So i got infected about a month ago and with the help of a member staff the virus seemed to be removed but today it appeared out of no where.
[removed]
Platform: Windows 10 Home (X64) Language: Português (Portugal)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
() C:\Program Files\AVAST Software\SecureLine\vpnsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Wi-Fi\Launcher.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
() C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
() C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.26\deploy\LoLLauncher.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\LoLPatcher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\LolClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6004.42261.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6004.42261.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040792 2015-07-06] (Realtek Semiconductor)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1710056 2015-07-14] (NVIDIA Corporation)
HKLM-x32\…\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [69632 2012-03-20] (Vodafone)
HKLM-x32\…\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\…\Run: [VodafoneMobileWiFi] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Wi-Fi\Launcher.exe [145920 2014-03-11] (Vodafone)
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\RunOnce: [Uninstall C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\RunOnce: [Uninstall C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.5892.0626"
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\RunOnce: [Uninstall C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\RunOnce: [Uninstall C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6390.0509] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6390.0509"
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\MountPoints2: {41aa1307-5d8b-11e6-9be6-54ab3a2c2168} - "E:\setup_vmb_lite.exe" /checkApplicationPresence
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\MountPoints2: {e34076f6-5e42-11e6-9be8-54ab3a2c2168} - "D:\setup_vmb_lite.exe" /checkApplicationPresence
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\MountPoints2: {e623694c-5e12-11e6-9be7-54ab3a2c2168} - "D:\SetupWi-Fi.exe"
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\MountPoints2: {f130394a-4c8e-11e6-9bcd-3052cb5e098b} - "D:\setup_vmb_lite.exe" /checkApplicationPresence
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\…\MountPoints2: {f1303a4b-4c8e-11e6-9bcd-3052cb5e098b} - "D:\setup_vmb_lite.exe" /checkApplicationPresence
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-06-27] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-06-27] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-06-27] (Acer Incorporated)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1e8e9d5e-2b9c-4bf6-a51b-ef48487b130e}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2b7bdd77-99c4-428f-ae3d-281d34bf9c0b}: [NameServer] 87.103.113.145 87.103.113.177
Tcpip\..\Interfaces\{2b7bdd77-99c4-428f-ae3d-281d34bf9c0b}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{8834f845-ecd9-43d2-a855-73fe734e0741}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{ae3a38cb-4f1d-46c8-9663-cf415c79f774}: [NameServer] 87.103.113.145 87.103.113.177
ManualProxies:
Internet Explorer:
==================
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer15.msn.com/?pc=ACTE
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-20] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-20] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Rafael Sobreiro\AppData\Roaming\Mozilla\Firefox\Profiles\iz0nvtgx.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-18] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-18] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-20] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-12] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-12] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-05-23] ()
FF Extension: (Português (Portugal) Language Pack) - C:\Users\Rafael Sobreiro\AppData\Roaming\Mozilla\Firefox\Profiles\iz0nvtgx.default\Extensions\[removed] [2016-08-04]
Chrome:
=======
CHR Profile: C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-12]
CHR Extension: (Google Docs) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-12]
CHR Extension: (Google Drive) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-12]
CHR Extension: (YouTube) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-12]
CHR Extension: (Adblock Plus) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Google Sheets) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-12]
CHR Extension: (Google Docs Offline) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-12]
CHR Extension: (Video download helper) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\mngdadkapbemiekajhhalpakdpleogfn [2016-08-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-12]
CHR Extension: (Gmail) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-12]
CHR Extension: (Chrome Media Router) - C:\Users\Rafael Sobreiro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-30]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [315472 2015-07-20] (Windows (R) Win 7 DDK provider)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2267352 2016-08-15] (Acer Incorporated)
S3 cplspcon; C:\Windows\system32\IntelCpHDCPSvc.exe [588904 2015-08-18] ()
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated)
S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-05-23] (WildTangent)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-14] (NVIDIA Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [350312 2015-08-18] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-08-14] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-14] (NVIDIA Corporation)
R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [401248 2015-09-04] (Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [453984 2015-09-04] (Acer Incorporated)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [592392 2016-07-17] ()
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (acer)
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone) [File not signed]
S3 vmicvss; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24856 2016-08-03] (Microsoft Corporation)
S2 InstallerService; "C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe" [X]
S2 mccspsvc; "C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 huawei_wwanecm; C:\Windows\System32\drivers\ew_juwwanecm.sys [227840 2012-03-16] (Huawei Technologies Co., Ltd.)
R3 iaLPSS2_I2C; C:\Windows\System32\drivers\iaLPSS2_I2C.sys [185128 2015-06-16] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21344 2015-09-04] (Acer Incorporated)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-24] (Malwarebytes)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation)
S3 Qcamain; C:\Windows\System32\drivers\Qcamainx64.sys [2276352 2015-07-10] (Qualcomm Atheros, Inc.)
R3 Qcamain10x64; C:\Windows\system32\DRIVERS\Qcamain10x64.sys [2340240 2015-07-20] (Qualcomm Atheros, Inc.)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14688 2015-09-04] (Acer Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-05] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 SGXEPC; C:\Windows\System32\drivers\sgx_driver.sys [54760 2016-07-22] (Windows (R) Win 7 DDK provider)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [47784 2015-07-29] (Synaptics Incorporated)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-08-11] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-30 04:28 - 2016-08-30 04:29 - 00020716 _____ C:\Users\Rafael Sobreiro\Desktop\FRST.txt
2016-08-30 04:28 - 2016-08-30 04:28 - 00000000 ____D C:\FRST
2016-08-30 04:26 - 2016-08-30 04:28 - 02397696 _____ (Farbar) C:\Users\Rafael Sobreiro\Desktop\FRST64.exe
2016-08-30 01:08 - 2016-08-30 01:08 - 00016148 _____ C:\Windows\system32\LAPTOP-8E1TS1M5_Rafael Sobreiro_HistoryPrediction.bin
2016-08-29 20:33 - 2016-08-29 20:34 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2819425019_spectate.bat
2016-08-29 16:33 - 2016-08-29 16:33 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2818659478_spectate.bat
2016-08-29 16:01 - 2016-08-29 16:01 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2818655882_spectate.bat
2016-08-29 01:23 - 2016-08-29 01:23 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2818191346_spectate.bat
2016-08-28 21:57 - 2016-08-28 21:58 - 00005994 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2816732061_replay (1).bat
2016-08-28 21:14 - 2016-08-28 21:14 - 00005994 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2816732061_replay.bat
2016-08-28 20:35 - 2016-08-28 20:35 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2817808965_spectate.bat
2016-08-28 08:57 - 2016-08-28 08:58 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2816734419_spectate.bat
2016-08-27 14:51 - 2016-08-27 14:51 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2815579894_spectate.bat
2016-08-27 13:57 - 2016-08-27 13:59 - 129545180 _____ C:\Users\Rafael Sobreiro\Downloads\Crystal Castles Live @ Reading 2016.mp4
2016-08-25 21:53 - 2016-08-25 23:07 - 00000000 ____D C:\Users\Rafael Sobreiro\Desktop\X
2016-08-25 21:22 - 2016-08-25 21:34 - 00000000 ____D C:\Users\Rafael Sobreiro\Desktop\Omega Ruby
2016-08-25 20:56 - 2016-08-25 20:57 - 00005992 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2270917110_replay (1).bat
2016-08-25 19:54 - 2016-08-25 19:54 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2813287350_spectate.bat
2016-08-25 19:43 - 2016-08-25 19:43 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2813281988_spectate.bat
2016-08-25 19:30 - 2016-08-25 19:30 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2813245867_spectate.bat
2016-08-25 17:25 - 2016-08-25 17:25 - 00844597 _____ C:\Users\Rafael Sobreiro\Downloads\Forest Guardian Janna v1 (By Damonix).wxy
2016-08-25 15:41 - 2016-08-25 15:41 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2812980127_spectate.bat
2016-08-25 15:02 - 2016-08-25 15:02 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2812981339_spectate.bat
2016-08-25 14:51 - 2016-08-25 14:51 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2812914913_spectate.bat
2016-08-25 13:23 - 2016-08-25 13:23 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2812854945_spectate.bat
2016-08-25 12:31 - 2016-08-25 12:31 - 04914507 _____ C:\Users\Rafael Sobreiro\Downloads\Lime and Hot Pink v6.7 (By LoneOkami).wxy
2016-08-25 03:14 - 2016-08-25 03:15 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2812218434_spectate.bat
2016-08-24 23:56 - 2016-08-24 23:57 - 00000000 ___HD C:\$WINDOWS.~BT
2016-08-24 19:47 - 2016-08-24 19:47 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2811841384_spectate.bat
2016-08-24 19:45 - 2016-08-24 19:45 - 00005991 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2811816176_spectate.bat
2016-08-24 18:30 - 2016-08-24 18:30 - 01085539 _____ C:\Users\Rafael Sobreiro\Downloads\ChampionSkinList.jpeg
2016-08-20 22:08 - 2016-08-20 22:08 - 00005992 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2270917110_replay.bat
2016-08-20 22:01 - 2016-08-20 22:01 - 00005992 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2271703264_replay.bat
2016-08-19 23:04 - 2016-08-19 23:08 - 00000000 ____D C:\Users\Rafael Sobreiro\Desktop\Nova pasta
2016-08-18 13:51 - 2016-08-18 13:51 - 00005906 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268313055_replay (1).bat
2016-08-18 13:49 - 2016-08-18 13:49 - 00005902 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269849539_spectate (3).bat
2016-08-18 13:49 - 2016-08-18 13:49 - 00005902 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269849539_spectate (2).bat
2016-08-18 13:48 - 2016-08-18 13:48 - 00005902 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269849539_spectate (1).bat
2016-08-18 13:46 - 2016-08-18 13:47 - 00005902 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269849539_spectate.bat
2016-08-17 20:03 - 2016-08-17 20:04 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269331971_spectate.bat
2016-08-17 18:08 - 2016-08-17 18:08 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269294665_spectate.bat
2016-08-17 17:21 - 2016-08-17 17:22 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269282885_spectate.bat
2016-08-17 15:30 - 2016-08-17 16:56 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269207620_spectate.bat
2016-08-17 14:45 - 2016-08-17 14:46 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269225670_spectate.bat
2016-08-17 13:43 - 2016-08-17 13:43 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2269224689_spectate.bat
2016-08-17 13:18 - 2016-08-17 13:52 - 106222323 _____ C:\Users\Rafael Sobreiro\Downloads\cc2016.rar
2016-08-16 22:41 - 2016-08-16 22:41 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268481313_spectate.bat
2016-08-16 22:03 - 2016-08-16 22:03 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268465687_spectate.bat
2016-08-16 21:30 - 2016-08-16 21:30 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268461836_spectate.bat
2016-08-16 20:34 - 2016-08-16 20:34 - 00005924 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268313055_replay.bat
2016-08-16 20:31 - 2016-08-16 20:32 - 00005924 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268247364_replay.bat
2016-08-16 13:39 - 2016-08-16 13:39 - 00003382 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task
2016-08-16 13:08 - 2016-08-16 13:09 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268247364_spectate.bat
2016-08-16 12:23 - 2016-08-16 12:29 - 00005920 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2268256266_spectate.bat
2016-08-15 15:10 - 2016-08-15 15:10 - 00001034 _____ C:\Users\Rafael Sobreiro\AppData\Local\recently-used.xbel
2016-08-15 14:38 - 2016-08-15 15:10 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\gtk-2.0
2016-08-13 21:40 - 2016-08-13 21:40 - 00000000 ____D C:\Users\Rafael Sobreiro\.thumbnails
2016-08-13 21:38 - 2016-08-16 05:11 - 00000000 ____D C:\Users\Rafael Sobreiro\.gimp-2.8
2016-08-13 21:38 - 2016-08-13 21:38 - 00000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2016-08-13 21:38 - 2016-08-13 21:38 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\gegl-0.2
2016-08-13 21:38 - 2016-08-13 21:38 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\fontconfig
2016-08-13 21:37 - 2016-08-13 21:38 - 00000000 ____D C:\Program Files\GIMP 2
2016-08-13 21:05 - 2016-08-13 21:37 - 77404656 _____ (The GIMP Team ) C:\Users\Rafael Sobreiro\Downloads\gimp-2.8.18-setup.exe
