-12-14 05:06 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-12-14 05:06 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-12-14 05:05 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-12-14 05:05 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2015-12-14 05:05 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-12-14 05:05 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-12-14 05:05 - 2015-09-25 07:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
    2015-12-14 05:05 - 2015-09-25 07:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
    2015-12-14 05:02 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-12-14 04:52 - 2015-10-30 04:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-12-14 04:16 - 2015-10-30 04:42 - 00000000 ___HD C:\$WINDOWS.~BT
    2015-12-09 21:43 - 2015-09-25 07:40 - 00000000 ____D C:\ProgramData\CyberLink
    2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\ProgramData\McAfee
    2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\Program Files\Common Files\McAfee
    2015-11-30 21:40 - 2015-09-25 07:19 - 00000000 ___HD C:\Intel
    2015-11-30 21:18 - 2015-09-25 07:28 - 00000000 ____D C:\ProgramData\TOSHIBA
    2015-11-30 19:33 - 2015-10-30 02:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-11-30 19:33 - 2015-10-30 02:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2015-12-05 08:30 - 2015-12-05 08:30 - 0009216 _____ () C:\Users\Dykes family\AppData\Local\kdapll.dll
    2015-12-05 08:30 - 2015-12-05 08:30 - 0002560 _____ () C:\Users\Dykes family\AppData\Local\uninstall.exe

    Files to move or delete:
    ====================
    C:\Users\Public\VOIP.dat


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-12-14 04:51

    ==================== End of FRST.txt ============================

     

    ——————

    Here is the Addition scan:

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
    Ran by [removed] (2015-12-23 18:54:03)
    Running from C:\Users\[removed]\Desktop
    Windows 10 Home (X64) (2015-12-14 10:22:36)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-843202709-3289130475-90754708-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-843202709-3289130475-90754708-503 - Limited - Disabled)
    Dykes family (S-1-5-21-843202709-3289130475-90754708-1001 - Administrator - Enabled) => C:\Users\Dykes family
    Guest (S-1-5-21-843202709-3289130475-90754708-501 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 11.1.2245 - AVAST Software)
    Bluetooth(R) Link (HKLM\…\{3F3DCC8C-2C93-4082-A6DE-BBDC74804FA0}) (Version: 4.3.03 - Toshiba Corporation)
    Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.66.8.52 - Conexant)
    CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5509.05 - CyberLink Corp.)
    Free Video to DVD Converter (HKLM-x32\…\Free Video to DVD Converter_is1) (Version: 5.0.69.1127 - DVDVideoSoft Ltd.)
    Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4112 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
    Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
    Java 8 Update 66 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
    Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
    NetStream 1.0 (HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\NetStream 1.0) (Version:  - )
    OpenOffice 4.1.2 (HKLM-x32\…\{E6AD67BB-1C33-4AB3-A387-E0D48137AB70}) (Version: 4.12.9782 - Apache Software Foundation)
    Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10130.29089 - Realtek Semiconductor Corp.)
    Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
    Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
    Skype™ 7.15 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.15.102 - Skype Technologies S.A.)
    Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.16.6 - Synaptics Incorporated)
    TOSHIBA Application Installer (HKLM\…\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
    TOSHIBA Audio Enhancement (HKLM\…\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 3.0.0.9 - Toshiba Corporation)
    TOSHIBA Display Utility (HKLM\…\{0B39C39A-3ECE-4582-9C91-842D22819A24}) (Version: 2.0.1.0 - Toshiba Corporation)
    TOSHIBA Password Utility (HKLM-x32\…\InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9}) (Version: 8.1.1.0 - Toshiba Corporation)
    TOSHIBA Service Station (HKLM\…\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
    TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 2.00.0005 - Toshiba Corporation)
    TOSHIBA System Settings (HKLM\…\{B040D5C9-C9AA-430A-A44E-696656012E61}) (Version: 3.0.0.6406 - Toshiba Corporation)
    TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
    VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-843202709-3289130475-90754708-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    15-12-2015 19:47:50 Windows Update
    18-12-2015 19:48:04 Windows Update
    18-12-2015 19:50:12 Windows Modules Installer
    21-12-2015 07:53:53 Windows Modules Installer