2016-08-13 17:48 - 2016-08-13 17:48 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-08-12 15:01 - 2016-08-12 15:02 - 00000834 _____ C:\DelFix.txt
2016-08-12 13:53 - 2016-08-12 13:54 - 00005924 _____ C:\Users\Rafael Sobreiro\Downloads\LOL_OPGG_Observer_2264013632_replay.bat
2016-08-12 04:52 - 2016-08-12 04:52 - 00000026 _____ C:\Users\Rafael Sobreiro\Desktop\pokemon.txt
2016-08-12 04:19 - 2016-08-29 02:20 - 00000000 ____D C:\Users\Rafael Sobreiro\Desktop\azx
2016-08-12 03:58 - 2016-08-12 03:59 - 00000000 ____D C:\Users\Rafael Sobreiro\Desktop\CC
2016-08-12 03:31 - 2016-08-12 03:37 - 347825742 _____ C:\Users\Rafael Sobreiro\Downloads\crystal castles ultra 2013.rar
2016-08-12 00:21 - 2016-08-12 00:21 - 00002348 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-12 00:21 - 2016-08-12 00:21 - 00002336 _____ C:\Users\Rafael Sobreiro\Desktop\Google Chrome.lnk
2016-08-12 00:20 - 2016-08-30 03:31 - 00001048 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-12 00:20 - 2016-08-30 00:49 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-12 00:20 - 2016-08-12 00:26 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-12 00:20 - 2016-08-12 00:26 - 00003874 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-12 00:19 - 2016-08-12 00:20 - 00987728 _____ (Google Inc.) C:\Users\Rafael Sobreiro\Downloads\ChromeSetup(1).exe
2016-08-11 22:00 - 2016-08-11 22:00 - 00000084 _____ C:\Users\Rafael Sobreiro\Desktop\edits.txt
2016-08-11 21:57 - 2016-08-11 21:57 - 00000207 _____ C:\Windows\tweaking.com-regbackup-LAPTOP-8E1TS1M5-Windows-10-Home-(64-bit).dat
2016-08-11 21:56 - 2016-08-11 21:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2016-08-11 21:56 - 2016-08-11 21:56 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2016-08-11 21:55 - 2016-08-11 21:56 - 00018013 _____ C:\Windows\Tweaking.com - Registry Backup Setup Log.txt
2016-08-11 17:28 - 2016-08-11 17:28 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\VS Revo Group
2016-08-11 17:28 - 2016-08-11 17:28 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-08-11 17:28 - 2016-08-11 17:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2016-08-11 17:28 - 2016-08-11 17:28 - 00000000 ____D C:\Program Files\VS Revo Group
2016-08-11 17:28 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2016-08-11 17:27 - 2016-08-11 17:27 - 11374528 _____ (VS Revo Group ) C:\Users\Rafael Sobreiro\Downloads\RevoUninProSetup.exe
2016-08-11 02:54 - 2016-08-11 15:09 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-08-11 02:53 - 2016-08-11 02:53 - 00000000 ____D C:\ProgramData\RogueKiller
2016-08-11 02:53 - 2016-08-11 02:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2016-08-11 02:53 - 2016-08-11 02:53 - 00000000 ____D C:\Program Files\RogueKiller
2016-08-11 02:51 - 2016-08-11 02:52 - 34613896 _____ (Adlice Software ) C:\Users\Rafael Sobreiro\Downloads\setup.exe
2016-08-10 17:43 - 2016-08-10 17:43 - 00318896 _____ C:\Windows\Minidump\081016-18078-01.dmp
2016-08-10 08:00 - 2016-08-10 08:00 - 00000512 _____ C:\Users\Rafael Sobreiro\Documents\MBR.dat
2016-08-09 23:09 - 2016-07-02 05:34 - 00828408 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-08-09 23:09 - 2016-07-02 05:34 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-08-09 20:15 - 2016-08-09 20:19 - 00000000 ____D C:\Windows\system32\MRT
2016-08-09 20:15 - 2016-08-09 20:15 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-09 18:48 - 2016-08-03 07:24 - 02152744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-08-09 18:48 - 2016-08-03 07:24 - 01356368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2016-08-09 18:48 - 2016-08-03 07:24 - 00439648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2016-08-09 18:48 - 2016-08-03 07:24 - 00046480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wldp.dll
2016-08-09 18:48 - 2016-08-03 07:15 - 00468832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-08-09 18:48 - 2016-08-03 07:14 - 00565648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2016-08-09 18:48 - 2016-08-03 07:09 - 00185952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2016-08-09 18:48 - 2016-08-03 06:46 - 08016728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-08-09 18:48 - 2016-08-03 06:46 - 03467776 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2016-08-09 18:48 - 2016-08-03 06:46 - 02463704 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-08-09 18:48 - 2016-08-03 06:46 - 01538168 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-08-09 18:48 - 2016-08-03 06:46 - 00552288 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2016-08-09 18:48 - 2016-08-03 06:46 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2016-08-09 18:48 - 2016-08-03 06:44 - 02429792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2016-08-09 18:48 - 2016-08-03 06:44 - 02115936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-08-09 18:48 - 2016-08-03 06:39 - 00660320 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-08-09 18:48 - 2016-08-03 06:38 - 06525424 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2016-08-09 18:48 - 2016-08-03 06:38 - 00724168 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2016-08-09 18:48 - 2016-08-03 06:03 - 16708608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-09 18:48 - 2016-08-03 05:57 - 24604160 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-09 18:48 - 2016-08-03 05:57 - 21862912 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-08-09 18:48 - 2016-08-03 05:57 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-09 18:48 - 2016-08-03 05:54 - 11557888 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-08-09 18:48 - 2016-08-03 05:53 - 13027328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2016-08-09 18:48 - 2016-08-03 05:53 - 07569408 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2016-08-09 18:48 - 2016-08-03 05:52 - 02418688 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-08-09 18:48 - 2016-08-03 05:49 - 00371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2016-08-09 18:48 - 2016-08-03 05:46 - 02238464 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-08-09 18:48 - 2016-08-03 05:46 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2016-08-09 18:48 - 2016-08-03 05:45 - 14241792 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-08-09 18:48 - 2016-08-03 05:45 - 12514304 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-09 18:48 - 2016-08-03 05:44 - 19337216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-09 18:48 - 2016-08-03 05:44 - 09889792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-08-09 18:48 - 2016-08-03 05:40 - 01918976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-08-09 18:48 - 2016-08-03 05:39 - 00846848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
2016-08-09 18:48 - 2016-08-03 05:39 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-09 18:48 - 2016-08-03 05:38 - 06101504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2016-08-09 18:48 - 2016-08-03 05:36 - 07524352 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-08-09 18:48 - 2016-08-03 05:36 - 07502848 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-08-09 18:48 - 2016-08-03 05:35 - 18799616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-08-09 18:48 - 2016-08-03 05:35 - 04791296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-09 18:48 - 2016-08-03 05:35 - 03584000 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-08-09 18:48 - 2016-08-03 05:35 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-08-09 18:48 - 2016-08-03 05:34 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2016-08-09 18:48 - 2016-08-03 05:33 - 12589056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-08-09 18:48 - 2016-08-03 05:32 - 00939008 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2016-08-09 18:48 - 2016-08-03 05:32 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-09 18:48 - 2016-08-03 05:28 - 03579392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-09 18:48 - 2016-08-03 05:27 - 11270656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-09 18:48 - 2016-08-03 05:26 - 06713856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2016-08-09 18:48 - 2016-08-03 05:26 - 05454848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-08-09 18:48 - 2016-08-03 05:22 - 00716288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2016-08-09 18:48 - 2016-06-24 05:07 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2016-08-09 18:48 - 2016-06-24 04:45 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-08-09 18:48 - 2016-06-24 04:45 - 00282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2016-08-09 18:48 - 2016-06-24 04:43 - 00841728 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-08-09 18:48 - 2016-06-24 04:42 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2016-08-09 18:48 - 2016-06-24 04:15 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-08-09 18:48 - 2016-05-28 06:02 - 06488312 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2016-08-09 18:48 - 2016-05-28 05:52 - 22326760 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-08-09 18:48 - 2016-05-28 05:38 - 05118024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-08-09 18:48 - 2016-05-28 05:27 - 20861984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-08-09 18:48 - 2016-05-28 05:10 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2016-08-09 18:48 - 2016-05-28 05:00 - 01336832 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-08-09 18:48 - 2016-05-28 04:58 - 00672256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-08-09 18:48 - 2016-05-28 04:58 - 00410624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-08-09 18:48 - 2016-05-28 04:58 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-08-09 18:48 - 2016-05-28 04:54 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2016-08-09 18:48 - 2016-05-28 04:53 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2016-08-09 18:48 - 2016-05-28 04:44 - 00737792 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2016-08-09 18:48 - 2016-05-28 04:44 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-08-09 18:48 - 2016-05-28 04:43 - 00240128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-08-09 18:48 - 2016-05-28 04:41 - 00272896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2016-08-09 18:48 - 2016-05-28 04:38 - 00291328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2016-08-09 18:48 - 2016-05-28 04:29 - 00502272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2016-08-09 18:48 - 2016-05-28 04:29 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-08-09 18:48 - 2016-04-09 11:06 - 01981280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-08-09 18:48 - 2016-04-09 11:05 - 00331616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2016-08-09 18:48 - 2016-04-09 10:50 - 01515936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2016-08-09 18:48 - 2016-04-09 10:04 - 01780352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2016-08-09 18:48 - 2016-04-09 09:09 - 00650240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-09 18:48 - 2016-04-09 08:55 - 00373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-09 18:48 - 2016-04-09 08:54 - 00768000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-09 18:48 - 2016-04-09 08:52 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2016-08-09 18:48 - 2016-04-09 08:38 - 00464384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2016-08-09 18:48 - 2016-04-09 08:22 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2016-08-09 18:48 - 2016-04-09 07:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-09 18:48 - 2016-04-09 07:42 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-09 18:48 - 2016-04-09 07:41 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2016-08-09 18:48 - 2016-04-09 07:27 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2016-08-09 18:48 - 2016-03-16 05:45 - 00140536 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2016-08-09 18:48 - 2016-03-16 05:37 - 01010016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2016-08-09 18:48 - 2016-03-16 04:47 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2016-08-09 18:48 - 2016-03-16 04:45 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthLEEnum.sys
2016-08-09 18:48 - 2016-03-16 04:40 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2016-08-09 18:48 - 2016-03-16 04:39 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-08-09 18:48 - 2016-03-16 04:38 - 01423872 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2016-08-09 18:48 - 2016-03-16 04:37 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
2016-08-09 18:48 - 2016-03-16 04:37 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 01205248 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\CallHistoryClient.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\UserDataPlatformHelperUtil.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTypeHelperUtil.dll
2016-08-09 18:48 - 2016-03-16 04:36 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataLanguageUtil.dll
2016-08-09 18:48 - 2016-03-16 04:27 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-08-09 18:48 - 2016-03-16 04:18 - 00104960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2016-08-09 18:48 - 2016-03-16 04:16 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-08-09 18:48 - 2016-03-16 04:13 - 00928256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2016-08-09 18:48 - 2016-03-16 04:13 - 00223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
2016-08-09 18:48 - 2016-03-16 04:13 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2016-08-09 18:48 - 2016-02-23 15:51 - 00633184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2016-08-09 18:48 - 2016-02-23 15:41 - 00299600 _____ (Microsoft Corporation) C:\Windows\system32\WMASF.DLL
2016-08-09 18:48 - 2016-02-23 15:11 - 00781984 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-08-09 18:48 - 2016-02-23 15:11 - 00103776 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2016-08-09 18:48 - 2016-02-23 14:11 - 00249976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMASF.DLL
2016-08-09 18:48 - 2016-02-23 13:50 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\NetCfgNotifyObjectHost.exe
2016-08-09 18:48 - 2016-02-23 13:42 - 00658536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-08-09 18:48 - 2016-02-23 13:42 - 00078176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2016-08-09 18:48 - 2016-02-23 13:20 - 00138240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-08-09 18:48 - 2016-02-23 12:59 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rasl2tp.sys
2016-08-09 18:48 - 2016-02-23 12:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-08-09 18:48 - 2016-02-23 12:37 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe
2016-08-09 18:48 - 2016-02-23 11:45 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-08-09 18:48 - 2016-01-31 07:25 - 01248896 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2016-08-09 18:48 - 2016-01-31 07:06 - 00809336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2016-08-09 18:48 - 2016-01-31 06:34 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\ngckeyenum.dll
2016-08-09 18:48 - 2016-01-31 06:26 - 03793408 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-08-09 18:48 - 2016-01-31 06:25 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-08-09 18:48 - 2016-01-31 06:23 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-08-09 18:48 - 2016-01-31 06:17 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2016-08-09 18:48 - 2016-01-31 06:11 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2016-08-09 18:48 - 2016-01-31 06:04 - 00100352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2016-08-09 18:48 - 2016-01-05 04:06 - 01063504 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2016-08-09 18:48 - 2016-01-05 04:06 - 00119800 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-08-09 18:48 - 2016-01-05 04:04 - 02824248 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-08-09 18:48 - 2016-01-05 04:04 - 00784136 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-08-09 18:48 - 2016-01-05 04:04 - 00779928 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-08-09 18:48 - 2016-01-05 04:04 - 00233992 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2016-08-09 18:48 - 2016-01-05 04:04 - 00090912 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-08-09 18:48 - 2016-01-05 03:30 - 00882208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2016-08-09 18:48 - 2016-01-05 03:30 - 00100712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-08-09 18:48 - 2016-01-05 03:29 - 00208688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2016-08-09 18:48 - 2016-01-05 03:28 - 02445128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2016-08-09 18:48 - 2016-01-05 03:28 - 00645144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-08-09 18:48 - 2016-01-05 03:28 - 00635312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-08-09 18:48 - 2016-01-05 03:28 - 00082096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2016-08-09 18:48 - 2016-01-05 03:15 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\usermgrcli.dll
2016-08-09 18:48 - 2016-01-05 03:02 - 01672192 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-08-09 18:48 - 2016-01-05 03:02 - 00678912 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-08-09 18:48 - 2016-01-05 03:02 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-08-09 18:48 - 2016-01-05 03:01 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-08-09 18:48 - 2016-01-05 02:57 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2016-08-09 18:48 - 2016-01-05 02:57 - 00578560 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-08-09 18:48 - 2016-01-05 02:32 - 01541632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-08-09 18:48 - 2016-01-05 02:32 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-08-09 18:48 - 2016-01-05 02:31 - 00563200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-08-09 18:48 - 2016-01-05 02:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-08-09 18:48 - 2015-11-25 06:40 - 00516448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2016-08-09 18:48 - 2015-11-25 05:49 - 01569280 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2016-08-09 18:48 - 2015-11-25 05:30 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2016-08-09 18:48 - 2015-11-25 05:30 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2016-08-09 18:48 - 2015-11-25 05:28 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2016-08-09 18:48 - 2015-11-25 05:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\profext.dll
2016-08-09 18:48 - 2015-11-25 05:18 - 01233920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2016-08-09 18:48 - 2015-11-25 05:10 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2016-08-09 18:48 - 2015-11-25 05:07 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\profext.dll
2016-08-09 18:48 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2016-08-09 18:48 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2016-08-09 18:48 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2016-08-09 18:48 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2016-08-09 18:48 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2016-08-09 18:48 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-08-09 18:48 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-08-09 18:48 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-08-09 18:48 - 2015-10-01 04:03 - 00757760 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-08-09 18:48 - 2015-09-25 04:03 - 00796160 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2016-08-09 18:48 - 2015-09-25 03:37 - 00613376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2016-08-09 18:48 - 2015-09-17 07:50 - 00099664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2016-08-09 18:48 - 2015-09-17 07:49 - 00894256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2016-08-09 18:48 - 2015-09-17 07:48 - 00476760 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2016-08-09 18:48 - 2015-09-17 07:28 - 00074880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2016-08-09 18:48 - 2015-09-17 07:26 - 00434376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2016-08-09 18:48 - 2015-09-17 07:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\CellularAPI.dll
2016-08-09 18:48 - 2015-09-17 06:55 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx02000.dll
2016-08-09 18:48 - 2015-09-17 06:55 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\dmcsps.dll
2016-08-09 18:48 - 2015-09-17 06:50 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2016-08-09 18:48 - 2015-09-17 06:47 - 00513536 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2016-08-09 18:48 - 2015-09-17 06:45 - 00869376 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2016-08-09 18:48 - 2015-09-17 06:44 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2016-08-09 18:48 - 2015-09-17 06:29 - 00677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2016-08-09 18:48 - 2015-08-27 06:42 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2016-08-09 18:48 - 2015-08-27 06:42 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2016-08-09 18:48 - 2015-08-27 06:11 - 00484352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2016-08-09 18:48 - 2015-08-27 06:11 - 00139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2016-08-09 18:47 - 2016-08-03 07:25 - 00953472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-08-09 18:47 - 2016-08-03 07:25 - 00365120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2016-08-09 18:47 - 2016-08-03 07:24 - 01767008 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2016-08-09 18:47 - 2016-08-03 07:24 - 01531368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-08-09 18:47 - 2016-08-03 07:23 - 01895576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hevcdecoder.dll
2016-08-09 18:47 - 2016-08-03 07:22 - 01811360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2016-08-09 18:47 - 2016-08-03 07:15 - 02881624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 02816016 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2016-08-09 18:47 - 2016-08-03 06:46 - 01951864 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 01563480 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 01561360 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 01314496 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 00632680 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-08-09 18:47 - 2016-08-03 06:46 - 00432352 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-08-09 18:47 - 2016-08-03 06:44 - 02495776 _____ C:\Windows\system32\CoreUIComponents.dll
2016-08-09 18:47 - 2016-08-03 06:44 - 02156400 _____ (Microsoft Corporation) C:\Windows\system32\hevcdecoder.dll
2016-08-09 18:47 - 2016-08-03 06:44 - 00388896 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2016-08-09 18:47 - 2016-08-03 06:38 - 03625928 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-09 18:47 - 2016-08-03 06:33 - 00224704 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2016-08-09 18:47 - 2016-08-03 06:32 - 00983904 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2016-08-09 18:47 - 2016-08-03 06:09 - 00954368 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2016-08-09 18:47 - 2016-08-03 05:51 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2016-08-09 18:47 - 2016-08-03 05:50 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2016-08-09 18:47 - 2016-08-03 05:49 - 06305792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2016-08-09 18:47 - 2016-08-03 05:48 - 06788096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-09 18:47 - 2016-08-03 05:47 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-09 18:47 - 2016-08-03 05:47 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oemlicense.dll
2016-08-09 18:47 - 2016-08-03 05:47 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2016-08-09 18:47 - 2016-08-03 05:46 - 01416704 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-09 18:47 - 2016-08-03 05:46 - 00963072 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2016-08-09 18:47 - 2016-08-03 05:46 - 00780288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2016-08-09 18:47 - 2016-08-03 05:46 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-09 18:47 - 2016-08-03 05:46 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2016-08-09 18:47 - 2016-08-03 05:45 - 04847616 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2016-08-09 18:47 - 2016-08-03 05:44 - 00893440 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2016-08-09 18:47 - 2016-08-03 05:44 - 00814592 _____ (Microsoft Corporation) C:\Windows\system32\provcore.dll
2016-08-09 18:47 - 2016-08-03 05:44 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2016-08-09 18:47 - 2016-08-03 05:44 - 00328704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2016-08-09 18:47 - 2016-08-03 05:43 - 07055872 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2016-08-09 18:47 - 2016-08-03 05:43 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2016-08-09 18:47 - 2016-08-03 05:43 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2016-08-09 18:47 - 2016-08-03 05:42 - 02839040 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2016-08-09 18:47 - 2016-08-03 05:42 - 02598912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2016-08-09 18:47 - 2016-08-03 05:42 - 02253824 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2016-08-09 18:47 - 2016-08-03 05:42 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-08-09 18:47 - 2016-08-03 05:42 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\eappprxy.dll
2016-08-09 18:47 - 2016-08-03 05:41 - 04398592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2016-08-09 18:47 - 2016-08-03 05:41 - 03119104 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-09 18:47 - 2016-08-03 05:41 - 01823232 _____ C:\Windows\SysWOW64\InputService.dll
2016-08-09 18:47 - 2016-08-03 05:41 - 01686528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-09 18:47 - 2016-08-03 05:41 - 01606656 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-09 18:47 - 2016-08-03 05:40 - 05160960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-08-09 18:47 - 2016-08-03 05:40 - 00771072 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-08-09 18:47 - 2016-08-03 05:40 - 00572928 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-09 18:47 - 2016-08-03 05:40 - 00338944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-09 18:47 - 2016-08-03 05:39 - 05448704 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2016-08-09 18:47 - 2016-08-03 05:39 - 00806912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2016-08-09 18:47 - 2016-08-03 05:39 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-09 18:47 - 2016-08-03 05:39 - 00587776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-08-09 18:47 - 2016-08-03 05:39 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-09 18:47 - 2016-08-03 05:38 - 03873280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2016-08-09 18:47 - 2016-08-03 05:38 - 03527168 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2016-08-09 18:47 - 2016-08-03 05:38 - 00819712 _____ (Microsoft Corporation) C:\Windows\system32\licensingdiag.exe
2016-08-09 18:47 - 2016-08-03 05:38 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2016-08-09 18:47 - 2016-08-03 05:38 - 00239104 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2016-08-09 18:47 - 2016-08-03 05:37 - 04453888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2016-08-09 18:47 - 2016-08-03 05:37 - 04168704 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2016-08-09 18:47 - 2016-08-03 05:37 - 02558976 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2016-08-09 18:47 - 2016-08-03 05:36 - 00671232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2016-08-09 18:47 - 2016-08-03 05:36 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\provcore.dll
2016-08-09 18:47 - 2016-08-03 05:36 - 00279552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2016-08-09 18:47 - 2016-08-03 05:36 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2016-08-09 18:47 - 2016-08-03 05:36 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\WPTaskScheduler.dll
2016-08-09 18:47 - 2016-08-03 05:35 - 01717760 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-08-09 18:47 - 2016-08-03 05:35 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2016-08-09 18:47 - 2016-08-03 05:35 - 00832512 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2016-08-09 18:47 - 2016-08-03 05:35 - 00243712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2016-08-09 18:47 - 2016-08-03 05:35 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappprxy.dll
2016-08-09 18:47 - 2016-08-03 05:34 - 01522176 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-08-09 18:47 - 2016-08-03 05:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-08-09 18:47 - 2016-08-03 05:33 - 02587136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-09 18:47 - 2016-08-03 05:33 - 02198016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2016-08-09 18:47 - 2016-08-03 05:33 - 01844736 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2016-08-09 18:47 - 2016-08-03 05:33 - 01387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-09 18:47 - 2016-08-03 05:32 - 05079552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2016-08-09 18:47 - 2016-08-03 05:32 - 01492992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-09 18:47 - 2016-08-03 05:32 - 00794112 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2016-08-09 18:47 - 2016-08-03 05:32 - 00679936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-09 18:47 - 2016-08-03 05:32 - 00574464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2016-08-09 18:47 - 2016-08-03 05:32 - 00088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2016-08-09 18:47 - 2016-08-03 05:31 - 05329408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2016-08-09 18:47 - 2016-08-03 05:31 - 01096192 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2016-08-09 18:47 - 2016-08-03 05:31 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\DbgModel.dll
2016-08-09 18:47 - 2016-08-03 05:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2016-08-09 18:47 - 2016-08-03 05:30 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2016-08-09 18:47 - 2016-08-03 05:30 - 00617472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licensingdiag.exe
2016-08-09 18:47 - 2016-08-03 05:30 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2016-08-09 18:47 - 2016-08-03 05:30 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\dbgcore.dll
2016-08-09 18:47 - 2016-08-03 05:28 - 03692032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2016-08-09 18:47 - 2016-08-03 05:27 - 03443200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2016-08-09 18:47 - 2016-08-03 05:27 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2016-08-09 18:47 - 2016-08-03 05:26 - 01467392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-08-09 18:47 - 2016-08-03 05:25 - 00565760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2016-08-09 18:47 - 2016-08-03 05:21 - 00854016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2016-08-09 18:47 - 2016-08-03 05:21 - 00404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DbgModel.dll
2016-08-09 18:47 - 2016-08-03 05:21 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2016-08-09 18:47 - 2016-08-03 05:20 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgcore.dll
2016-08-09 18:47 - 2016-06-25 06:38 - 01119744 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-08-09 18:47 - 2016-06-24 05:56 - 01823760 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-08-09 18:47 - 2016-06-24 05:25 - 01522632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-08-09 18:47 - 2016-06-24 04:55 - 01012736 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2016-08-09 18:47 - 2016-06-24 04:44 - 05510656 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-08-09 18:47 - 2016-06-24 04:42 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2016-08-09 18:47 - 2016-06-24 04:22 - 04737536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-08-09 18:47 - 2016-06-24 04:22 - 00309248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2016-08-09 18:47 - 2016-05-28 06:02 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-08-09 18:47 - 2016-05-28 06:02 - 00421536 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-08-09 18:47 - 2016-05-28 06:00 - 02543784 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2016-08-09 18:47 - 2016-05-28 06:00 - 01591304 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-08-09 18:47 - 2016-05-28 06:00 - 00203496 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2016-08-09 18:47 - 2016-05-28 05:59 - 00363872 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-08-09 18:47 - 2016-05-28 05:47 - 00613120 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2016-08-09 18:47 - 2016-05-28 05:47 - 00379232 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-08-09 18:47 - 2016-05-28 05:39 - 04047288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-08-09 18:47 - 2016-05-28 05:39 - 01365584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-08-09 18:47 - 2016-05-28 05:38 - 00372368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2016-08-09 18:47 - 2016-05-28 05:38 - 00306528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2016-08-09 18:47 - 2016-05-28 05:35 - 02188472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-08-09 18:47 - 2016-05-28 05:35 - 00183904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2016-08-09 18:47 - 2016-05-28 05:21 - 00545400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2016-08-09 18:47 - 2016-05-28 05:21 - 00316256 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-08-09 18:47 - 2016-05-28 05:09 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2016-08-09 18:47 - 2016-05-28 04:54 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-08-09 18:47 - 2016-05-28 04:52 - 02663424 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-08-09 18:47 - 2016-05-28 04:51 - 02119680 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-09 18:47 - 2016-05-28 04:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-08-09 18:47 - 2016-05-28 04:39 - 00667648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-08-09 18:47 - 2016-05-28 04:39 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2016-08-09 18:47 - 2016-05-28 04:38 - 01821696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2016-08-09 18:47 - 2016-05-28 04:35 - 02042368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-09 18:47 - 2016-04-15 07:06 - 00602624 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-08-09 18:47 - 2016-04-15 06:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2016-08-09 18:47 - 2016-04-09 11:53 - 01535032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-08-09 18:47 - 2016-04-09 11:52 - 00502504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2016-08-09 18:47 - 2016-04-09 11:10 - 01824872 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-08-09 18:47 - 2016-04-09 11:10 - 00609976 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2016-08-09 18:47 - 2016-04-09 08:06 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-09 18:47 - 2016-03-16 05:56 - 01022664 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-08-09 18:47 - 2016-03-16 05:56 - 00861512 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2016-08-09 18:47 - 2016-03-16 05:55 - 01299032 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-08-09 18:47 - 2016-03-16 05:55 - 01127024 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-08-09 18:47 - 2016-03-16 05:54 - 00595016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2016-08-09 18:47 - 2016-03-16 04:56 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\PhoneCallHistoryApis.dll
2016-08-09 18:47 - 2016-03-16 04:55 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll
2016-08-09 18:47 - 2016-03-16 04:55 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\ExtrasXmlParser.dll
2016-08-09 18:47 - 2016-03-16 04:51 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-08-09 18:47 - 2016-03-16 04:49 - 00850432 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-08-09 18:47 - 2016-03-16 04:44 - 01016832 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2016-08-09 18:47 - 2016-03-16 04:42 - 02180608 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-08-09 18:47 - 2016-03-16 04:42 - 01290240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2016-08-09 18:47 - 2016-03-16 04:40 - 00931840 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2016-08-09 18:47 - 2016-03-16 04:40 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2016-08-09 18:47 - 2016-03-16 04:40 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2016-08-09 18:47 - 2016-03-16 04:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll
2016-08-09 18:47 - 2016-03-16 04:40 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-08-09 18:47 - 2016-03-16 04:39 - 03363328 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-08-09 18:47 - 2016-03-16 04:37 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2016-08-09 18:47 - 2016-03-16 04:37 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
2016-08-09 18:47 - 2016-03-16 04:37 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\FontProvider.dll
2016-08-09 18:47 - 2016-03-16 04:36 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2016-08-09 18:47 - 2016-03-16 04:36 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\cemapi.dll
2016-08-09 18:47 - 2016-03-16 04:36 - 00195072 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2016-08-09 18:47 - 2016-03-16 04:36 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\POSyncServices.dll
2016-08-09 18:47 - 2016-03-16 04:35 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-09 18:47 - 2016-03-16 04:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\AppxApplicabilityEngine.dll
2016-08-09 18:47 - 2016-03-16 04:35 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2016-08-09 18:47 - 2016-03-16 04:35 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2016-08-09 18:47 - 2016-03-16 04:34 - 01871872 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-08-09 18:47 - 2016-03-16 04:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2016-08-09 18:47 - 2016-03-16 04:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2016-08-09 18:47 - 2016-03-16 04:31 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhoneCallHistoryApis.dll
2016-08-09 18:47 - 2016-03-16 04:17 - 03680256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2016-08-09 18:47 - 2016-03-16 04:17 - 00842240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2016-08-09 18:47 - 2016-03-16 04:17 - 00168448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2016-08-09 18:47 - 2016-03-16 04:17 - 00133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll
2016-08-09 18:47 - 2016-03-16 04:17 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-08-09 18:47 - 2016-03-16 04:14 - 00625152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2016-08-09 18:47 - 2016-03-16 04:14 - 00579584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll
2016-08-09 18:47 - 2016-03-16 04:14 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll
2016-08-09 18:47 - 2016-03-16 04:13 - 00525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2016-08-09 18:47 - 2016-03-16 04:13 - 00201216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cemapi.dll
2016-08-09 18:47 - 2016-03-16 04:13 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2016-08-09 18:47 - 2016-03-16 04:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataLanguageUtil.dll
2016-08-09 18:47 - 2016-03-16 04:11 - 01594368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-08-09 18:47 - 2016-02-23 15:41 - 01150816 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-08-09 18:47 - 2016-02-23 15:38 - 00272752 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2016-08-09 18:47 - 2016-02-23 14:25 - 01085632 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-08-09 18:47 - 2016-02-23 14:09 - 00229352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2016-08-09 18:47 - 2016-02-23 12:59 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\NetworkBindingEngineMigPlugin.dll
2016-08-09 18:47 - 2016-02-23 12:45 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\serial.sys
2016-08-09 18:47 - 2016-02-23 12:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2016-08-09 18:47 - 2016-02-23 12:04 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2016-08-09 18:47 - 2016-02-23 12:03 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2016-08-09 18:47 - 2016-02-23 11:51 - 00915456 _____ (Microsoft Corporation) C:\Windows\system32\configurationclient.dll
2016-08-09 18:47 - 2016-02-23 11:51 - 00678912 _____ (Microsoft Corporation) C:\Windows\system32\scapi.dll
2016-08-09 18:47 - 2016-02-23 11:46 - 00400384 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2016-08-09 18:47 - 2016-02-23 11:45 - 01844736 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2016-08-09 18:47 - 2016-02-23 11:17 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2016-08-09 18:47 - 2016-02-23 11:03 - 01495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2016-08-09 18:47 - 2016-01-31 07:23 - 02601160 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2016-08-09 18:47 - 2016-01-31 07:23 - 01420392 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-08-09 18:47 - 2016-01-31 07:04 - 01180696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-08-09 18:47 - 2016-01-31 06:33 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\IoTAssignedAccessLockFramework.dll
2016-08-09 18:47 - 2016-01-31 06:22 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2016-08-09 18:47 - 2016-01-31 06:19 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\NetworkDesktopSettings.dll
2016-08-09 18:47 - 2016-01-31 06:19 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IoTAssignedAccessLockFramework.dll
2016-08-09 18:47 - 2016-01-05 04:07 - 00377592 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2016-08-09 18:47 - 2016-01-05 04:06 - 01991120 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2016-08-09 18:47 - 2016-01-05 04:06 - 01270104 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-08-09 18:47 - 2016-01-05 04:04 - 02641928 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00862056 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-08-09 18:47 - 2016-01-05 04:04 - 00787720 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00772448 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-08-09 18:47 - 2016-01-05 04:04 - 00751992 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00667856 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-08-09 18:47 - 2016-01-05 04:04 - 00250520 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00249464 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00115704 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2016-08-09 18:47 - 2016-01-05 04:04 - 00083704 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2016-08-09 18:47 - 2016-01-05 03:52 - 00441696 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-08-09 18:47 - 2016-01-05 03:50 - 00723648 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-08-09 18:47 - 2016-01-05 03:50 - 00345080 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-08-09 18:47 - 2016-01-05 03:50 - 00251544 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2016-08-09 18:47 - 2016-01-05 03:50 - 00205072 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2016-08-09 18:47 - 2016-01-05 03:30 - 02459096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2016-08-09 18:47 - 2016-01-05 03:30 - 02162064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2016-08-09 18:47 - 2016-01-05 03:30 - 01106872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2016-08-09 18:47 - 2016-01-05 03:30 - 00368776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2016-08-09 18:47 - 2016-01-05 03:30 - 00232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2016-08-09 18:47 - 2016-01-05 03:28 - 00714808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2016-08-09 18:47 - 2016-01-05 03:28 - 00696192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2016-08-09 18:47 - 2016-01-05 03:28 - 00695752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-08-09 18:47 - 2016-01-05 03:28 - 00497896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-08-09 18:47 - 2016-01-05 03:28 - 00277400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2016-08-09 18:47 - 2016-01-05 03:28 - 00107952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2016-08-09 18:47 - 2016-01-05 03:28 - 00072808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2016-08-09 18:47 - 2016-01-05 03:15 - 00931328 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-08-09 18:47 - 2016-01-05 03:10 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\mfh264enc.dll
2016-08-09 18:47 - 2016-01-05 03:10 - 00305776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2016-08-09 18:47 - 2016-01-05 03:10 - 00278424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2016-08-09 18:47 - 2016-01-05 03:10 - 00188032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2016-08-09 18:47 - 2016-01-05 03:09 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-08-09 18:47 - 2016-01-05 02:51 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-08-09 18:47 - 2016-01-05 02:51 - 01009664 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-08-09 18:47 - 2016-01-05 02:51 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2016-08-09 18:47 - 2016-01-05 02:51 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2016-08-09 18:47 - 2016-01-05 02:51 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2016-08-09 18:47 - 2016-01-05 02:42 - 00871936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-08-09 18:47 - 2016-01-05 02:38 - 00556032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfh264enc.dll
2016-08-09 18:47 - 2016-01-05 02:20 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-08-09 18:47 - 2016-01-05 02:19 - 01070080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-08-09 18:47 - 2016-01-05 02:19 - 00747008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2016-08-09 18:47 - 2016-01-05 02:19 - 00409088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2016-08-09 18:47 - 2016-01-05 02:19 - 00404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2016-08-09 18:47 - 2015-11-25 06:27 - 01366680 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-08-09 18:47 - 2015-11-25 06:09 - 01310880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-08-09 18:47 - 2015-11-25 05:49 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2016-08-09 18:47 - 2015-11-25 05:49 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\RasMediaManager.dll
2016-08-09 18:47 - 2015-11-25 05:48 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\EthernetMediaManager.dll
2016-08-09 18:47 - 2015-11-25 05:48 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\DAMediaManager.dll
2016-08-09 18:47 - 2015-11-25 05:37 - 02350592 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-08-09 18:47 - 2015-11-25 05:36 - 01710592 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2016-08-09 18:47 - 2015-11-25 05:35 - 00929792 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2016-08-09 18:47 - 2015-11-25 05:35 - 00845824 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
2016-08-09 18:47 - 2015-11-25 05:31 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\DAMM.dll
2016-08-09 18:47 - 2015-11-25 05:30 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\dot3mm.dll
2016-08-09 18:47 - 2015-11-25 05:29 - 01649152 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2016-08-09 18:47 - 2015-11-25 05:29 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\ninput.dll
2016-08-09 18:47 - 2015-11-25 05:23 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-09 18:47 - 2015-11-25 05:22 - 00603648 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll
2016-08-09 18:47 - 2015-11-25 05:17 - 00774656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2016-08-09 18:47 - 2015-11-25 05:16 - 01442816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRHInproc.dll
2016-08-09 18:47 - 2015-11-25 05:16 - 00786432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
2016-08-09 18:47 - 2015-11-25 05:13 - 02153984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-08-09 18:47 - 2015-11-25 05:11 - 00296960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ninput.dll
2016-08-09 18:47 - 2015-11-25 05:10 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2016-08-09 18:47 - 2015-11-25 05:08 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2016-08-09 18:47 - 2015-11-25 05:04 - 00480768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\duser.dll
2016-08-09 18:47 - 2015-11-25 05:04 - 00474624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-08-09 18:47 - 2015-11-25 03:52 - 00775312 _____ C:\Windows\SysWOW64\locale.nls
2016-08-09 18:47 - 2015-11-25 03:52 - 00775312 _____ C:\Windows\system32\locale.nls
2016-08-09 18:47 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2016-08-09 18:47 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-08-09 18:47 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2016-08-09 18:47 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\Windows\system32\internetmail.dll
2016-08-09 18:47 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2016-08-09 18:47 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2016-08-09 18:47 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2016-08-09 18:47 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\dlnashext.dll
2016-08-09 18:47 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2016-08-09 18:47 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2016-08-09 18:47 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2016-08-09 18:47 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dlnashext.dll
2016-08-09 18:47 - 2015-09-25 05:01 - 02573768 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2016-08-09 18:47 - 2015-09-25 04:33 - 01997336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2016-08-09 18:47 - 2015-09-25 04:07 - 01276416 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2016-08-09 18:47 - 2015-09-25 04:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2016-08-09 18:47 - 2015-09-25 03:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-08-09 18:47 - 2015-09-17 07:49 - 00501008 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-08-09 18:47 - 2015-09-17 07:48 - 00809352 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2016-08-09 18:47 - 2015-09-17 07:48 - 00537080 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2016-08-09 18:47 - 2015-09-17 07:48 - 00505696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-08-09 18:47 - 2015-09-17 07:48 - 00406864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2016-08-09 18:47 - 2015-09-17 07:48 - 00395088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-08-09 18:47 - 2015-09-17 07:48 - 00278352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2016-08-09 18:47 - 2015-09-17 07:37 - 01295712 _____ (Microsoft Corporation) C:\Windows\system32\wpx.dll
2016-08-09 18:47 - 2015-09-17 07:28 - 00407608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-08-09 18:47 - 2015-09-17 07:26 - 00428128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll
2016-08-09 18:47 - 2015-09-17 07:08 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Speech.Pal.dll
2016-08-09 18:47 - 2015-09-17 07:05 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2016-08-09 18:47 - 2015-09-17 07:04 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\DataSenseHandlers.dll
2016-08-09 18:47 - 2015-09-17 07:03 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2016-08-09 18:47 - 2015-09-17 07:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2016-08-09 18:47 - 2015-09-17 07:00 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\KeywordDetectorMsftSidAdapter.dll
2016-08-09 18:47 - 2015-09-17 06:57 - 02228736 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2016-08-09 18:47 - 2015-09-17 06:57 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2016-08-09 18:47 - 2015-09-17 06:56 - 00859136 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-08-09 18:47 - 2015-09-17 06:55 - 01601536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2016-08-09 18:47 - 2015-09-17 06:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\ngccredprov.dll
2016-08-09 18:47 - 2015-09-17 06:55 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\accountaccessor.dll
2016-08-09 18:47 - 2015-09-17 06:54 - 03781120 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2016-08-09 18:47 - 2015-09-17 06:52 - 06572032 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2016-08-09 18:47 - 2015-09-17 06:52 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2016-08-09 18:47 - 2015-09-17 06:52 - 01181696 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-08-09 18:47 - 2015-09-17 06:52 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2016-08-09 18:47 - 2015-09-17 06:51 - 01812480 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2016-08-09 18:47 - 2015-09-17 06:51 - 01203712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2016-08-09 18:47 - 2015-09-17 06:49 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Speech.Pal.dll
2016-08-09 18:47 - 2015-09-17 06:48 - 02093056 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2016-08-09 18:47 - 2015-09-17 06:48 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\ncryptprov.dll
2016-08-09 18:47 - 2015-09-17 06:46 - 00928256 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2016-08-09 18:47 - 2015-09-17 06:46 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2016-08-09 18:47 - 2015-09-17 06:45 - 01331200 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2016-08-09 18:47 - 2015-09-17 06:45 - 00193024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2016-08-09 18:47 - 2015-09-17 06:43 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\RemoteNaturalLanguage.dll
2016-08-09 18:47 - 2015-09-17 06:43 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
2016-08-09 18:47 - 2015-09-17 06:40 - 01162240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2016-08-09 18:47 - 2015-09-17 06:38 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2016-08-09 18:47 - 2015-09-17 06:36 - 01171456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcenter.dll
2016-08-09 18:47 - 2015-09-17 06:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2016-08-09 18:47 - 2015-09-17 06:31 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptprov.dll
2016-08-09 18:47 - 2015-09-17 06:29 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2016-08-09 18:47 - 2015-09-17 06:29 - 00701952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2016-08-09 18:47 - 2015-09-17 06:26 - 00899584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RemoteNaturalLanguage.dll
2016-08-09 18:47 - 2015-08-27 06:51 - 01774592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2016-08-09 18:47 - 2015-08-27 06:42 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.PicturePassword.dll
2016-08-09 18:47 - 2015-08-27 06:16 - 01612288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2016-08-09 18:46 - 2016-08-03 07:15 - 00700256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-08-09 18:46 - 2016-08-03 07:15 - 00046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NAPCRYPT.DLL
2016-08-09 18:46 - 2016-08-03 07:13 - 00065096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Clipc.dll
2016-08-09 18:46 - 2016-08-03 06:46 - 00601336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-08-09 18:46 - 2016-08-03 06:46 - 00158048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-09 18:46 - 2016-08-03 06:44 - 00243760 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-08-09 18:46 - 2016-08-03 06:38 - 01134792 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2016-08-09 18:46 - 2016-08-03 06:38 - 00801632 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-08-09 18:46 - 2016-08-03 06:38 - 00252760 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2016-08-09 18:46 - 2016-08-03 06:38 - 00078040 _____ (Microsoft Corporation) C:\Windows\system32\Clipc.dll
2016-08-09 18:46 - 2016-08-03 06:37 - 00658568 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2016-08-09 18:46 - 2016-08-03 05:57 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-08-09 18:46 - 2016-08-03 05:55 - 00290304 _____ (Microsoft Corporation) C:\Windows\system32\oemlicense.dll
2016-08-09 18:46 - 2016-08-03 05:49 - 02446336 _____ C:\Windows\system32\InputService.dll
2016-08-09 18:46 - 2016-08-03 05:47 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2016-08-09 18:46 - 2016-08-03 05:47 - 00293376 _____ C:\Windows\system32\TextInputFramework.dll
2016-08-09 18:46 - 2016-08-03 05:45 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\iassvcs.dll
2016-08-09 18:46 - 2016-08-03 05:43 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2016-08-09 18:46 - 2016-08-03 05:41 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2016-08-09 18:46 - 2016-08-03 05:40 - 00420352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2016-08-09 18:46 - 2016-08-03 05:40 - 00200704 _____ C:\Windows\SysWOW64\TextInputFramework.dll
2016-08-09 18:46 - 2016-08-03 05:39 - 00153088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2016-08-09 18:46 - 2016-08-03 05:39 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2016-08-09 18:46 - 2016-08-03 05:38 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2016-08-09 18:46 - 2016-08-03 05:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2016-08-09 18:46 - 2016-08-03 05:37 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassvcs.dll
2016-08-09 18:46 - 2016-08-03 05:36 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2016-08-09 18:46 - 2016-08-03 05:35 - 00336384 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2016-08-09 18:46 - 2016-08-03 05:35 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00763904 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00394752 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
2016-08-09 18:46 - 2016-08-03 05:34 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MosHostClient.dll
2016-08-09 18:46 - 2016-08-03 05:33 - 01418240 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2016-08-09 18:46 - 2016-08-03 05:33 - 01061888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2016-08-09 18:46 - 2016-08-03 05:33 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2016-08-09 18:46 - 2016-08-03 05:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2016-08-09 18:46 - 2016-08-03 05:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2016-08-09 18:46 - 2016-08-03 05:31 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-09 18:46 - 2016-08-03 05:30 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IdCtrls.dll
2016-08-09 18:46 - 2016-08-03 05:29 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2016-08-09 18:46 - 2016-08-03 05:29 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2016-08-09 18:46 - 2016-08-03 05:26 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2016-08-09 18:46 - 2016-08-03 05:26 - 00282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2016-08-09 18:46 - 2016-08-03 05:26 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2016-08-09 18:46 - 2016-08-03 05:26 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2016-08-09 18:46 - 2016-08-03 05:25 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2016-08-09 18:46 - 2016-08-03 05:25 - 00695808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2016-08-09 18:46 - 2016-08-03 05:25 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2016-08-09 18:46 - 2016-08-03 05:25 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2016-08-09 18:46 - 2016-08-03 05:25 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosHostClient.dll
2016-08-09 18:46 - 2016-08-03 05:25 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2016-08-09 18:46 - 2016-06-24 05:58 - 00442208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2016-08-09 18:46 - 2016-06-24 04:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2016-08-09 18:46 - 2016-06-24 04:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2016-08-09 18:46 - 2016-06-24 04:44 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2016-08-09 18:46 - 2016-05-28 06:02 - 00113144 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2016-08-09 18:46 - 2016-05-28 06:00 - 00327520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2016-08-09 18:46 - 2016-05-28 05:59 - 00131208 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2016-08-09 18:46 - 2016-05-28 05:53 - 00026464 _____ (Microsoft Corporation) C:\Windows\system32\browser_broker.exe
2016-08-09 18:46 - 2016-05-28 05:38 - 00097096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2016-08-09 18:46 - 2016-05-28 05:35 - 00112632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2016-08-09 18:46 - 2016-05-28 04:53 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2016-08-09 18:46 - 2016-05-28 04:40 - 00672768 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2016-08-09 18:46 - 2016-05-28 04:38 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2016-08-09 18:46 - 2016-05-28 04:25 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2016-08-09 18:46 - 2016-04-15 08:21 - 01085776 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-08-09 18:46 - 2016-04-15 07:43 - 00916800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-08-09 18:46 - 2016-04-15 07:05 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\CloudDomainJoinDataModelServer.dll
2016-08-09 18:46 - 2016-04-09 11:52 - 00705520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-08-09 18:46 - 2016-04-09 11:05 - 01199368 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-08-09 18:46 - 2016-03-16 05:41 - 00208736 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2016-08-09 18:46 - 2016-03-16 05:08 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-08-09 18:46 - 2016-03-16 05:06 - 00181088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2016-08-09 18:46 - 2016-03-16 04:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModelShim.dll
2016-08-09 18:46 - 2016-03-16 04:55 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
2016-08-09 18:46 - 2016-03-16 04:47 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2016-08-09 18:46 - 2016-03-16 04:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2016-08-09 18:46 - 2016-03-16 04:46 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2016-08-09 18:46 - 2016-03-16 04:43 - 00573952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
2016-08-09 18:46 - 2016-03-16 04:43 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-08-09 18:46 - 2016-03-16 04:40 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2016-08-09 18:46 - 2016-03-16 04:40 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
2016-08-09 18:46 - 2016-03-16 04:39 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2016-08-09 18:46 - 2016-03-16 04:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2016-08-09 18:46 - 2016-03-16 04:36 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
2016-08-09 18:46 - 2016-03-16 04:36 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenanceClient.dll
2016-08-09 18:46 - 2016-03-16 04:35 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll
2016-08-09 18:46 - 2016-03-16 04:31 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExtrasXmlParser.dll
2016-08-09 18:46 - 2016-03-16 04:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll
2016-08-09 18:46 - 2016-03-16 04:24 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2016-08-09 18:46 - 2016-03-16 04:24 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2016-08-09 18:46 - 2016-03-16 04:24 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2016-08-09 18:46 - 2016-03-16 04:20 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-08-09 18:46 - 2016-03-16 04:17 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CallHistoryClient.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\POSyncServices.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-08-09 18:46 - 2016-03-16 04:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-08-09 18:46 - 2016-03-16 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll
2016-08-09 18:46 - 2016-02-23 15:51 - 00146784 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2016-08-09 18:46 - 2016-02-23 15:50 - 00630160 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2016-08-09 18:46 - 2016-02-23 15:43 - 00127840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-08-09 18:46 - 2016-02-23 15:41 - 00078040 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2016-08-09 18:46 - 2016-02-23 15:40 - 00110584 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2016-08-09 18:46 - 2016-02-23 15:36 - 00080128 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2016-08-09 18:46 - 2016-02-23 14:30 - 01643872 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-08-09 18:46 - 2016-02-23 14:21 - 00529456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2016-08-09 18:46 - 2016-02-23 14:21 - 00141152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2016-08-09 18:46 - 2016-02-23 14:11 - 00073360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srvcli.dll
2016-08-09 18:46 - 2016-02-23 14:11 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wkscli.dll
2016-08-09 18:46 - 2016-02-23 14:06 - 00069232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2016-08-09 18:46 - 2016-02-23 13:15 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-08-09 18:46 - 2016-02-23 12:17 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2016-08-09 18:46 - 2016-02-23 12:17 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2016-08-09 18:46 - 2016-02-23 11:29 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2016-08-09 18:46 - 2016-01-31 06:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rasman.dll
2016-08-09 18:46 - 2016-01-31 06:24 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-08-09 18:46 - 2016-01-31 06:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-08-09 18:46 - 2016-01-31 06:19 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2016-08-09 18:46 - 2016-01-31 06:13 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasman.dll
2016-08-09 18:46 - 2016-01-31 06:13 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\ztrace_maps.dll
2016-08-09 18:46 - 2016-01-31 06:11 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-08-09 18:46 - 2016-01-31 05:58 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ztrace_maps.dll
2016-08-09 18:46 - 2016-01-05 03:50 - 01817064 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2016-08-09 18:46 - 2016-01-05 03:28 - 00116728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-08-09 18:46 - 2016-01-05 03:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2016-08-09 18:46 - 2016-01-05 03:09 - 01234944 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2016-08-09 18:46 - 2016-01-05 02:44 - 00159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2016-08-09 18:46 - 2016-01-05 02:44 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usermgrcli.dll
2016-08-09 18:46 - 2015-12-01 07:03 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\gpuenergydrv.sys
2016-08-09 18:46 - 2015-11-25 06:42 - 00168288 _____ (Microsoft Corporation) C:\Windows\system32\NetworkUXBroker.exe
2016-08-09 18:46 - 2015-11-25 06:32 - 00113184 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2016-08-09 18:46 - 2015-11-25 05:59 - 00092992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2016-08-09 18:46 - 2015-11-25 05:49 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\WlanMediaManager.dll
2016-08-09 18:46 - 2015-11-25 05:36 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys
2016-08-09 18:46 - 2015-11-25 05:36 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2016-08-09 18:46 - 2015-11-25 05:26 - 00849408 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2016-08-09 18:46 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2016-08-09 18:46 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZST.DLL
2016-08-09 18:46 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2016-08-09 18:46 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2016-08-09 18:46 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2016-08-09 18:46 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZST.DLL
2016-08-09 18:46 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2016-08-09 18:46 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2016-08-09 18:46 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-08-09 18:46 - 2015-10-10 08:12 - 00078528 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-08-09 18:46 - 2015-09-25 05:01 - 00498016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2016-08-09 18:46 - 2015-09-25 03:59 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll
2016-08-09 18:46 - 2015-09-25 03:32 - 00466432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll
2016-08-09 18:46 - 2015-09-19 06:14 - 00102304 _____ (Microsoft Corporation) C:\Windows\system32\omadmapi.dll
2016-08-09 18:46 - 2015-09-17 07:50 - 00088384 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2016-08-09 18:46 - 2015-09-17 07:48 - 00584656 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-08-09 18:46 - 2015-09-17 07:48 - 00555768 _____ (Microsoft Corporation) C:\Windows\system32\directmanipulation.dll
2016-08-09 18:46 - 2015-09-17 07:37 - 01168736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2016-08-09 18:46 - 2015-09-17 07:27 - 00454512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\directmanipulation.dll
2016-08-09 18:46 - 2015-09-17 07:26 - 00508248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-08-09 18:46 - 2015-09-17 07:11 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2016-08-09 18:46 - 2015-09-17 07:10 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2016-08-09 18:46 - 2015-09-17 07:09 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2016-08-09 18:46 - 2015-09-17 07:09 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll
2016-08-09 18:46 - 2015-09-17 07:08 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2016-08-09 18:46 - 2015-09-17 07:08 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManagerShellext.exe
2016-08-09 18:46 - 2015-09-17 07:06 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2016-08-09 18:46 - 2015-09-17 07:03 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2016-08-09 18:46 - 2015-09-17 07:03 - 00154624 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2016-08-09 18:46 - 2015-09-17 07:02 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\mdmmigrator.dll
2016-08-09 18:46 - 2015-09-17 07:02 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-08-09 18:46 - 2015-09-17 06:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2016-08-09 18:46 - 2015-09-17 06:57 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll
2016-08-09 18:46 - 2015-09-17 06:57 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2016-08-09 18:46 - 2015-09-17 06:56 - 00521728 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2016-08-09 18:46 - 2015-09-17 06:56 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll
2016-08-09 18:46 - 2015-09-17 06:55 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2016-08-09 18:46 - 2015-09-17 06:55 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\wwancfg.dll
2016-08-09 18:46 - 2015-09-17 06:52 - 00591360 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2016-08-09 18:46 - 2015-09-17 06:52 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2016-08-09 18:46 - 2015-09-17 06:52 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2016-08-09 18:46 - 2015-09-17 06:52 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2016-08-09 18:46 - 2015-09-17 06:52 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\SubscriptionMgr.dll
2016-08-09 18:46 - 2015-09-17 06:51 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2016-08-09 18:46 - 2015-09-17 06:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll
2016-08-09 18:46 - 2015-09-17 06:50 - 00929280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2016-08-09 18:46 - 2015-09-17 06:50 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2016-08-09 18:46 - 2015-09-17 06:50 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2016-08-09 18:46 - 2015-09-17 06:50 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\LocationPeWiFi.dll
2016-08-09 18:46 - 2015-09-17 06:50 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\LocationPeCell.dll
2016-08-09 18:46 - 2015-09-17 06:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\buttonconverter.sys
2016-08-09 18:46 - 2015-09-17 06:49 - 00439296 _____ (Microsoft Corporation) C:\Windows\system32\LocationWebproxy.dll
2016-08-09 18:46 - 2015-09-17 06:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\LocationGeofences.dll
2016-08-09 18:46 - 2015-09-17 06:49 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2016-08-09 18:46 - 2015-09-17 06:49 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\LocationCrowdsource.dll
2016-08-09 18:46 - 2015-09-17 06:49 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\LocationPeIP.dll
2016-08-09 18:46 - 2015-09-17 06:49 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\LocationWiFiAdapter.dll
2016-08-09 18:46 - 2015-09-17 06:48 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2016-08-09 18:46 - 2015-09-17 06:48 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2016-08-09 18:46 - 2015-09-17 06:48 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2016-08-09 18:46 - 2015-09-17 06:48 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-08-09 18:46 - 2015-09-17 06:47 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2016-08-09 18:46 - 2015-09-17 06:46 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2016-08-09 18:46 - 2015-09-17 06:46 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2016-08-09 18:46 - 2015-09-17 06:46 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2016-08-09 18:46 - 2015-09-17 06:46 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\HttpsDataSource.dll
2016-08-09 18:46 - 2015-09-17 06:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\syncmlhook.dll
2016-08-09 18:46 - 2015-09-17 06:44 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2016-08-09 18:46 - 2015-09-17 06:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\syncutil.dll
2016-08-09 18:46 - 2015-09-17 06:41 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2016-08-09 18:46 - 2015-09-17 06:37 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2016-08-09 18:46 - 2015-09-17 06:34 - 00253440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2016-08-09 18:46 - 2015-09-17 06:32 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2016-08-09 18:46 - 2015-09-17 06:32 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll
2016-08-09 18:46 - 2015-09-17 06:32 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2016-08-09 18:46 - 2015-09-17 06:28 - 00473088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2016-08-09 18:46 - 2015-09-17 06:16 - 00512000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2016-08-09 13:16 - 2016-08-09 13:16 - 00002278 _____ C:\Users\Public\Desktop\Vodafone Mobile Wi-Fi.lnk
2016-08-08 16:51 - 2016-08-24 11:36 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-08 16:50 - 2016-08-08 16:50 - 00001179 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-08 16:50 - 2016-08-08 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-08 16:50 - 2016-08-08 16:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-08 16:50 - 2016-08-08 16:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-08 16:50 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-08-08 16:50 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-08-08 16:50 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-08-08 16:49 - 2016-08-08 16:49 - 22851472 _____ (Malwarebytes ) C:\Users\Rafael Sobreiro\Downloads\mbam-setup-2.2.1.1043.exe
2016-08-08 16:47 - 2016-08-08 16:47 - 00000049 _____ C:\Users\Rafael Sobreiro\Documents\White3.txt
2016-08-08 16:43 - 2016-08-08 16:48 - 180611176 _____ C:\Users\Rafael Sobreiro\Downloads\UOL Mais Fairy Tail 232.mp4
2016-08-08 16:43 - 2016-08-08 16:48 - 128079146 _____ C:\Users\Rafael Sobreiro\Downloads\UOL Mais Fairy Tail 233.mp4
2016-08-08 16:40 - 2016-08-08 16:52 - 367936749 _____ C:\Users\Rafael Sobreiro\Downloads\fairyPROJECT_-_Epi_231_HD.mp4
2016-08-08 16:40 - 2016-08-08 16:44 - 142619487 _____ C:\Users\Rafael Sobreiro\Downloads\UOL Mais Fairy Tail Episdio 229 OnLine.mp4
2016-08-08 16:31 - 2016-08-08 16:43 - 367577523 _____ C:\Users\Rafael Sobreiro\Downloads\fairyPROJECT_-_Epi_230_HD.mp4
2016-08-08 16:19 - 2016-08-08 16:31 - 367825110 _____ C:\Users\Rafael Sobreiro\Downloads\fairyPROJECT_-_Epi_228_HD.mp4
2016-08-08 16:17 - 2016-08-08 16:29 - 367720420 _____ C:\Users\Rafael Sobreiro\Downloads\fairyPROJECT_-_Epi_227_HD.mp4
2016-08-08 11:17 - 2016-08-10 17:43 - 691200209 _____ C:\Windows\MEMORY.DMP
2016-08-08 11:17 - 2016-08-10 17:43 - 00000000 ____D C:\Windows\Minidump
2016-08-08 11:17 - 2016-08-08 11:17 - 00321824 _____ C:\Windows\Minidump\080816-16875-01.dmp
2016-08-06 06:17 - 2016-08-06 06:17 - 01940464 _____ C:\Users\Rafael Sobreiro\Downloads\Trundle_Base_VO_audio.wpk
2016-08-03 06:21 - 2016-08-07 09:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-03 01:56 - 2016-08-03 01:56 - 08345816 _____ C:\Users\Rafael Sobreiro\Downloads\Brand Chroma Pack Full v1 (By blackbox).zip
2016-08-03 01:07 - 2016-08-03 01:07 - 06450927 _____ C:\Users\Rafael Sobreiro\Downloads\Old Karma (Model + Particles).wxy
2016-08-01 22:43 - 2016-08-20 19:27 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\CrashDumps
2016-07-31 06:58 - 2016-07-31 06:58 - 01106074 _____ C:\Users\Rafael Sobreiro\Downloads\Mythril Ashe - Base skin replace v1 (By Ancient).wxy
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-30 04:23 - 2016-07-17 19:55 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Roaming\Skype
2016-08-30 03:08 - 2016-07-17 20:04 - 00004204 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{82888F8C-4B09-44AD-BA85-C62F95B6D1F6}
2016-08-30 02:07 - 2016-07-24 22:30 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Roaming\Audacity
2016-08-30 01:18 - 2015-12-22 20:42 - 00795894 _____ C:\Windows\system32\prfh0816.dat
2016-08-30 01:18 - 2015-12-22 20:42 - 00156194 _____ C:\Windows\system32\prfc0816.dat
2016-08-30 01:18 - 2015-08-31 12:01 - 01827502 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-30 01:18 - 2015-07-10 12:02 - 00000000 ____D C:\Windows\INF
2016-08-30 00:55 - 2015-08-31 11:50 - 00004252 _____ C:\Windows\System32\Tasks\avast! SL Update
2016-08-30 00:49 - 2016-07-18 03:34 - 00000000 __SHD C:\Users\Rafael Sobreiro\IntelGraphicsProfiles
2016-08-30 00:49 - 2016-07-18 03:30 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-28 23:37 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\AppReadiness
2016-08-27 19:27 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-25 23:44 - 2016-07-19 03:43 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\ElevatedDiagnostics
2016-08-24 23:58 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2016-08-24 23:57 - 2015-08-31 12:45 - 00000000 ____D C:\Windows\Panther
2016-08-21 04:37 - 2016-07-18 03:34 - 00000000 ____D C:\Users\Rafael Sobreiro
2016-08-20 21:37 - 2015-07-10 13:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-18 11:36 - 2016-07-19 04:05 - 00003508 _____ C:\Windows\System32\Tasks\BacKGroundAgent
2016-08-18 11:36 - 2015-08-31 12:43 - 00000000 ___HD C:\OEM
2016-08-18 11:36 - 2015-08-31 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2016-08-18 11:34 - 2016-07-18 03:37 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\clear.fi
2016-08-17 15:02 - 2016-07-17 19:55 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-17 15:02 - 2016-07-17 19:55 - 00000000 ____D C:\ProgramData\Skype
2016-08-16 13:39 - 2016-07-18 03:38 - 00002401 _____ C:\Users\Rafael Sobreiro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-16 13:39 - 2016-07-18 03:38 - 00000000 ___RD C:\Users\Rafael Sobreiro\OneDrive
2016-08-13 17:49 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\NDF
2016-08-13 17:49 - 2015-07-10 10:05 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-08-13 11:31 - 2016-07-20 22:25 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\Comms
2016-08-12 03:54 - 2016-07-18 03:35 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\Packages
2016-08-12 00:21 - 2016-07-17 18:55 - 00000000 ____D C:\Program Files (x86)\Google
2016-08-11 22:52 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\rescache
2016-08-11 14:25 - 2015-07-10 11:55 - 00000000 ____D C:\Windows\CbsTemp
2016-08-10 13:36 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2016-08-09 23:10 - 2015-08-31 11:49 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-09 23:08 - 2015-07-10 13:20 - 00198032 _____ C:\Windows\system32\FNTCACHE.DAT
2016-08-09 23:05 - 2015-07-10 14:14 - 00000000 ____D C:\Program Files\Windows Journal
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\SysWOW64\F12
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\system32\F12
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___SD C:\Windows\system32\DiagSvcs
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\PurchaseDialog
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ___RD C:\Windows\DevicesFlow
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\SysWOW64\oobe
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\oobe
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\system32\appraiser
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\Provisioning
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Windows\L2Schemas
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Windows Defender
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-08-09 23:05 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-08-09 23:05 - 2015-07-10 10:05 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-08-09 13:16 - 2016-07-17 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
2016-08-09 13:16 - 2016-07-17 18:47 - 00000000 ____D C:\Program Files (x86)\Vodafone
2016-08-09 13:16 - 2016-07-17 18:46 - 00000000 ____D C:\Users\Rafael Sobreiro\AppData\Local\Downloaded Installations
2016-08-07 09:08 - 2015-08-31 11:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-05 15:42 - 2016-07-30 11:28 - 00000765 _____ C:\Users\Rafael Sobreiro\Documents\Omega Ruby.txt
2016-08-03 07:45 - 2015-08-31 11:47 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2016-08-03 01:56 - 2016-07-25 05:43 - 00000000 ____D C:\Wooxy
==================== Files in the root of some directories =======
2016-08-15 15:10 - 2016-08-15 15:10 - 0001034 _____ () C:\Users\Rafael Sobreiro\AppData\Local\recently-used.xbel
2012-03-16 14:55 - 2012-03-16 14:55 - 0286678 ____R () C:\ProgramData\DeviceManager.xml.rc4
2015-12-22 13:42 - 2015-12-22 13:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Rafael Sobreiro\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-29 18:44
==================== End of FRST.txt ============================
Addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-08-2016
Ran by [removed] (30-08-2016 04:30:02)
Running from C:\Users\[removed]\Desktop
Windows 10 Home (X64) (2016-07-18 02:29:27)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrador (S-1-5-21-1796416936-1353488523-4272779061-500 - Administrator - Disabled)
Convidado (S-1-5-21-1796416936-1353488523-4272779061-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1796416936-1353488523-4272779061-503 - Limited - Disabled)
Rafael Sobreiro (S-1-5-21-1796416936-1353488523-4272779061-1001 - Administrator - Enabled) => C:\Users\Rafael Sobreiro
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
12 Labours of Hercules III: Girl Power (x32 Version: 3.0.2.118 - WildTangent) Hidden
abFiles (HKLM-x32\…\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.03.2003 - Acer Incorporated)
abPhoto (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.08.2003.3 - Acer Incorporated)
Acer Care Center (HKLM\…\{1AF41E84-3408-499A-8C93-8891F0612719}) (Version: 2.00.3005 - Acer Incorporated)
Acer Explorer Agent (HKLM\…\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3001 - Acer Incorporated)
Acer Portal (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.11.2000 - Acer Incorporated)
Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8109 - Acer Incorporated)
Acer Quick Access (HKLM\…\{E3678E72-78E3-4F91-A9FB-913876FF6DA2}) (Version: 2.00.3008 - Acer Incorporated)
Acer UEIP Framework (HKLM\…\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 2.01.3002 - Acer Incorporated)
Actualizações da NVIDIA 2.5.11.45 (Version: 2.5.11.45 - NVIDIA Corporation) Hidden
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
AOP Framework (HKLM-x32\…\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.22.2000.2 - Acer Incorporated)
Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version: - Audacity Team)
Avast SecureLine (HKLM\…\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 1.0.239.4 - AVAST Software)
DriverSetupUtility (HKLM\…\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3011 - Acer Incorporated)
Foxit PhantomPDF (HKLM-x32\…\{A4023BDF-82D5-412D-9D58-8C2819EBFE2E}) (Version: 7.0.410.326 - Foxit Software Inc.)
Game Explorer Categories - genres (HKLM-x32\…\WildTangentGameProvider-acer-genres) (Version: 13.0.0.6 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\…\WildTangentGameProvider-acer-main) (Version: 13.0.0.6 - WildTangent, Inc.)
GIMP 2.8.18 (HKLM\…\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Home Makeover (x32 Version: 3.0.2.59 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1163 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4248 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.2.1088 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel® Security Assist (HKLM-x32\…\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Java 8 Update 101 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Match Snowscapes (x32 Version: 3.0.2.118 - WildTangent) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
Magic Academy (x32 Version: 2.2.0.97 - WildTangent) Hidden
Malwarebytes Anti-Malware versão 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4693.1005 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
NVIDIA Controlador gráfico 353.54 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.54 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.11.45 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.11.45 - NVIDIA Corporation)
NVIDIA O software do sistema PhysX 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Painel de controlo da NVIDIA 353.54 (Version: 353.54 - NVIDIA Corporation) Hidden
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Qualcomm Atheros QCA9377 Wireless LAN & Bluetooth Installer (HKLM-x32\…\{3241744A-BA36-41F0-B4AA-EF3946D00632}) (Version: 11.0.0.067 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7553 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.6 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.6 - VS Revo Group, Ltd.)
RogueKiller versão 12 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12 - Adlice Software)
Rory's Restaurant (x32 Version: 3.0.2.126 - WildTangent) Hidden
Runefall (x32 Version: 3.0.2.126 - WildTangent) Hidden
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.11.45 - NVIDIA Corporation) Hidden
Skype™ 7.26 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Software de Dispositivos Chipset Intel® (x32 Version: 10.1.1.8 - Intel(R) Corporation) Hidden
Tweaking.com - Registry Backup (HKLM-x32\…\Tweaking.com - Registry Backup) (Version: 3.5.0 - Tweaking.com)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Vegas World (x32 Version: 13.0.0.6 - WildTangent) Hidden
Villagers and Heroes (x32 Version: 13.0.0.6 - WildTangent) Hidden
Vodafone Mobile Broadband (HKLM-x32\…\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.3.203.38322 - Vodafone)
Vodafone Wi-Fi (HKLM-x32\…\{F08DBC61-FBFC-4D26-997F-74B42C51DC56}) (Version: 2.0.9.48121 - Vodafone)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.16 - WildTangent) Hidden
WildTangent Games App (x32 Version: 4.1.1.14 - WildTangent) Hidden
Wooxy version 1.5.0.0 (HKLM-x32\…\{C183CD14-47D8-4F98-AF06-4744CB834C8E}_is1) (Version: 1.5.0.0 - Chewy)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1796416936-1353488523-4272779061-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {07B57DE5-DE93-408F-92A9-AB3454AD96F6} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2015-05-14] (Acer Incorporated)
Task: {2DDAEB9B-5BA2-4EAF-8223-956FDA7FBF4C} - System32\Tasks\Power Button => C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe [2015-05-14] (Acer Incorporated)
Task: {38BB970B-D059-4F94-A260-4931A479E5FD} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2016-06-27] (Acer)
Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {5995466D-F8AF-4AC6-B066-B8BE16EC57E6} - System32\Tasks\FUBTrackingByPLD => C:\OEM\Preload\FubTracking\FubTracking.exe [2015-05-14] ()
Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2015-07-10] ()
Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [2015-07-10] ()
Task: {6C8F889A-CE0E-4157-BB8F-CE973725B356} - System32\Tasks\Microsoft\Office\Microsoft Office Touchless Attach Notification => C:\Program Files (x86)\Microsoft Office\Office15\FirstRun.exe [2015-03-14] (Microsoft Corporation)
Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [2016-07-17] (AVAST Software)
Task: {9B1BE93E-2D1B-479D-80BC-9AAFD5CEF911} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-12] (Google Inc.)
Task: {BC4BCF21-2562-4729-9FE3-2EB507B9BE36} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-16] (Microsoft Corporation)
Task: {CB0DC988-9DF5-4498-82EF-E861DE3E9EF9} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2015-09-04] (Acer Incorporated)
Task: {D580BF3C-83CE-4E6B-B1A1-20EB95353BC4} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: )
Task: {E0C21389-EC01-402F-A776-C3731FA73825} - System32\Tasks\avast! SL Update => C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [2016-07-17] (AVAST Software)
Task: {E6916FAB-2ABC-47BC-A7E6-F5AC64698847} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2016-08-15] (Acer Incorporated)
Task: {F47E9E29-0D00-4AE9-BBF4-1F72679444CF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-12] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-12-22 21:03 - 2015-12-22 21:03 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll
2016-07-17 23:51 - 2016-07-17 23:52 - 00592392 _____ () C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
2015-12-22 21:03 - 2015-12-22 21:03 - 00404480 _____ () C:\Windows\System32\diagtrack_wininternal.dll
2015-12-22 13:54 - 2015-07-13 18:37 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-08-09 18:47 - 2016-08-03 06:44 - 02495776 _____ () C:\Windows\system32\CoreUIComponents.dll
2015-09-14 10:37 - 2015-08-18 23:54 - 00395368 _____ () C:\Windows\system32\igfxTray.exe
2016-08-09 18:47 - 2016-08-03 06:44 - 02495776 _____ () C:\Windows\System32\CoreUIComponents.dll
2016-08-16 13:38 - 2016-08-16 13:38 - 01864384 _____ () C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll
2016-08-09 18:47 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 11:59 - 2015-07-10 11:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2016-08-09 18:47 - 2016-08-03 05:34 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-08-09 18:48 - 2015-11-25 05:17 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-08-09 18:47 - 2016-08-03 05:31 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-08-09 18:47 - 2015-09-17 06:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 12:00 - 2015-07-10 14:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2016-08-12 00:21 - 2016-08-03 00:41 - 02366280 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-12 00:21 - 2016-08-03 00:40 - 00107848 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
2015-07-10 11:38 - 2015-07-10 11:38 - 04580704 _____ () C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
2016-08-16 11:47 - 2016-08-16 11:52 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-08-16 11:47 - 2016-08-16 11:52 - 13475840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-08-16 11:47 - 2016-08-16 11:52 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2016-07-23 17:47 - 2016-07-23 17:48 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2015-12-22 13:41 - 2015-02-08 20:18 - 00124440 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2016-04-01 12:30 - 2016-07-21 18:00 - 01294336 _____ () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
2016-08-24 11:39 - 2016-08-24 11:39 - 02409464 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.26\deploy\LoLLauncher.exe
2016-08-24 11:39 - 2016-08-24 11:39 - 04602872 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\LoLPatcher.exe
2016-08-12 00:21 - 2016-08-03 00:04 - 31541952 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\PepperFlash\pepflashplayer.dll
2016-07-23 01:10 - 2016-07-23 01:10 - 00074752 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\LolClient.exe
2016-08-09 18:46 - 2016-08-03 05:47 - 00293376 _____ () C:\Windows\SYSTEM32\textinputframework.dll
2015-08-14 03:17 - 2015-08-14 03:17 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-12-22 13:54 - 2015-07-14 20:07 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-08-16 13:38 - 2016-08-16 13:38 - 01383616 _____ () C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\ClientTelemetry.dll
2016-08-16 13:38 - 2016-08-16 13:38 - 00118976 _____ () C:\Users\Rafael Sobreiro\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncViews.dll
2012-03-20 13:08 - 2012-03-20 13:08 - 00396800 _____ () C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\Vodafone.View.Taskbar.dll
2016-08-15 18:03 - 2016-08-15 18:03 - 00202456 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2016-08-15 18:05 - 2016-08-15 18:05 - 00654000 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2016-08-15 18:05 - 2016-08-15 18:05 - 00641240 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2016-08-15 18:04 - 2016-08-15 18:04 - 00119000 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2016-08-18 11:36 - 2016-08-18 11:36 - 00015064 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2016-08-15 14:36 - 2016-08-15 14:36 - 00013016 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2016-08-15 14:33 - 2016-08-15 14:33 - 00277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2016-06-27 16:12 - 2016-06-27 16:12 - 00202456 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll
2016-06-27 16:12 - 2016-06-27 16:12 - 00119000 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll
2016-08-24 11:39 - 2016-08-24 11:39 - 00449528 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\RiotLauncher.dll
2016-07-21 19:27 - 2016-07-21 19:27 - 04887216 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll
2016-07-21 19:07 - 2016-07-21 19:07 - 19397808 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-07-10 12:04 - 2016-08-10 14:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1796416936-1353488523-4272779061-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rafael Sobreiro\Downloads\traditional__karma_splash_art_by_dbr01-d8w5nrw.png
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{47DCA9E8-956B-4F2C-9294-4A0A50D6EC8A}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe
FirewallRules: [{D58377B0-F3E6-4D54-A4FD-62D56A9BA27D}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe
FirewallRules: [{53D74214-AC4C-49DB-A776-AF915F466E31}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe
FirewallRules: [{4A6244BC-DE14-42E9-A6A6-15B9D3EE81B7}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe
FirewallRules: [TCP Query User{519263B1-D027-42E7-9CA0-DC995E5CAECC}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{5601755B-4728-4D28-A376-04E0985D00AB}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{EA1DD956-888A-444B-AC18-5F659F52837E}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{D23A286F-4A7E-47D9-846D-408441A83035}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{28EE6B79-ADA0-46F3-994C-DA5BCC6C2495}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{950567F5-2E18-42EF-BF21-68CE73F40824}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{689784FF-4DC3-433A-B40E-A0F0CB5F23CA}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{9D187EE6-5870-4349-A062-1BA556CFB26A}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{AD0F1D36-4753-4974-8A71-4E11BD121BFF}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{43C74F18-CC01-4C93-B419-DFD5BA5A5D0C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E0D2360E-7C64-43EC-BC3A-E04E2ED6C2B8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{83270D9C-40D9-4ACA-BC23-A8DB52091624}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
11-08-2016 17:29:22 Revo Uninstaller Pro's restore point - Google Chrome
18-08-2016 18:00:47 Ponto de Verificação Agendado
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/30/2016 04:31:00 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:31:00 AM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (1628) SRUJet: Foi detetada uma ligação de página incorreta (erro -338) numa Árvore B (ObjectId: 30, PgnoRoot: 225) da base de dados C:\Windows\system32\SRU\SRUDB.dat (225 => 3871, 3872).
Error: (08/30/2016 04:30:59 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:58 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:57 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:56 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:56 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:55 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:53 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
Error: (08/30/2016 04:30:52 AM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (1628) SRUJet: Falha na verificação da página da base de dados lida a partir do ficheiro "C:\Windows\system32\SRU\SRUDB.dat" no deslocamento 17965056 (0x0000000001122000) (página da base de dados 4385 (0x1121)) para 4096 (0x00001000) bytes porque não contém dados de página. A operação de leitura irá falhar com o erro -1019 (0xfffffc05). Se esta condição persistir, efetue o restauro da base de dados a partir de uma cópia de segurança anterior. Este problema deve-se provavelmente a uma falha de hardware. Contacte o fabricante do hardware para obter mais ajuda no diagnóstico deste problema.
System errors:
=============
Error: (08/30/2016 12:31:47 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-8E1TS1M5)
Description: O servidor {D63B10C5-BB46-4990-A94F-E40B9D520160} não foi registado no DCOM dentro do tempo limite necessário.
Error: (08/30/2016 12:31:35 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-8E1TS1M5)
Description: O servidor CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mca não foi registado no DCOM dentro do tempo limite necessário.
Error: (08/30/2016 12:31:31 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço Anfitrião de Sincronização_Session13.
Error: (08/30/2016 12:31:31 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço Armazenamento de Dados do Utilizador_Session13.
Error: (08/30/2016 12:31:31 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: O gestor de controlo de serviços tentou efetuar uma ação corretiva (Reiniciar o serviço) após a terminação inesperada do serviço Armazenamento de Dados do Utilizador_Session13, mas esta ação falhou com o seguinte erro:
Já existe uma instância do serviço em execução.
Error: (08/30/2016 12:31:24 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-8E1TS1M5)
Description: O servidor CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mca não foi registado no DCOM dentro do tempo limite necessário.
Error: (08/30/2016 12:31:23 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-8E1TS1M5)
Description: O servidor App.AppXrvx5vw3ftamg62prcf1xd7e4aena2tfj.mca não foi registado no DCOM dentro do tempo limite necessário.
Error: (08/30/2016 12:31:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: O serviço Acesso a Dados do Utilizador_Session13 terminou inesperadamente. Já o fez 1 vez(es). Será efetuada a seguinte ação corretiva em 10000 milissegundos: Reiniciar o serviço.
Error: (08/30/2016 12:31:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: O serviço Armazenamento de Dados do Utilizador_Session13 terminou inesperadamente. Já o fez 1 vez(es). Será efetuada a seguinte ação corretiva em 10000 milissegundos: Reiniciar o serviço.
Error: (08/30/2016 12:31:21 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: O serviço Dados de Contacto_Session13 terminou inesperadamente. Já o fez 1 vez(es). Será efetuada a seguinte ação corretiva em 10000 milissegundos: Reiniciar o serviço.
CodeIntegrity:
===================================
Date: 2016-08-22 19:32:40.282
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-19 16:21:18.975
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-14 16:00:52.142
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-13 18:53:24.724
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-12 18:00:23.017
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-11 16:03:30.626
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-10 18:49:20.629
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-08-10 13:54:06.182
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-10 13:54:06.085
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-10 13:54:02.913
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-6500U CPU @ 2.50GHz
Percentage of memory in use: 71%
Total physical RAM: 7946.59 MB
Available physical RAM: 2242.93 MB
Total Virtual: 13512.77 MB
Available Virtual: 5355.82 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:930.91 GB) (Free:861.13 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 2CECD241)
Partition: GPT.
==================== End of Addition.txt ============================