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-07-10 06:04 - 2015-12-05 14:54 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    127.0.0.1       localhost

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {02C0A321-FD63-4DE7-8EDB-EB21DB915B0C} - System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948} => launchwinapp.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.1.0.166&LastError;=404
    Task: {06EBFEF3-D10F-4C99-ABFE-0E6DD5D2F4B1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
    Task: {2A49C756-107C-4F3E-AD56-CC0F42EFEEC0} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2015-06-12] (TOSHIBA Corporation)
    Task: {3EAEE635-F519-439F-B155-FB6ECF37E58B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-12-11] (Microsoft Corporation)
    Task: {4603A09B-4202-4DFE-8E18-163233E6CECD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe
    Task: {53F06927-DA16-4A76-9CA7-BB66BF0CBD86} - System32\Tasks\win => C:\Windows\system32\win.exe
    Task: {5B554B79-11E1-4622-9A36-63A7CC6C9000} - System32\Tasks\BTSchedulerTask => C:\Program Files (x86)\TOSHIBA\Toshiba Bluetooth Device Profile Utility\TosBt_NotificationScheduler.exe [2015-07-08] (Toshiba Corporation)
    Task: {5F753A44-BB07-47CC-90F9-8D55A51EEF24} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
    Task: {632CD2E0-A082-4CB6-A66E-F0D23CB52915} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe
    Task: {6F792032-E46E-4F9F-A51C-66329AF9D144} - System32\Tasks\GoogleUp => C:\Windows\system32\hsysinfo.exe
    Task: {7BCB58D7-FC51-4AAF-95F5-3679D470A307} - System32\Tasks\import => C:\Windows\system32\Mint.exe
    Task: {7E884694-3DEA-4F4D-9586-86D599E51FD8} - System32\Tasks\Googleuptodate => C:\Windows\system32\Wimboldon.exe
    Task: {7FCD847D-5CEB-4C0D-BB67-2E7EB2D23121} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-12-05] (AVAST Software)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2015-12-14 07:45 - 2015-12-14 07:45 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00396688 _____ () C:\WINDOWS\system32\igfxTray.exe
    2015-12-14 07:45 - 2015-12-14 07:45 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-17 19:24 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-12-17 19:24 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2015-12-17 19:24 - 2015-12-06 23:00 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
    2012-07-18 20:38 - 2012-07-18 20:38 - 00020904 _____ () C:\Program Files\TOSHIBA\System Setting\SmoothView.dll
    2015-12-16 19:12 - 2015-12-16 19:13 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2015-12-17 19:25 - 2015-12-06 22:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-12-17 19:24 - 2015-12-06 22:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-12-17 19:25 - 2015-12-06 22:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2015-12-17 19:25 - 2015-12-06 22:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2015-12-09 18:05 - 2015-12-09 18:06 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    2015-12-09 18:05 - 2015-12-09 18:06 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
    2015-12-04 20:02 - 2015-12-04 20:02 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
    2015-12-05 19:35 - 2015-12-05 19:35 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
    2015-12-05 19:35 - 2015-12-05 19:35 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
    2015-12-05 19:37 - 2015-12-05 19:37 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15120504\algo.dll
    2015-12-05 19:35 - 2015-12-05 19:35 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00110952 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00253800 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\collector.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00295272 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\stat.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00104296 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00020328 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
    2015-11-30 22:31 - 2015-11-27 19:06 - 00044392 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
    2015-12-05 19:35 - 2015-12-05 19:35 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2015-12-16 19:12 - 2015-12-16 19:13 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-12-16 19:12 - 2015-12-16 19:14 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-843202709-3289130475-90754708-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Innovation\Bishop Tree.jpg
    DNS Servers: [removed] - [removed]
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: HomeNetSvc => 2
    MSCONFIG\Services: PCSUService => 2
    MSCONFIG\Services: SCService => 2

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [UDP Query User{431BE04D-1AD8-46FC-A950-F66C8186AAAE}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{7DA9A593-D765-4CAF-8EC7-DC29D32B703D}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [{CB0B5FBE-5B3F-4A98-A08C-DFFB10BFE152}] => (Allow) C:\Windows\system32\rundll32.exe
    FirewallRules: [{B0E073D4-455F-44E3-8476-20A4C39B421C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{A0763D73-A490-4EA9-A3E9-FABAC2D73F91}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{96C8546B-32FD-4AC8-8526-130F7848FA16}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
    FirewallRules: [{CBD50D8C-3674-4618-B66B-AFC682B5F36E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{5C0A2729-53D8-41DC-85E0-C9450AD46815}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/21/2015 07:54:09 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (12/20/2015 09:40:09 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: plugin-container.exe, version: 43.0.1.5828, time stamp: 0x56723a12
    Faulting module name: mozglue.dll, version: 43.0.1.5828, time stamp: 0x56722c0b
    Exception code: 0x80000003
    Fault offset: 0x0000ed63
    Faulting process id: 0x1b84
    Faulting application start time: 0xplugin-container.exe0
    Faulting application path: plugin-container.exe1
    Faulting module path: plugin-container.exe2
    Report Id: plugin-container.exe3
    Faulting package full name: plugin-container.exe4
    Faulting package-relative application ID: plugin-container.exe5

    Error: (12/19/2015 08:46:09 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: LAPTOP-L02074TA)
    Description: Package Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe+MicrosoftEdge#{e1b78e4a-b7c7-4aae-af80-2830d3376ae4} was terminated because it took too long to suspend.

    Error: (12/18/2015 07:50:16 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (12/18/2015 07:50:11 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.0, time stamp: 0x5632d93d
    Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x56540c3b
    Exception code: 0xc0000374
    Fault offset: 0x00000000000ee00c
    Faulting process id: 0x1070
    Faulting application start time: 0xShellExperienceHost.exe0
    Faulting application path: ShellExperienceHost.exe1
    Faulting module path: ShellExperienceHost.exe2
    Report Id: ShellExperienceHost.exe3
    Faulting package full name: ShellExperienceHost.exe4
    Faulting package-relative application ID: ShellExperienceHost.exe5

    Error: (12/18/2015 07:48:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (12/16/2015 03:52:26 AM) (Source: Perflib) (EventID: 1008) (User: )
    Description: BITSC:\Windows\System32\bitsperf.dll8

    Error: (12/15/2015 07:47:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (12/15/2015 05:53:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-L02074TA)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/14/2015 06:08:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-L02074TA)
    Description: Activation of app Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App failed with error: -2147024770 See the Microsoft-Windows-TWinUI/Operational log for additional information.


    System errors:
    =============
    Error: (12/23/2015 06:42:20 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-L02074TA)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}LAPTOP-L02074TADykes familyS-1-5-21-843202709-3289130475-90754708-1001LocalHost (Using LRPC)Microsoft.WindowsStore_2015.25.5.0_x64__8wekyb3d8bbweS-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157

    Error: (12/23/2015 12:02:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/22/2015 08:51:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/22/2015 07:49:07 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/22/2015 07:44:43 AM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.

    Error: (12/21/2015 09:47:12 PM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.

    Error: (12/21/2015 09:47:12 PM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.

    Error: (12/21/2015 09:47:12 PM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.

    Error: (12/21/2015 09:47:11 PM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.

    Error: (12/21/2015 09:47:11 PM) (Source: disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk1\DR5.


    CodeIntegrity:
    ===================================
      Date: 2015-12-22 07:48:15.461
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-19 03:33:48.297
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-16 03:36:08.873
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-16 03:33:35.954
      Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-12-15 19:50:14.690
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-14 05:15:04.238
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-14 05:13:39.148
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-14 04:53:39.889
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
    Percentage of memory in use: 37%
    Total physical RAM: 8106.14 MB
    Available physical RAM: 5090.87 MB
    Total Virtual: 16810.14 MB
    Available Virtual: 13564.2 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.75 GB) (Free:874.61 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 00000000)

    Partition: GPT.

    ==================== End of Addition.txt ============================

    While I am looking over your logs lets do this

     

     
    Download CKScanner by askey127 from Here & save it to your Desktop.
    • Doubleclick CKScanner.exe then click Search For Files
    • When the cursor hourglass disappears, click Save List To File
    • A message box will verify the file saved
    • Please Run this program only once
    • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
    • Here is that txt file:

      CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
      c:\windows.old\windows\prefetch\kmsauto net.exe-5f8ef789.pf
      c:\windows.old\windows\prefetch\kmsss.exe-ea251358.pf
      scanner sequence 3.LB.11.OLNAHZ
       —– EOF —– 

      About two minutes after I posted this recent log, my computer inexplicably shut down. And it had almost a full charge. When I turned it back on, It froze for a few moments before my desktop screen appeared. It's never done either of those things before.

      You have markers in our CKScanner log to suggest your copy of windows and or Office may not be valid 

      You have markers in our CKScanner log to suggest your copy of windows and or Office may not be valid 

      ? - I don't have MS Office. It was a suspect program after my last incident, having downloaded it from my cousin, and I had deleted anything Office-related. And the OS that's on here is what came with the laptop.

       

      Btw, I think my computer shut down because it ran out of power - which shouldn't have happened since it's been plugged in all day and I had only been on it for about an hour. When I hover over the battery icon it tells me "2% until fully charged" which is obviously wrong, since it's only now at 23%. So I know the outlet and power cord are alive. Unfortunately, I'm still experiencing delays.

      Your logs look ok. Those files that are used to bypass Office may just be leftover

       

      Where did you get this PC from, whats the make and model ?

      This computer got pretty good reviews , seems like a solid system from what I can see. But its possible that this system had some history prior to being upgraded to Win 10. Unless you purchase right from the manufacturer sometimes it could be a problem.  I have come across many heavily infected computers in my time but not one like this that was infected in just two weeks.  I suspect it was using the torrents to download stuff and also downloading Office from your cousin is when you problems seemed to start

       

      From our tech

       

       

      I also see reference in his logs to both Hard drive0 (His primary drive) and also hard drive1 with a 14gb size and referencing Win XP…. 

       

      That also seems to be very odd to me especially on what he says is a brand new machine!… that supposedly came with Win 10 preinstalled….

       

      I don't understand why he should be getting the warning about refreshing Win 10 unless there is a lot of history surrounding the acquisition and usage of this computer.

       

       

       

      You may want to do a System Restore if you can find a date prior to all this happening by going to the Control Panel > Recovery

       

      Thanks. I agree that my problem was probably due to the software I torrent-downloaded. It was fine before that. And I sure hope I didn't get a refurbished computer instead of a new one. A new one with Windows 10 shouldn't have any kind of log file referencing Windows XP.

       

      I'm going o see how to go about doing a clean wipe of my computer - without wiping my operating system (if that's possible) That should erase any malware that may have found its way on here (correct me if I'm wrong). Thanks for your help.

      First a Merry Christmas to you and your family

       

      We just do malware removal on this forum, so post in our windows forum and they can guide you through bringing your computer back to factory or what ever you want to do, you can link them to this thread if you like so that they can see what we have done. 

       

      http://forums.whatthetech.com/index.php?showforum=119

       

      I hope you realize by now that actually, nothing is free. When you download that free program using the torrents it comes with strings attached in the form of malware. 

       

      Take Care

       

      Ken :)

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI