Ir ao conteúdo
  • Comunicados

    • diego_moicano

      Gostaria de se tornar um analista em Remoção de Malware?   07-12-2015

      Gostaria de se tornar um analista em Remoção de Malware? O Fórum Clube do Hardware deu início a um programa de treinamento em análises de log. Os interessados deverão enviar um email para aprendizes (arroba) clubedohardware (ponto) com (ponto) br respondendo as seguintes perguntas: Por que você gostaria de aprender a analisar logs? Possui tempo hábil para o treinamento? Tem conhecimentos em informática? Se sim descreva-os. Possui inglês para leitura? Qual seu objetivo após completar o treinamento?   Não se esqueça de incluir no e-mail o seu nome de usuário (fornecer o link também), idade e cidade onde vive. Adicione também qualquer experiência e/ou razão sobre o porquê você seria um bom Analista. É digno de nota que apenas os que forem selecionados receberão resposta por MP (Mensagem Pessoal), não existe um padrão na escolha dos futuros aprendizes, todos os e-mails serão lidos e serão analisados de forma imparcial, portanto não será permitido reclamações neste aspecto. O treinamento é dado no próprio fórum. Quando um aprendiz é selecionado ele é movido para um novo grupo, onde terá acesso a fóruns fechados para os demais usuários onde poderá dar inicio ao seu treinamento. Importante: A cada 30 dias os e-mails não selecionados serão apagados, portanto você pode enviar um novo e-mail após 1 mês, e-mails enviados antes serão desconsiderados.  
    • Gabriel Torres

      Seja um moderador do Clube do Hardware!   12-02-2016

      Prezados membros do Clube do Hardware, Está aberto o processo de seleção de novos moderadores para diversos setores ou áreas do Clube do Hardware. Os requisitos são:   Pelo menos 500 posts e um ano de cadastro; Boa frequência de participação; Ser respeitoso, cordial e educado com os demais membros; Ter bom nível de português; Ter razoável conhecimento da área em que pretende atuar; Saber trabalhar em equipe (com os moderadores, coordenadores e administradores).   Os interessados deverão enviar uma mensagem privada para o usuário @Equipe Clube do Hardware com o título "Candidato a moderador". A mensagem deverá conter respostas às perguntas abaixo:   Qual o seu nome completo? Qual sua data de nascimento? Qual sua formação/profissão? Já atuou como moderador em algo outro fórum, se sim, qual? De forma sucinta, explique o porquê de querer ser moderador do fórum e conte-nos um pouco sobre você.   OBS: Não se trata de função remunerada. Todos que fazem parte do staff são voluntários.
Gabriel Bernardes de Almeida

Conexão de rede de entrada suspeita bloqueada

Recommended Posts

Boa noite,

 

Hoje alguém invadiu meu notebook remotamente, me pediu dinheiro para não danificar meu notebook. Não respondi, desliguei a internet e reiniciei o computador. Fiz uma varredura completa com o anti-vírus McAfee. E mesmo após remover alguns arquivos, continuo tendo tentativas de conexões de rede de entrada suspeitas. Porém até agora, não aconteceu a solicitação de dinheiro como havia acontecido antes. Por favor, peço ajuda para remover totalmente qualquer malware que ainda possa estar no meu notebook.

Desde já agradeço e aguardo o retorno o mais breve possível.

 

Atenciosamente,

 

Gabriel Almeida

Compartilhar este post


Link para o post
Compartilhar em outros sites
Citação

Hoje alguém invadiu meu notebook remotamente, me pediu dinheiro para não danificar meu notebook.

 

Amigo, por favor, descreva o que ocorreu.

  • Curtir 1

Compartilhar este post


Link para o post
Compartilhar em outros sites
  • Autor do tópico
  • 16 horas atrás, diego_moicano disse:

     

    Amigo, por favor, descreva o que ocorreu.

    Amigo, na madrugada do sábado estava jogando Point Blank, quando uma tela de mensagem (parecida com a de comando) apareceu na minha área de trabalho minimizando o jogo, a qual eu não conseguia fechar apenas podia responder a quem estava me enviando mensagens. Nesta tela a pessoa que hackeou meu notebook solicitou dinheiro para não roubar minhas informações pessoais e não danificar meu computador. Eu não respondi, apenas desconectei meu computador do wifi e coloquei rodar o antivirus, fazer uma varredura. Nessa varredura o antivirus, McAfee, achou um Trojan e excluiu o mesmo, colocou em quarentena. Porém o hacker conseguiu roubar minha conta do jogo e minha conta do Netflix, a qual as duas tinha as senhas salvas neste notebook. Essas contas eu consegui recuperar, pois entrei em contato com todas empresas e troquei todas as senhas utilizando outro computador fora da rede. Só que meu antivirus continua bloqueando conexões de rede de entrada suspeitas e estou com medo que este hacker possa ainda roubar alguma informação minha ou danificar o meu notebook, o qual utilizo para trabalhar. Por isso solicitei ajuda de vocês. Não sei se conseguir ser claro, caso não tenha conseguido, continue me questionando, se consegui... indique-me os passos que tenho que seguir para ficar seguro quanto à este ataque.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Perfeito! Agiu corretamente com relação as suas contas/senhas :)

     

    Citação

    McAfee, achou um Trojan e excluiu o mesmo, colocou em quarentena.

     

    Teria como me enviar um print ou o relatório do McAfee?

     

    Abraços :D

    • Curtir 1

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Em 14/09/2017 às 10:35, diego_moicano disse:

    Caro @Gabriel Bernardes de Almeida

     

    Perfeito! Agiu corretamente com relação as suas contas/senhas :)

     

     

    Teria como me enviar um print ou o relatório do McAfee?

     

    Abraços :D

    Segue em anexo os prints.

     

    Abraço

    06.jpg

    01.jpg

    02.jpg

    03.jpg

    04.jpg

    05.jpg

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Recomendo que salve este tópico em seus Favoritos para facilitar na hora de encontrá-lo.

     

    Por favor, atente para o seguinte:

    • Caso fique sem resposta durante 3 dias, me envie uma Mensagem Privada (MP);
    • O que será passado aqui, somente será com relação ao problema do seu computador portanto, não faça mais em nenhum outro;
    • Siga, por favor, atentamente as instruções passadas e em caso de dúvidas não hesite em perguntá-las;
    • Sempre coloque suas respostas neste tópico... Não abra outro!
    • Procure sempre me manter informado, durante a remoção, sobre o que acontece com seu computador.
    • Respeite a ordem das instruções passadas.

    Observação: Não tome outra medida além das passadas aqui; atente para que, caso peça ajuda em outro fórum, não deixe de nos informar, sob risco de desconfigurar seu computador!

     

    # Etapa nº 1 #
     
    Baixe o AdwCleaner e salve em sua Área de trabalho (Desktop)

    Execute o arquivo adwcleaner.exe Como Administrador

    • Clique na aba Opções e deixe marcado apenas "Restaurar Políticas do IE" e "Restaurar Políticas do Chrome"
    • Clique no botão Verificar e aguarde o exame finalizar.
    • Clique no botão Limpar.
    • Abrirá um bloco de notas com o resultado.
    • Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.
    • O log também será salvo em C:\AdwCleaner


    NOTA: Se o AdwCleaner encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC. Faça isso imediatamente, ao ser perguntado se quer reiniciar.
     
    # Etapa nº 2 #
     
    Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

    Baixe o Junkware Removal Tool (JRT) e salve em sua Área de trabalho (Desktop)

     

    Execute o jrt.exe Como Administrador

    • A ferramenta começará o exame do seu sistema.
    • Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.
    • Ao final um log se abrirá. Será salvo no desktop com o nome de JRT.txt.
    • Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

     
    # Etapa nº 3 #
     
    Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

    Faça o download do ZHPCleaner e salve em sua Área de trabalho (Desktop)

     

    Execute o arquivo ZHPCleaner.exe Como Administrador

    • Clique no botão Scanner.
    • A ferramenta começara o exame do seu sistema.
    • Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.
    • Em seguida clique no botão Reparar.
    • Será gerado um log chamado ZHPCleaner.txt
    • Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

    Abraços :D

    • Curtir 1

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Bom dia! :)

     

    Desative temporariamente seu antivírus, antispywares e firewall, para não causar conflitos.

     

    Baixe o Farbar Recovery Scan Tool e salve-o na Área de Trabalho (Desktop).


    32 bit (x86) ou 64 bit (x64)

    • Clique com o botão direito e escolha Executar como Administrador;
    • Marque a caixa Arquivos 90 dias,  e clique no botão Examinar;
    • Aguarde e ao final os logs FRST.txt e Addition.txt serão salvos em sua Área de Trabalho (Desktop);
    • Selecione, copie e cole o conteúdo do log  FRST.txt em sua próxima resposta;
    • Anexe o log Addition.txt.

    Abraços :D

    • Curtir 1

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Boa noite @diego_moicano

     

    Segue FRST.txt:

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01
    Ran by gabri (administrator) on WINDOWS-8C63VIO (18-09-2017 18:06:46)
    Running from C:\Users\gabri\Desktop
    Loaded Profiles: gabri (Available Profiles: gabri)
    Platform: Windows 10 Home Version 1703 (X64) Language: Inglês (Estados Unidos)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120165.inf_amd64_3b2006f0a82a4c14\igfxCUIService.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120165.inf_amd64_3b2006f0a82a4c14\IntelCpHDCPSvc.exe
    (Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
    (Intel Corporation) C:\Windows\System32\ibtsiva.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
    (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
    (Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
    (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120165.inf_amd64_3b2006f0a82a4c14\IntelCpHeciSvc.exe
    (McAfee, Inc.) C:\Program Files\mcafee\MfeAV\MfeAVSvc.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\mcsvchost\McSvHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
    () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\cmd.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionUriServer.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.21.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35071.16410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
    (McAfee, Inc.) C:\Program Files\mcafee\vul\McVulCtr.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe
    (McAfee, Inc.) C:\Program Files\mcafee\CoreUI\Launch.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ChromiumContainer\delegate.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9186816 2016-12-23] (Realtek Semiconductor)
    HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [7824848 2016-07-20] (Dell Inc.)
    HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [943536 2016-12-21] (Waves Audio Ltd.)
    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel Corporation)
    HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
    HKU\S-1-5-21-1227778907-1800773084-68729552-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3071776 2017-09-07] (Valve Corporation)
    HKU\S-1-5-21-1227778907-1800773084-68729552-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 189.7.104.24 189.7.104.16
    Tcpip\..\Interfaces\{e7573f4d-efa6-4fcd-afbe-c3753c514e7b}: [DhcpNameServer] 10.49.34.1 10.49.34.2
    Tcpip\..\Interfaces\{fbf224be-bbd7-4d96-aebf-be74bad0b703}: [DhcpNameServer] 189.7.104.24 189.7.104.16

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-1227778907-1800773084-68729552-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-1227778907-1800773084-68729552-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.dell.com
    SearchScopes: HKU\S-1-5-21-1227778907-1800773084-68729552-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-09-02] (Microsoft Corporation)
    BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-09-02] (Microsoft Corporation)
    BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-02] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-02] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-02] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-02] (Microsoft Corporation)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2017-08-08] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2017-08-08] (McAfee, Inc.)

    FireFox:
    ========
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
    FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-07-20]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-09-09] [not signed]
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-08-08] ()
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-08-08] ()
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-09-02] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-28] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-28] (Google Inc.)

    Chrome: 
    =======
    CHR Profile: C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default [2017-09-18]
    CHR Extension: (Google Apresentações) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-08-28]
    CHR Extension: (Sudoku) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\agdhembpgcpfegeigidembjopfhghnpj [2017-09-03]
    CHR Extension: (Google Docs) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-08-28]
    CHR Extension: (Google Drive) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-28]
    CHR Extension: (Sport Clube Internacional) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bliacfcnokgdkdneoioaaahibjcbdpgl [2017-09-03]
    CHR Extension: (YouTube) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-28]
    CHR Extension: (Math Mahjong) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbcfbhpnngegochhbdlanodnmijfplal [2017-09-03]
    CHR Extension: (Planilhas do Google) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-08-28]
    CHR Extension: (McAfee® WebAdvisor) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-08-29]
    CHR Extension: (Documentos Google off-line) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-28]
    CHR Extension: (AdBlock) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-09-03]
    CHR Extension: (Chess!) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhajejfkogjnnkenablkhgkdmmenbjgh [2017-09-03]
    CHR Extension: (Calculadora) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao [2017-09-03]
    CHR Extension: (Google Maps) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-09-03]
    CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-28]
    CHR Extension: (Tarifa de Táxi) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbldopcdkcepddcophogapjebhfjbpfp [2017-09-03]
    CHR Extension: (Gmail) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-28]
    CHR Extension: (Chrome Media Router) - C:\Users\gabri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-28]
    CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4424384 2017-08-28] (Microsoft Corporation)
    R3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1511728 2017-08-10] (McAfee, Inc.)
    S2 CLKMSVC10_3CD7F304; C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDVD14\Common\NavFilter\KmSvc.exe [312088 2016-05-10] (CyberLink)
    R2 esifsvc; C:\windows\system32\Intel\DPTF\esif_uf.exe [2208888 2016-09-02] (Intel Corporation)
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17976 2016-09-20] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-26] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-10-05] (Intel Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [590880 2017-09-06] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [993256 2017-08-07] (McAfee, Inc.)
    S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [419096 2016-04-01] (McAfee, Inc.)
    R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-30] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.)
    R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.)
    R3 mfevtp; C:\windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.)
    R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1546904 2017-08-17] (McAfee, Inc.)
    S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    S3 NcdAutoSetup; C:\windows\System32\svchost.exe [47664 2017-03-18] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
    S3 NcdAutoSetup; C:\windows\SysWOW64\svchost.exe [40904 2017-03-18] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
    R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1043864 2017-07-31] (Intel Security, Inc.)
    R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [320512 2016-12-23] (Realtek Semiconductor)
    R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [410032 2016-12-21] (Waves Audio Ltd.)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
    R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
    R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 cfwids; C:\windows\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.)
    R1 CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
    R3 dptf_acpi; C:\windows\System32\drivers\dptf_acpi.sys [71232 2016-08-12] (Intel Corporation)
    R3 dptf_cpu; C:\windows\System32\drivers\dptf_cpu.sys [66624 2016-08-12] (Intel Corporation)
    R3 esif_lf; C:\windows\system32\DRIVERS\esif_lf.sys [350272 2016-08-12] (Intel Corporation)
    R3 HidEventFilter; C:\windows\System32\drivers\HidEventFilter.sys [54800 2016-08-16] (Intel Corporation)
    S3 HipShieldK; C:\windows\System32\drivers\HipShieldK.sys [209608 2017-08-07] (McAfee, Inc.)
    S3 iaLPSS2_GPIO2; C:\windows\System32\drivers\iaLPSS2_GPIO2.sys [89912 2016-08-29] (Intel Corporation)
    S3 ibtuart; C:\windows\System32\drivers\ibtuart.sys [762632 2016-10-07] (Intel Corporation)
    R3 ibtusb; C:\windows\system32\DRIVERS\ibtusb.sys [249104 2016-10-07] (Intel Corporation)
    R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 mfeaack; C:\windows\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.)
    R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.)
    U3 mfeavfk01; no ImagePath
    S0 mfeelamk; C:\windows\System32\drivers\mfeelamk.sys [84544 2017-06-26] (McAfee, Inc.)
    R3 mfefirek; C:\windows\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.)
    R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.)
    R3 mfencbdc; C:\windows\System32\DRIVERS\mfencbdc.sys [504792 2017-06-27] (McAfee LLC.)
    S3 mfencrk; C:\windows\System32\DRIVERS\mfencrk.sys [108504 2017-06-27] (McAfee LLC.)
    R3 mfeplk; C:\windows\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.)
    R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
    R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.)
    R3 Netwtw04; C:\windows\System32\drivers\Netwtw04.sys [7308560 2016-09-13] (Intel Corporation)
    R3 nvlddmkm; C:\windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_16a2b84d76fc369e\nvlddmkm.sys [14157752 2016-11-08] (NVIDIA Corporation)
    S3 NVSWCFilter; C:\windows\System32\drivers\nvswcfilter.sys [35272 2016-07-31] (Windows (R) Win 7 DDK provider)
    R3 rt640x64; C:\windows\System32\drivers\rt640x64.sys [946696 2016-10-19] (Realtek )
    S3 RTSUER; C:\windows\system32\Drivers\RtsUer.sys [418784 2016-08-05] (Realsil Semiconductor Corporation)
    S3 SDFRd; C:\windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
    S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
    S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
    S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
    R1 ZAM; C:\windows\System32\drivers\zam64.sys [203680 2017-09-09] (Zemana Ltd.)
    R1 ZAM_Guard; C:\windows\System32\drivers\zamguard64.sys [203680 2017-09-09] (Zemana Ltd.)
    S3 xhunter1; \??\C:\windows\xhunter1.sys [X]
    S3 xspirit; \??\C:\windows\xspirit.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Three Months Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-09-18 18:06 - 2017-09-18 18:07 - 000021907 _____ C:\Users\gabri\Desktop\FRST.txt
    2017-09-18 18:06 - 2017-09-18 18:06 - 000000000 ____D C:\FRST
    2017-09-18 18:03 - 2017-09-18 18:03 - 002399744 _____ (Farbar) C:\Users\gabri\Desktop\FRST64.exe
    2017-09-18 18:02 - 2017-09-18 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2017-09-17 11:25 - 2017-09-17 11:25 - 000001772 _____ C:\Users\gabri\Downloads\ZHPCleaner-[R]-17092017-11_11_23.txt
    2017-09-17 11:09 - 2017-09-17 11:14 - 000001571 _____ C:\Users\gabri\Desktop\ZHPCleaner.txt
    2017-09-17 11:05 - 2017-09-17 11:14 - 000000000 ____D C:\Users\gabri\AppData\Roaming\ZHP
    2017-09-17 11:05 - 2017-09-17 11:05 - 000000877 _____ C:\Users\gabri\Desktop\ZHPCleaner.lnk
    2017-09-17 11:05 - 2017-09-17 11:05 - 000000000 ____D C:\Users\gabri\AppData\Local\ZHP
    2017-09-17 11:04 - 2017-09-17 11:04 - 002884992 _____ C:\Users\gabri\Desktop\ZHPCleaner.exe
    2017-09-17 11:03 - 2017-09-17 11:03 - 000000708 _____ C:\Users\gabri\Desktop\JRT.txt
    2017-09-17 11:00 - 2017-09-17 11:00 - 001790024 _____ (Malwarebytes) C:\Users\gabri\Desktop\JRT.exe
    2017-09-17 10:58 - 2017-09-17 10:58 - 000001129 _____ C:\Users\gabri\Desktop\AdwCleaner[C0].txt
    2017-09-17 10:53 - 2017-09-17 10:53 - 000000945 _____ C:\Users\gabri\Desktop\AdwCleaner[S0].txt
    2017-09-17 10:47 - 2017-09-17 10:54 - 000000000 ____D C:\AdwCleaner
    2017-09-17 10:45 - 2017-09-17 10:45 - 008182736 _____ (Malwarebytes) C:\Users\gabri\Desktop\adwcleaner_7.0.2.1.exe
    2017-09-15 02:44 - 2017-09-15 02:44 - 000000000 ___HD C:\OneDriveTemp
    2017-09-12 18:56 - 2017-09-05 02:30 - 000287648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
    2017-09-12 18:56 - 2017-09-05 02:27 - 002399728 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
    2017-09-12 18:56 - 2017-09-05 02:27 - 000136096 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
    2017-09-12 18:56 - 2017-09-05 02:26 - 008319904 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2017-09-12 18:56 - 2017-09-05 02:26 - 001930840 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
    2017-09-12 18:56 - 2017-09-05 02:25 - 002969880 _____ (Microsoft Corporation) C:\windows\system32\CoreUIComponents.dll
    2017-09-12 18:56 - 2017-09-05 02:24 - 000519584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
    2017-09-12 18:56 - 2017-09-05 02:23 - 001242528 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
    2017-09-12 18:56 - 2017-09-05 02:21 - 000189344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
    2017-09-12 18:56 - 2017-09-05 02:18 - 002972552 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
    2017-09-12 18:56 - 2017-09-05 02:18 - 000820128 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe
    2017-09-12 18:56 - 2017-09-05 02:18 - 000212384 _____ (Microsoft Corporation) C:\windows\system32\browserbroker.dll
    2017-09-12 18:56 - 2017-09-05 02:17 - 000316320 _____ (Microsoft Corporation) C:\windows\system32\WerFault.exe
    2017-09-12 18:56 - 2017-09-05 02:16 - 000724200 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
    2017-09-12 18:56 - 2017-09-05 02:16 - 000546208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
    2017-09-12 18:56 - 2017-09-05 02:16 - 000410168 _____ (Microsoft Corporation) C:\windows\system32\Faultrep.dll
    2017-09-12 18:56 - 2017-09-05 02:16 - 000182688 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
    2017-09-12 18:56 - 2017-09-05 02:15 - 000654976 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentClient.dll
    2017-09-12 18:56 - 2017-09-05 02:14 - 004708504 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
    2017-09-12 18:56 - 2017-09-05 02:14 - 001146176 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
    2017-09-12 18:56 - 2017-09-05 02:14 - 000958664 _____ (Microsoft Corporation) C:\windows\system32\msvproc.dll
    2017-09-12 18:56 - 2017-09-05 02:14 - 000254176 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
    2017-09-12 18:56 - 2017-09-05 02:14 - 000094624 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
    2017-09-12 18:56 - 2017-09-05 02:12 - 001409048 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32full.dll
    2017-09-12 18:56 - 2017-09-05 02:12 - 001292880 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
    2017-09-12 18:56 - 2017-09-05 02:12 - 000627080 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontdrvhost.exe
    2017-09-12 18:56 - 2017-09-05 02:12 - 000081176 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32u.dll
    2017-09-12 18:56 - 2017-09-05 02:11 - 002675104 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
    2017-09-12 18:56 - 2017-09-05 02:11 - 000610720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
    2017-09-12 18:56 - 2017-09-05 02:11 - 000387936 _____ (Microsoft Corporation) C:\windows\system32\wmpps.dll
    2017-09-12 18:56 - 2017-09-05 01:53 - 001839872 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
    2017-09-12 18:56 - 2017-09-05 01:53 - 001620880 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
    2017-09-12 18:56 - 2017-09-05 01:52 - 002259760 _____ (Microsoft Corporation) C:\windows\SysWOW64\CoreUIComponents.dll
    2017-09-12 18:56 - 2017-09-05 01:50 - 004330920 _____ (Microsoft Corporation) C:\windows\SysWOW64\setupapi.dll
    2017-09-12 18:56 - 2017-09-05 01:46 - 004471888 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
    2017-09-12 18:56 - 2017-09-05 01:45 - 023679488 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
    2017-09-12 18:56 - 2017-09-05 01:45 - 005821496 _____ (Microsoft Corporation) C:\windows\SysWOW64\windows.storage.dll
    2017-09-12 18:56 - 2017-09-05 01:45 - 002476712 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
    2017-09-12 18:56 - 2017-09-05 01:45 - 002166808 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2017-09-12 18:56 - 2017-09-05 01:45 - 000750496 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe
    2017-09-12 18:56 - 2017-09-05 01:45 - 000085784 _____ (Microsoft Corporation) C:\windows\SysWOW64\CredentialUIBroker.exe
    2017-09-12 18:56 - 2017-09-05 01:44 - 000569264 _____ (Microsoft Corporation) C:\windows\SysWOW64\SHCore.dll
    2017-09-12 18:56 - 2017-09-05 01:43 - 000611096 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
    2017-09-12 18:56 - 2017-09-05 01:43 - 000359560 _____ (Microsoft Corporation) C:\windows\SysWOW64\Faultrep.dll
    2017-09-12 18:56 - 2017-09-05 01:43 - 000280480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFault.exe
    2017-09-12 18:56 - 2017-09-05 01:43 - 000169376 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
    2017-09-12 18:56 - 2017-09-05 01:43 - 000042456 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbs.dll
    2017-09-12 18:56 - 2017-09-05 01:42 - 002330520 _____ (Microsoft Corporation) C:\windows\SysWOW64\combase.dll
    2017-09-12 18:56 - 2017-09-05 01:42 - 000703056 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
    2017-09-12 18:56 - 2017-09-05 01:42 - 000519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppXDeploymentClient.dll
    2017-09-12 18:56 - 2017-09-05 01:42 - 000291904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wevtapi.dll
    2017-09-12 18:56 - 2017-09-05 01:42 - 000182688 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
    2017-09-12 18:56 - 2017-09-05 01:41 - 020373408 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
    2017-09-12 18:56 - 2017-09-05 01:41 - 006761560 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2017-09-12 18:56 - 2017-09-05 01:41 - 004671832 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
    2017-09-12 18:56 - 2017-09-05 01:41 - 001106904 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
    2017-09-12 18:56 - 2017-09-05 01:41 - 001013912 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvproc.dll
    2017-09-12 18:56 - 2017-09-05 01:40 - 000052768 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
    2017-09-12 18:56 - 2017-09-05 01:37 - 000583160 _____ (Microsoft Corporation) C:\windows\SysWOW64\CoreMessaging.dll
    2017-09-12 18:56 - 2017-09-05 01:29 - 000037376 _____ (Microsoft Corporation) C:\windows\system32\SEMgrPS.dll
    2017-09-12 18:56 - 2017-09-05 01:28 - 000071680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbser.sys
    2017-09-12 18:56 - 2017-09-05 01:28 - 000039424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\buttonconverter.sys
    2017-09-12 18:56 - 2017-09-05 01:27 - 000128000 _____ (Microsoft Corporation) C:\windows\system32\mssprxy.dll
    2017-09-12 18:56 - 2017-09-05 01:27 - 000104960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\UcmCx.sys
    2017-09-12 18:56 - 2017-09-05 01:27 - 000095232 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
    2017-09-12 18:56 - 2017-09-05 01:27 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\odbcconf.dll
    2017-09-12 18:56 - 2017-09-05 01:26 - 002953216 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32kfull.sys
    2017-09-12 18:56 - 2017-09-05 01:26 - 000404480 _____ (Microsoft Corporation) C:\windows\SysWOW64\werui.dll
    2017-09-12 18:56 - 2017-09-05 01:26 - 000130560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthpan.sys
    2017-09-12 18:56 - 2017-09-05 01:26 - 000107008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidbth.sys
    2017-09-12 18:56 - 2017-09-05 01:26 - 000084992 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2017-09-12 18:56 - 2017-09-05 01:26 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
    2017-09-12 18:56 - 2017-09-05 01:26 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
    2017-09-12 18:56 - 2017-09-05 01:25 - 013844480 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
    2017-09-12 18:56 - 2017-09-05 01:25 - 001448960 _____ (Microsoft Corporation) C:\windows\SysWOW64\GdiPlus.dll
    2017-09-12 18:56 - 2017-09-05 01:25 - 000293376 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32k.sys
    2017-09-12 18:56 - 2017-09-05 01:25 - 000154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWWIN.EXE
    2017-09-12 18:56 - 2017-09-05 01:25 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nsiproxy.sys
    2017-09-12 18:56 - 2017-09-05 01:24 - 002199552 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.Resources.dll
    2017-09-12 18:56 - 2017-09-05 01:24 - 000457728 _____ (Microsoft Corporation) C:\windows\system32\webplatstorageserver.dll
    2017-09-12 18:56 - 2017-09-05 01:24 - 000353280 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
    2017-09-12 18:56 - 2017-09-05 01:24 - 000334336 _____ (Microsoft Corporation) C:\windows\system32\wc_storage.dll
    2017-09-12 18:56 - 2017-09-05 01:24 - 000182272 _____ (Microsoft Corporation) C:\windows\system32\ngcrecovery.dll
    2017-09-12 18:56 - 2017-09-05 01:24 - 000096256 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2017-09-12 18:56 - 2017-09-05 01:23 - 020509184 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
    2017-09-12 18:56 - 2017-09-05 01:23 - 000140288 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
    2017-09-12 18:56 - 2017-09-05 01:23 - 000107008 _____ (Microsoft Corporation) C:\windows\system32\ngcpopkeysrv.dll
    2017-09-12 18:56 - 2017-09-05 01:23 - 000025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcconf.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 023684608 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000742912 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000640512 _____ (Microsoft Corporation) C:\windows\system32\ngccredprov.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000477696 _____ (Microsoft Corporation) C:\windows\system32\rasplap.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000458752 _____ (Microsoft Corporation) C:\windows\system32\NgcCtnr.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000388096 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000327168 _____ (Microsoft Corporation) C:\windows\system32\WinBioDataModel.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000274944 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000225792 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2017-09-12 18:56 - 2017-09-05 01:22 - 000173568 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000165888 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
    2017-09-12 18:56 - 2017-09-05 01:22 - 000079872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 006728704 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 001178624 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.Vpn.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 001051136 _____ (Microsoft Corporation) C:\windows\system32\nettrace.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000946688 _____ (Microsoft Corporation) C:\windows\system32\rasgcw.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000422400 _____ (Microsoft Corporation) C:\windows\system32\WpAXHolder.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000408576 _____ (Microsoft Corporation) C:\windows\system32\cryptngc.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\Phoneutil.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\srpapi.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2017-09-12 18:56 - 2017-09-05 01:21 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
    2017-09-12 18:56 - 2017-09-05 01:20 - 000805888 _____ (Microsoft Corporation) C:\windows\system32\ieproxy.dll
    2017-09-12 18:56 - 2017-09-05 01:20 - 000546816 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
    2017-09-12 18:56 - 2017-09-05 01:20 - 000412160 _____ (Microsoft Corporation) C:\windows\system32\ActivationManager.dll
    2017-09-12 18:56 - 2017-09-05 01:20 - 000370176 _____ (Microsoft Corporation) C:\windows\SysWOW64\daxexec.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 019336192 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000364032 _____ (Microsoft Corporation) C:\windows\SysWOW64\msIso.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000311296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000181760 _____ (Microsoft Corporation) C:\windows\SysWOW64\authz.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000134656 _____ (Microsoft Corporation) C:\windows\SysWOW64\dinput.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
    2017-09-12 18:56 - 2017-09-05 01:19 - 000080384 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 012801536 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 002078720 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2017-09-12 18:56 - 2017-09-05 01:18 - 000921600 _____ (Microsoft Corporation) C:\windows\system32\rasdlg.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000832000 _____ (Microsoft Corporation) C:\windows\system32\printfilterpipelinesvc.exe
    2017-09-12 18:56 - 2017-09-05 01:18 - 000752640 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\ngccredprov.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000491520 _____ (Microsoft Corporation) C:\windows\system32\NgcCtnrSvc.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000471040 _____ (Microsoft Corporation) C:\windows\SysWOW64\TpmCoreProvisioning.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000452608 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasplap.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000339968 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000266240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000257024 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000176640 _____ (Microsoft Corporation) C:\windows\system32\wersvc.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dinput8.dll
    2017-09-12 18:56 - 2017-09-05 01:18 - 000100352 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasman.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 008213504 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 008207872 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 000918528 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Networking.Vpn.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 000852480 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasgcw.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 000757760 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
    2017-09-12 18:56 - 2017-09-05 01:17 - 000586240 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
    2017-09-12 18:56 - 2017-09-05 01:17 - 000307712 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptngc.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 005961728 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 000844288 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasdlg.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 000563200 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 000358400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieproxy.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 000357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActivationManager.dll
    2017-09-12 18:56 - 2017-09-05 01:16 - 000257024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Phoneutil.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 004730368 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 004396032 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_47.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 001248768 _____ (Microsoft Corporation) C:\windows\SysWOW64\AzureSettingSyncProvider.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 001143296 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 000664576 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 000657408 _____ (Microsoft Corporation) C:\windows\SysWOW64\netlogon.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 000636416 _____ (Microsoft Corporation) C:\windows\SysWOW64\WpcWebFilter.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 000430592 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
    2017-09-12 18:56 - 2017-09-05 01:15 - 000232960 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2017-09-12 18:56 - 2017-09-05 01:15 - 000223744 _____ (Microsoft Corporation) C:\windows\SysWOW64\shdocvw.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 011887104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 005557760 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 002516480 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 002006528 _____ (Microsoft Corporation) C:\windows\system32\LocationFramework.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 001657344 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 001583616 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 001046016 _____ (Microsoft Corporation) C:\windows\system32\ngcsvc.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 000827904 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 000754176 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 000590336 _____ (Microsoft Corporation) C:\windows\SysWOW64\PCPKsp.dll
    2017-09-12 18:56 - 2017-09-05 01:14 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dsreg.dll
    2017-09-12 18:56 - 2017-09-05 01:13 - 007598080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
    2017-09-12 18:56 - 2017-09-05 01:13 - 002009600 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2017-09-12 18:56 - 2017-09-05 01:13 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\cldapi.dll
    2017-09-12 18:56 - 2017-09-05 01:12 - 006265856 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
    2017-09-12 18:56 - 2017-09-05 01:12 - 005225984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
    2017-09-12 18:56 - 2017-09-05 01:12 - 002859520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2017-09-12 18:56 - 2017-09-05 01:12 - 000899584 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 003667456 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_47.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 003654656 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 001463296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 001355264 _____ (Microsoft Corporation) C:\windows\SysWOW64\OpcServices.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 001060352 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 001019904 _____ (Microsoft Corporation) C:\windows\SysWOW64\aadtb.dll
    2017-09-12 18:56 - 2017-09-05 01:11 - 000787456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
    2017-09-12 18:56 - 2017-09-05 01:10 - 004559360 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
    2017-09-12 18:56 - 2017-09-05 01:10 - 001627136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2017-09-12 18:56 - 2017-09-05 01:10 - 000761344 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasapi32.dll
    2017-09-12 18:56 - 2017-09-05 01:10 - 000431616 _____ (Microsoft Corporation) C:\windows\system32\BthHFSrv.dll
    2017-09-12 18:56 - 2017-09-05 01:06 - 000221696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wisp.dll
    2017-09-12 18:56 - 2017-09-05 01:06 - 000089088 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
    2017-09-12 18:56 - 2017-09-05 01:06 - 000078848 _____ (Microsoft Corporation) C:\windows\system32\offreg.dll
    2017-09-12 18:56 - 2017-09-05 01:04 - 000175616 _____ (Microsoft Corporation) C:\windows\SysWOW64\RstrtMgr.dll
    2017-09-12 18:56 - 2017-09-05 01:04 - 000057856 _____ (Microsoft Corporation) C:\windows\SysWOW64\offreg.dll
    2017-09-12 18:56 - 2017-09-01 02:55 - 000031932 _____ C:\windows\system32\edgehtmlpluginpolicy.bin
    2017-09-12 18:55 - 2017-09-05 02:31 - 001596592 _____ (Microsoft Corporation) C:\windows\system32\gdi32full.dll
    2017-09-12 18:55 - 2017-09-05 02:31 - 001346112 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
    2017-09-12 18:55 - 2017-09-05 02:31 - 001147296 _____ (Microsoft Corporation) C:\windows\system32\hvix64.exe
    2017-09-12 18:55 - 2017-09-05 02:31 - 001024928 _____ (Microsoft Corporation) C:\windows\system32\hvax64.exe
    2017-09-12 18:55 - 2017-09-05 02:31 - 000821664 _____ (Microsoft Corporation) C:\windows\system32\hvloader.exe
    2017-09-12 18:55 - 2017-09-05 02:31 - 000750560 _____ (Microsoft Corporation) C:\windows\system32\fontdrvhost.exe
    2017-09-12 18:55 - 2017-09-05 02:31 - 000115792 _____ (Microsoft Corporation) C:\windows\system32\win32u.dll
    2017-09-12 18:55 - 2017-09-05 02:25 - 000159648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\partmgr.sys
    2017-09-12 18:55 - 2017-09-05 02:24 - 000923040 _____ (Microsoft Corporation) C:\windows\system32\CoreMessaging.dll
    2017-09-12 18:55 - 2017-09-05 02:23 - 004462120 _____ (Microsoft Corporation) C:\windows\system32\setupapi.dll
    2017-09-12 18:55 - 2017-09-05 02:20 - 001057824 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
    2017-09-12 18:55 - 2017-09-05 02:19 - 004848960 _____ (Microsoft Corporation) C:\windows\explorer.exe
    2017-09-12 18:55 - 2017-09-05 02:19 - 002443168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
    2017-09-12 18:55 - 2017-09-05 02:18 - 007326128 _____ (Microsoft Corporation) C:\windows\system32\windows.storage.dll
    2017-09-12 18:55 - 2017-09-05 02:18 - 005477096 _____ (Microsoft Corporation) C:\windows\system32\OneCoreUAPCommonProxyStub.dll
    2017-09-12 18:55 - 2017-09-05 02:18 - 002647224 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2017-09-12 18:55 - 2017-09-05 02:18 - 001668344 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll
    2017-09-12 18:55 - 2017-09-05 02:18 - 000685512 _____ (Microsoft Corporation) C:\windows\system32\SHCore.dll
    2017-09-12 18:55 - 2017-09-05 02:16 - 001320344 _____ (Microsoft Corporation) C:\windows\system32\wpx.dll
    2017-09-12 18:55 - 2017-09-05 02:16 - 000872472 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
    2017-09-12 18:55 - 2017-09-05 02:16 - 000715168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
    2017-09-12 18:55 - 2017-09-05 02:16 - 000228256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
    2017-09-12 18:55 - 2017-09-05 02:16 - 000049720 _____ (Microsoft Corporation) C:\windows\system32\tbs.dll
    2017-09-12 18:55 - 2017-09-05 02:15 - 003116184 _____ (Microsoft Corporation) C:\windows\system32\combase.dll
    2017-09-12 18:55 - 2017-09-05 02:15 - 000871448 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
    2017-09-12 18:55 - 2017-09-05 02:15 - 000381824 _____ (Microsoft Corporation) C:\windows\system32\wevtapi.dll
    2017-09-12 18:55 - 2017-09-05 02:15 - 000257440 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
    2017-09-12 18:55 - 2017-09-05 02:14 - 021352656 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
    2017-09-12 18:55 - 2017-09-05 02:14 - 007907344 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
    2017-09-12 18:55 - 2017-09-05 02:13 - 001619816 _____ (Microsoft Corporation) C:\windows\system32\sppobjs.dll
    2017-09-12 18:55 - 2017-09-05 02:13 - 000064680 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
    2017-09-12 18:55 - 2017-09-05 01:31 - 003668992 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
    2017-09-12 18:55 - 2017-09-05 01:30 - 001639936 _____ (Microsoft Corporation) C:\windows\system32\GdiPlus.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 001275904 _____ (Microsoft Corporation) C:\windows\system32\werconcpl.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 000584192 _____ (Microsoft Corporation) C:\windows\system32\UIRibbonRes.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 000463360 _____ (Microsoft Corporation) C:\windows\system32\werui.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 000447488 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2017-09-12 18:55 - 2017-09-05 01:30 - 000184320 _____ (Microsoft Corporation) C:\windows\system32\DWWIN.EXE
    2017-09-12 18:55 - 2017-09-05 01:30 - 000093184 _____ (Microsoft Corporation) C:\windows\system32\wercplsupport.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 000089088 _____ (Microsoft Corporation) C:\windows\system32\winsrvext.dll
    2017-09-12 18:55 - 2017-09-05 01:30 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\wsqmcons.exe
    2017-09-12 18:55 - 2017-09-05 01:28 - 017371136 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
    2017-09-12 18:55 - 2017-09-05 01:28 - 002199552 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.Resources.dll
    2017-09-12 18:55 - 2017-09-05 01:27 - 007931392 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
    2017-09-12 18:55 - 2017-09-05 01:27 - 000133632 _____ (Microsoft Corporation) C:\windows\system32\CfgSPCellular.dll
    2017-09-12 18:55 - 2017-09-05 01:27 - 000131584 _____ (Microsoft Corporation) C:\windows\system32\EnterpriseAPNCsp.dll
    2017-09-12 18:55 - 2017-09-05 01:27 - 000090112 _____ (Microsoft Corporation) C:\windows\system32\datamarketsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:27 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
    2017-09-12 18:55 - 2017-09-05 01:26 - 000499712 _____ (Microsoft Corporation) C:\windows\system32\nltest.exe
    2017-09-12 18:55 - 2017-09-05 01:26 - 000156160 _____ (Microsoft Corporation) C:\windows\system32\csplte.dll
    2017-09-12 18:55 - 2017-09-05 01:26 - 000142848 _____ (Microsoft Corporation) C:\windows\system32\srpapi.dll
    2017-09-12 18:55 - 2017-09-05 01:26 - 000124928 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll
    2017-09-12 18:55 - 2017-09-05 01:26 - 000113152 _____ (Microsoft Corporation) C:\windows\system32\wuuhosdeployment.dll
    2017-09-12 18:55 - 2017-09-05 01:25 - 000584192 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIRibbonRes.dll
    2017-09-12 18:55 - 2017-09-05 01:25 - 000527872 _____ (Microsoft Corporation) C:\windows\system32\daxexec.dll
    2017-09-12 18:55 - 2017-09-05 01:25 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
    2017-09-12 18:55 - 2017-09-05 01:25 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\TpmTasks.dll
    2017-09-12 18:55 - 2017-09-05 01:24 - 000385536 _____ (Microsoft Corporation) C:\windows\system32\tpmvsc.dll
    2017-09-12 18:55 - 2017-09-05 01:24 - 000274432 _____ (Microsoft Corporation) C:\windows\system32\authz.dll
    2017-09-12 18:55 - 2017-09-05 01:24 - 000160768 _____ (Microsoft Corporation) C:\windows\system32\dinput.dll
    2017-09-12 18:55 - 2017-09-05 01:24 - 000109056 _____ (Microsoft Corporation) C:\windows\system32\dab.dll
    2017-09-12 18:55 - 2017-09-05 01:23 - 000739840 _____ (Microsoft Corporation) C:\windows\system32\PhoneProviders.dll
    2017-09-12 18:55 - 2017-09-05 01:23 - 000450048 _____ (Microsoft Corporation) C:\windows\system32\bcdedit.exe
    2017-09-12 18:55 - 2017-09-05 01:23 - 000433664 _____ (Microsoft Corporation) C:\windows\system32\msIso.dll
    2017-09-12 18:55 - 2017-09-05 01:23 - 000305152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbt.sys
    2017-09-12 18:55 - 2017-09-05 01:23 - 000138752 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
    2017-09-12 18:55 - 2017-09-05 01:23 - 000128512 _____ (Microsoft Corporation) C:\windows\system32\rasman.dll
    2017-09-12 18:55 - 2017-09-05 01:22 - 000556032 _____ (Microsoft Corporation) C:\windows\system32\TpmCoreProvisioning.dll
    2017-09-12 18:55 - 2017-09-05 01:22 - 000527360 _____ (Microsoft Corporation) C:\windows\system32\aadcloudap.dll
    2017-09-12 18:55 - 2017-09-05 01:22 - 000413184 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:22 - 000329728 _____ (Microsoft Corporation) C:\windows\system32\RasMediaManager.dll
    2017-09-12 18:55 - 2017-09-05 01:22 - 000213504 _____ (Microsoft Corporation) C:\windows\system32\dinput8.dll
    2017-09-12 18:55 - 2017-09-05 01:21 - 000773120 _____ (Microsoft Corporation) C:\windows\system32\PhoneService.dll
    2017-09-12 18:55 - 2017-09-05 01:21 - 000691712 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
    2017-09-12 18:55 - 2017-09-05 01:20 - 007337472 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
    2017-09-12 18:55 - 2017-09-05 01:20 - 001878016 _____ (Microsoft Corporation) C:\windows\system32\AzureSettingSyncProvider.dll
    2017-09-12 18:55 - 2017-09-05 01:20 - 000925696 _____ (Microsoft Corporation) C:\windows\system32\WpcWebFilter.dll
    2017-09-12 18:55 - 2017-09-05 01:20 - 000282112 _____ (Microsoft Corporation) C:\windows\system32\dnsrslvr.dll
    2017-09-12 18:55 - 2017-09-05 01:20 - 000229888 _____ (Microsoft Corporation) C:\windows\system32\SIHClient.exe
    2017-09-12 18:55 - 2017-09-05 01:19 - 001260544 _____ (Microsoft Corporation) C:\windows\system32\GamePanel.exe
    2017-09-12 18:55 - 2017-09-05 01:19 - 001085440 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
    2017-09-12 18:55 - 2017-09-05 01:19 - 001028608 _____ (Microsoft Corporation) C:\windows\system32\modernexecserver.dll
    2017-09-12 18:55 - 2017-09-05 01:19 - 000996864 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:19 - 000772096 _____ (Microsoft Corporation) C:\windows\system32\PCPKsp.dll
    2017-09-12 18:55 - 2017-09-05 01:19 - 000772096 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
    2017-09-12 18:55 - 2017-09-05 01:19 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 004175872 _____ (Microsoft Corporation) C:\windows\system32\StartTileData.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000922112 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000874496 _____ (Microsoft Corporation) C:\windows\system32\rasmans.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000864256 _____ (Microsoft Corporation) C:\windows\system32\NotificationController.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000803328 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000564736 _____ (Microsoft Corporation) C:\windows\system32\dsreg.dll
    2017-09-12 18:55 - 2017-09-05 01:18 - 000056832 _____ (Microsoft Corporation) C:\windows\system32\cldapi.dll
    2017-09-12 18:55 - 2017-09-05 01:17 - 002765824 _____ (Microsoft Corporation) C:\windows\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
    2017-09-12 18:55 - 2017-09-05 01:17 - 001886208 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.onecore.dll
    2017-09-12 18:55 - 2017-09-05 01:17 - 001397760 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
    2017-09-12 18:55 - 2017-09-05 01:16 - 002805248 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
    2017-09-12 18:55 - 2017-09-05 01:16 - 002680320 _____ (Microsoft Corporation) C:\windows\system32\Windows.CloudStore.dll
    2017-09-12 18:55 - 2017-09-05 01:16 - 000440320 _____ (Microsoft Corporation) C:\windows\system32\windows.immersiveshell.serviceprovider.dll
    2017-09-12 18:55 - 2017-09-05 01:16 - 000397312 _____ (Microsoft Corporation) C:\windows\system32\rascustom.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 003307008 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 003059200 _____ (Microsoft Corporation) C:\windows\system32\NetworkMobileSettings.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 002503680 _____ (Microsoft Corporation) C:\windows\system32\twinui.pcshell.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 002055680 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
    2017-09-12 18:55 - 2017-09-05 01:15 - 001736704 _____ (Microsoft Corporation) C:\windows\system32\wevtsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 001460224 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 001293824 _____ (Microsoft Corporation) C:\windows\system32\aadtb.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 001077248 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll
    2017-09-12 18:55 - 2017-09-05 01:15 - 000706560 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
    2017-09-12 18:55 - 2017-09-05 01:14 - 002445824 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
    2017-09-12 18:55 - 2017-09-05 01:14 - 002177024 _____ (Microsoft Corporation) C:\windows\system32\OpcServices.dll
    2017-09-12 18:55 - 2017-09-05 01:14 - 000986624 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
    2017-09-12 18:55 - 2017-09-05 01:14 - 000810496 _____ (Microsoft Corporation) C:\windows\system32\rasapi32.dll
    2017-09-12 18:55 - 2017-09-05 01:13 - 001802752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2017-09-12 18:55 - 2017-09-05 01:13 - 000407040 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll
    2017-09-12 18:55 - 2017-09-05 01:12 - 002153984 _____ (Microsoft Corporation) C:\windows\system32\wlidsvc.dll
    2017-09-12 18:55 - 2017-09-05 01:11 - 000254976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
    2017-09-12 18:55 - 2017-09-05 01:09 - 000268288 _____ (Microsoft Corporation) C:\windows\system32\wisp.dll
    2017-09-12 18:55 - 2017-09-05 01:07 - 000201728 _____ (Microsoft Corporation) C:\windows\system32\RstrtMgr.dll
    2017-09-12 18:55 - 2017-09-05 01:07 - 000061952 _____ (Microsoft Corporation) C:\windows\system32\vss_ps.dll
    2017-09-12 18:22 - 2017-09-12 18:22 - 000019756 _____ C:\Users\gabri\Desktop\ZA-Scan.txt
    2017-09-12 18:20 - 2017-09-12 18:20 - 000019753 _____ C:\ZA-Scan.txt
    2017-09-12 18:18 - 2017-09-12 18:20 - 000000147 _____ C:\runcheck.txt
    2017-09-09 16:05 - 2017-09-09 16:05 - 000000685 _____ C:\DelFix.txt
    2017-09-09 16:05 - 2017-09-09 16:05 - 000000000 ____D C:\windows\ERUNT
    2017-09-09 15:58 - 2017-09-18 18:07 - 004294600 _____ C:\windows\ZAM.krnl.trace
    2017-09-09 15:58 - 2017-09-18 18:07 - 000622632 _____ C:\windows\ZAM_Guard.krnl.trace
    2017-09-09 15:58 - 2017-09-09 15:58 - 000203680 _____ (Zemana Ltd.) C:\windows\system32\Drivers\zamguard64.sys
    2017-09-09 15:58 - 2017-09-09 15:58 - 000203680 _____ (Zemana Ltd.) C:\windows\system32\Drivers\zam64.sys
    2017-09-09 15:58 - 2017-09-09 15:58 - 000001219 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
    2017-09-09 15:58 - 2017-09-09 15:58 - 000000000 ____D C:\Users\gabri\AppData\Local\Zemana
    2017-09-09 15:58 - 2017-09-09 15:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
    2017-09-09 15:58 - 2017-09-09 15:58 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
    2017-09-09 15:41 - 2017-09-09 15:43 - 000000000 ____D C:\MGtools
    2017-09-09 15:23 - 2017-09-12 18:44 - 000192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
    2017-09-09 15:23 - 2017-09-09 15:23 - 000001173 _____ C:\Users\Public\Desktop\MB.lnk
    2017-09-09 15:23 - 2017-09-09 15:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2017-09-09 15:23 - 2017-09-09 15:23 - 000000000 ____D C:\ProgramData\Malwarebytes
    2017-09-09 15:23 - 2017-09-09 15:23 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2017-09-09 15:23 - 2015-10-05 09:50 - 000109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
    2017-09-09 15:23 - 2015-10-05 09:50 - 000064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
    2017-09-09 15:23 - 2015-10-05 09:50 - 000025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
    2017-09-09 15:15 - 2017-09-09 15:15 - 009598376 _____ (Piriform Ltd) C:\Users\gabri\Downloads\ccsetup531.exe
    2017-09-09 15:15 - 2017-09-09 15:15 - 000002870 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
    2017-09-09 15:15 - 2017-09-09 15:15 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
    2017-09-09 15:15 - 2017-09-09 15:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2017-09-09 15:15 - 2017-09-09 15:15 - 000000000 ____D C:\Program Files\CCleaner
    2017-09-03 17:18 - 2017-09-03 17:18 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Google
    2017-09-03 17:02 - 2015-10-26 03:28 - 001697232 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr110d.dll
    2017-09-03 17:02 - 2015-10-26 03:27 - 001505104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100d.dll
    2017-09-03 17:02 - 2015-10-26 03:27 - 000821200 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp110d.dll
    2017-09-03 17:02 - 2015-09-14 12:37 - 000815272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp120d.dll
    2017-09-03 17:02 - 2013-12-13 12:53 - 001824344 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120d.dll
    2017-09-03 17:01 - 2015-10-26 03:28 - 001697232 _____ (Microsoft Corporation) C:\windows\system32\msvcr110d.dll
    2017-09-03 17:01 - 2015-10-26 03:27 - 001505104 _____ (Microsoft Corporation) C:\windows\system32\msvcr100d.dll
    2017-09-03 17:01 - 2015-10-26 03:27 - 000821200 _____ (Microsoft Corporation) C:\windows\system32\msvcp110d.dll
    2017-09-03 17:01 - 2015-09-14 12:37 - 000815272 _____ (Microsoft Corporation) C:\windows\system32\msvcp120d.dll
    2017-09-03 17:01 - 2013-12-13 12:53 - 001824344 _____ (Microsoft Corporation) C:\windows\system32\msvcr120d.dll
    2017-09-03 16:44 - 2017-09-03 16:44 - 000000000 ____D C:\Users\gabri\AppData\Roaming\WinRAR
    2017-09-03 16:44 - 2017-09-03 16:44 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2017-09-03 16:44 - 2017-09-03 16:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2017-09-03 16:44 - 2017-09-03 16:44 - 000000000 ____D C:\Program Files (x86)\WinRAR
    2017-09-02 15:28 - 2017-09-02 15:28 - 000000000 ____D C:\Users\gabri\Documents\PointBlank
    2017-09-02 14:06 - 2017-09-02 14:06 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Waves Audio
    2017-09-02 13:38 - 2017-09-02 13:38 - 000000000 ____D C:\Users\gabri\AppData\Local\DBG
    2017-08-30 20:30 - 2017-08-30 20:30 - 000000000 ____D C:\windows\SysWOW64\XPSViewer
    2017-08-30 20:29 - 2017-08-30 20:29 - 000000000 ____D C:\Program Files\Reference Assemblies
    2017-08-30 20:29 - 2017-08-30 20:29 - 000000000 ____D C:\Program Files\MSBuild
    2017-08-30 20:29 - 2017-08-30 20:29 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
    2017-08-30 20:29 - 2017-08-30 20:29 - 000000000 ____D C:\Program Files (x86)\MSBuild
    2017-08-30 20:27 - 2017-02-10 11:21 - 000778936 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationNative_v0300.dll
    2017-08-30 20:27 - 2017-02-10 11:21 - 000103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2017-08-30 20:27 - 2017-02-10 11:21 - 000035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
    2017-08-30 20:26 - 2017-02-10 11:26 - 001166520 _____ (Microsoft Corporation) C:\windows\system32\PresentationNative_v0300.dll
    2017-08-30 20:26 - 2017-02-10 11:26 - 000124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2017-08-30 20:26 - 2017-02-10 11:26 - 000035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
    2017-08-29 21:27 - 2010-06-02 04:55 - 000527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll
    2017-08-29 21:27 - 2010-06-02 04:55 - 000518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll
    2017-08-29 21:27 - 2010-06-02 04:55 - 000239960 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_7.dll
    2017-08-29 21:27 - 2010-06-02 04:55 - 000176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_7.dll
    2017-08-29 21:27 - 2010-06-02 04:55 - 000077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll
    2017-08-29 21:27 - 2010-06-02 04:55 - 000074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 002526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 002401112 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 002106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 001998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 001907552 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 001868128 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 000511328 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 000470880 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 000276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll
    2017-08-29 21:27 - 2010-05-26 11:41 - 000248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000530776 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_6.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000528216 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_6.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_6.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000176984 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_6.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000078680 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_4.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_4.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_7.dll
    2017-08-29 21:27 - 2010-02-04 10:01 - 000022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_7.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_5.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_5.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_5.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_5.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_3.dll
    2017-08-29 21:27 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_3.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\windows\system32\d3dcsx_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dcsx_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_42.dll
    2017-08-29 21:27 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_42.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_4.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_4.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_4.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_4.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_6.dll
    2017-08-29 21:27 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_6.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_41.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_41.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_41.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_41.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_41.dll
    2017-08-29 21:27 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_41.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_3.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_3.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_3.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_3.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_2.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_2.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_5.dll
    2017-08-29 21:27 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_5.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_40.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_40.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_40.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_40.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_40.dll
    2017-08-29 21:27 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_40.dll
    2017-08-29 21:27 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_2.dll
    2017-08-29 21:27 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_2.dll
    2017-08-29 21:27 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_1.dll
    2017-08-29 21:27 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_1.dll
    2017-08-29 21:27 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_2.dll
    2017-08-29 21:27 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_2.dll
    2017-08-29 21:27 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_39.dll
    2017-08-29 21:27 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_39.dll
    2017-08-29 21:27 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_39.dll
    2017-08-29 21:27 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_39.dll
    2017-08-29 21:27 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_39.dll
    2017-08-29 21:27 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_39.dll
    2017-08-29 21:27 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_1.dll
    2017-08-29 21:27 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_1.dll
    2017-08-29 21:27 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_1.dll
    2017-08-29 21:27 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_1.dll
    2017-08-29 21:27 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_0.dll
    2017-08-29 21:27 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_0.dll
    2017-08-29 21:27 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_4.dll
    2017-08-29 21:27 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_4.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_38.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_38.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_38.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_38.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_38.dll
    2017-08-29 21:27 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_38.dll
    2017-08-29 21:27 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_0.dll
    2017-08-29 21:27 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_0.dll
    2017-08-29 21:27 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_0.dll
    2017-08-29 21:27 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\windows\system32\xactengine3_0.dll
    2017-08-29 21:27 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_3.dll
    2017-08-29 21:27 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_3.dll
    2017-08-29 21:27 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_37.dll
    2017-08-29 21:27 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_37.dll
    2017-08-29 21:27 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_37.dll
    2017-08-29 21:27 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_37.dll
    2017-08-29 21:27 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_37.dll
    2017-08-29 21:27 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_37.dll
    2017-08-29 21:27 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_10.dll
    2017-08-29 21:27 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_10.dll
    2017-08-29 21:27 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\windows\system32\X3DAudio1_2.dll
    2017-08-29 21:27 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_2.dll
    2017-08-29 21:27 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_36.dll
    2017-08-29 21:27 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_36.dll
    2017-08-29 21:27 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_36.dll
    2017-08-29 21:27 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_36.dll
    2017-08-29 21:27 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_36.dll
    2017-08-29 21:27 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_36.dll
    2017-08-29 21:27 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_9.dll
    2017-08-29 21:27 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_9.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_35.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_35.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_35.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_35.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_35.dll
    2017-08-29 21:27 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_35.dll
    2017-08-29 21:27 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_8.dll
    2017-08-29 21:27 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_8.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_34.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_34.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_34.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_34.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_34.dll
    2017-08-29 21:27 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_34.dll
    2017-08-29 21:27 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_7.dll
    2017-08-29 21:27 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_7.dll
    2017-08-29 21:27 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\windows\system32\xinput1_3.dll
    2017-08-29 21:27 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_3.dll
    2017-08-29 21:27 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_33.dll
    2017-08-29 21:27 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_33.dll
    2017-08-29 21:27 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_33.dll
    2017-08-29 21:27 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_33.dll
    2017-08-29 21:27 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_33.dll
    2017-08-29 21:27 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_33.dll
    2017-08-29 21:27 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_6.dll
    2017-08-29 21:27 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_6.dll
    2017-08-29 21:26 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_1.dll
    2017-08-29 21:26 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_1.dll
    2017-08-29 21:26 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_5.dll
    2017-08-29 21:26 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_5.dll
    2017-08-29 21:26 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_32.dll
    2017-08-29 21:26 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_32.dll
    2017-08-29 21:26 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\windows\system32\d3dx10.dll
    2017-08-29 21:26 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10.dll
    2017-08-29 21:26 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_31.dll
    2017-08-29 21:26 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_31.dll
    2017-08-29 21:26 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_4.dll
    2017-08-29 21:26 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_4.dll
    2017-08-29 21:26 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\windows\system32\xinput1_2.dll
    2017-08-29 21:26 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_3.dll
    2017-08-29 21:26 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_3.dll
    2017-08-29 21:26 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_2.dll
    2017-08-29 21:26 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_2.dll
    2017-08-29 21:26 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_2.dll
    2017-08-29 21:26 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_30.dll
    2017-08-29 21:26 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_30.dll
    2017-08-29 21:26 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_1.dll
    2017-08-29 21:26 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_1.dll
    2017-08-29 21:26 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\windows\system32\xinput1_1.dll
    2017-08-29 21:26 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_1.dll
    2017-08-29 21:26 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_29.dll
    2017-08-29 21:26 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_29.dll
    2017-08-29 21:26 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\windows\system32\xactengine2_0.dll
    2017-08-29 21:26 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine2_0.dll
    2017-08-29 21:26 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\windows\system32\x3daudio1_0.dll
    2017-08-29 21:26 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\windows\SysWOW64\x3daudio1_0.dll
    2017-08-29 21:26 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_28.dll
    2017-08-29 21:26 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_28.dll
    2017-08-29 21:26 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_27.dll
    2017-08-29 21:26 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_27.dll
    2017-08-29 21:26 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_26.dll
    2017-08-29 21:26 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_26.dll
    2017-08-29 21:26 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_25.dll
    2017-08-29 21:26 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_25.dll
    2017-08-29 21:26 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_24.dll
    2017-08-29 21:26 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_24.dll
    2017-08-29 20:01 - 2017-09-12 19:05 - 000000000 ____D C:\windows\system32\MRT
    2017-08-29 20:01 - 2017-09-12 19:03 - 138202976 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
    2017-08-29 19:59 - 2017-07-31 23:34 - 000349600 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
    2017-08-29 19:59 - 2017-07-31 23:31 - 000176024 _____ (Microsoft Corporation) C:\windows\SysWOW64\basecsp.dll
    2017-08-29 19:59 - 2017-07-31 23:12 - 000229888 _____ (Microsoft Corporation) C:\windows\SysWOW64\scksp.dll
    2017-08-29 19:59 - 2017-07-31 23:07 - 002671616 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
    2017-08-29 19:59 - 2017-07-31 23:06 - 000798208 _____ (Microsoft Corporation) C:\windows\SysWOW64\TokenBroker.dll
    2017-08-29 19:59 - 2017-07-31 22:30 - 003377664 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 001311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjet40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000866816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswdat10.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswstr10.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000616448 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrepl40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000518144 _____ C:\windows\SysWOW64\msjetoledb40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000475648 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxbde40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000375808 _____ (Microsoft Corporation) C:\windows\SysWOW64\mspbde40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000343552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrd3x40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000339968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msexcl40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000310272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrd2x40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000290816 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjtes40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstext40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000240640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msltus40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000144896 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjint40.dll
    2017-08-29 19:59 - 2017-07-31 19:45 - 000083968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjter40.dll
    2017-08-29 19:59 - 2017-07-28 02:07 - 000805816 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.dll
    2017-08-29 19:59 - 2017-07-28 01:38 - 004213656 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.StateRepository.dll
    2017-08-29 19:59 - 2017-07-28 01:36 - 005808640 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
    2017-08-29 19:59 - 2017-07-28 01:36 - 002424024 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
    2017-08-29 19:59 - 2017-07-28 01:36 - 001195760 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
    2017-08-29 19:59 - 2017-07-28 01:36 - 000864248 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
    2017-08-29 19:59 - 2017-07-28 01:35 - 000988168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
    2017-08-29 19:59 - 2017-07-28 01:16 - 001291776 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVPXENC.dll
    2017-08-29 19:59 - 2017-07-28 01:15 - 005721600 _____ (Microsoft Corporation) C:\windows\SysWOW64\BingMaps.dll
    2017-08-29 19:59 - 2017-07-28 01:14 - 000368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\InstallAgentUserBroker.exe
    2017-08-29 19:59 - 2017-07-28 01:12 - 000952832 _____ (Microsoft Corporation) C:\windows\SysWOW64\comdlg32.dll
    2017-08-29 19:59 - 2017-07-28 01:12 - 000337920 _____ (Microsoft Corporation) C:\windows\SysWOW64\InstallAgent.exe
    2017-08-29 19:59 - 2017-07-28 01:08 - 004417024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
    2017-08-29 19:59 - 2017-07-28 01:08 - 004056064 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
    2017-08-29 19:59 - 2017-07-28 01:07 - 002211840 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputService.dll
    2017-08-29 19:59 - 2017-07-28 01:05 - 001536512 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Immersive.dll
    2017-08-29 19:59 - 2017-07-28 01:05 - 000892928 _____ (Microsoft Corporation) C:\windows\SysWOW64\autochk.exe
    2017-08-29 19:59 - 2017-07-07 04:13 - 000336320 _____ (Microsoft Corporation) C:\windows\system32\SecurityHealthService.exe
    2017-08-29 19:59 - 2017-07-07 03:31 - 001518088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
    2017-08-29 19:59 - 2017-07-07 03:26 - 001529384 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmde.dll
    2017-08-29 19:59 - 2017-07-07 03:05 - 000312320 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
    2017-08-29 19:59 - 2017-07-07 03:04 - 000506368 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2017-08-29 19:59 - 2017-07-07 03:03 - 006123520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mos.dll
    2017-08-29 19:59 - 2017-07-07 03:00 - 002588160 _____ (Microsoft Corporation) C:\windows\SysWOW64\MapRouter.dll
    2017-08-29 19:59 - 2017-07-07 03:00 - 001565184 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
    2017-08-29 19:59 - 2017-07-07 02:59 - 001494016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActiveSyncProvider.dll
    2017-08-29 19:59 - 2017-07-07 02:58 - 002782720 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
    2017-08-29 19:59 - 2017-07-07 02:58 - 002298368 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
    2017-08-29 19:59 - 2017-07-07 02:58 - 001237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.Maps.dll
    2017-08-29 19:59 - 2017-07-07 02:55 - 000329216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SensorsApi.dll
    2017-08-29 19:59 - 2017-07-07 02:53 - 001301504 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdc.dll
    2017-08-29 19:59 - 2017-06-20 02:34 - 000192416 _____ (Microsoft Corporation) C:\windows\SysWOW64\aepic.dll
    2017-08-29 19:59 - 2017-06-20 02:15 - 000455104 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSAudDecMFT.dll
    2017-08-29 19:59 - 2017-06-20 02:06 - 000754592 _____ (Microsoft Corporation) C:\windows\SysWOW64\LicenseManager.dll
    2017-08-29 19:59 - 2017-06-20 02:05 - 000438096 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.dll
    2017-08-29 19:59 - 2017-06-20 02:04 - 001178528 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll
    2017-08-29 19:59 - 2017-06-20 02:04 - 001077496 _____ (Microsoft Corporation) C:\windows\SysWOW64\webservices.dll
    2017-08-29 19:59 - 2017-06-20 02:03 - 000443728 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll
    2017-08-29 19:59 - 2017-06-20 02:02 - 001121928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
    2017-08-29 19:59 - 2017-06-20 02:02 - 000354400 _____ (Microsoft Corporation) C:\windows\SysWOW64\MMDevAPI.dll
    2017-08-29 19:59 - 2017-06-20 02:00 - 002597888 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
    2017-08-29 19:59 - 2017-06-20 01:42 - 000387584 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Payments.dll
    2017-08-29 19:59 - 2017-06-20 01:41 - 000646656 _____ (Microsoft Corporation) C:\windows\SysWOW64\MbaeApi.dll
    2017-08-29 19:59 - 2017-06-20 01:41 - 000433152 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Internal.Bluetooth.dll
    2017-08-29 19:59 - 2017-06-20 01:39 - 000969728 _____ (Microsoft Corporation) C:\windows\SysWOW64\Unistore.dll
    2017-08-29 19:59 - 2017-06-20 01:38 - 001451008 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAutomationCore.dll
    2017-08-29 19:59 - 2017-06-20 01:38 - 001285120 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbghelp.dll
    2017-08-29 19:59 - 2017-06-20 01:35 - 002679296 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
    2017-08-29 19:59 - 2017-06-20 01:35 - 002132480 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
    2017-08-29 19:59 - 2017-06-20 01:34 - 002750464 _____ (Microsoft Corporation) C:\windows\SysWOW64\CertEnroll.dll
    2017-08-29 19:59 - 2017-06-20 01:34 - 001492480 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Bluetooth.dll
    2017-08-29 19:59 - 2017-06-03 06:59 - 000311200 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
    2017-08-29 19:59 - 2017-06-03 06:11 - 000038912 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
    2017-08-29 19:59 - 2017-06-03 06:09 - 000094720 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTimeUtil.dll
    2017-08-29 19:59 - 2017-06-03 06:05 - 000169984 _____ (Microsoft Corporation) C:\windows\SysWOW64\devicengccredprov.dll
    2017-08-29 19:59 - 2017-06-03 05:57 - 000797184 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
    2017-08-29 19:59 - 2017-06-03 05:54 - 002341376 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
    2017-08-29 19:58 - 2017-07-31 23:38 - 000406544 _____ (Microsoft Corporation) C:\windows\SysWOW64\policymanager.dll
    2017-08-29 19:58 - 2017-07-31 23:36 - 000119712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
    2017-08-29 19:58 - 2017-07-31 23:35 - 000133904 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFaultSecure.exe
    2017-08-29 19:58 - 2017-07-31 23:17 - 000034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\tokenbinding.dll
    2017-08-29 19:58 - 2017-07-31 23:14 - 000035840 _____ (Microsoft Corporation) C:\windows\SysWOW64\sscore.dll
    2017-08-29 19:58 - 2017-07-31 23:13 - 000127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdeploy.dll
    2017-08-29 19:58 - 2017-07-31 23:09 - 000394240 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Internal.Management.dll
    2017-08-29 19:58 - 2017-07-31 23:08 - 000267264 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncryptprov.dll
    2017-08-29 19:58 - 2017-07-28 02:23 - 000723360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\acpi.sys
    2017-08-29 19:58 - 2017-07-28 02:20 - 000279968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
    2017-08-29 19:58 - 2017-07-28 02:15 - 000554400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
    2017-08-29 19:58 - 2017-07-28 01:48 - 000096648 _____ (Microsoft Corporation) C:\windows\SysWOW64\dmcmnutils.dll
    2017-08-29 19:58 - 2017-07-28 01:40 - 000551200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
    2017-08-29 19:58 - 2017-07-28 01:36 - 000866808 _____ (Microsoft Corporation) C:\windows\SysWOW64\DolbyDecMFT.dll
    2017-08-29 19:58 - 2017-07-28 01:36 - 000173104 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsensorgroup.dll
    2017-08-29 19:58 - 2017-07-28 01:36 - 000090464 _____ (Microsoft Corporation) C:\windows\SysWOW64\msacm32.dll
    2017-08-29 19:58 - 2017-07-28 01:35 - 000277432 _____ (Microsoft Corporation) C:\windows\SysWOW64\shlwapi.dll
    2017-08-29 19:58 - 2017-07-28 01:33 - 000967584 _____ (Microsoft Corporation) C:\windows\SysWOW64\ReAgent.dll
    2017-08-29 19:58 - 2017-07-28 01:33 - 000414296 _____ (Microsoft Corporation) C:\windows\SysWOW64\TextInputFramework.dll
    2017-08-29 19:58 - 2017-07-28 01:27 - 000051712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\UcmUcsi.sys
    2017-08-29 19:58 - 2017-07-28 01:26 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\cmintegrator.dll
    2017-08-29 19:58 - 2017-07-28 01:24 - 000184832 _____ (Microsoft Corporation) C:\windows\system32\VCardParser.dll
    2017-08-29 19:58 - 2017-07-28 01:21 - 000029184 _____ (Microsoft Corporation) C:\windows\SysWOW64\cmintegrator.dll
    2017-08-29 19:58 - 2017-07-28 01:20 - 000018432 _____ (Microsoft Corporation) C:\windows\SysWOW64\IpNatHlpClient.dll
    2017-08-29 19:58 - 2017-07-28 01:19 - 000942592 _____ (Microsoft Corporation) C:\windows\system32\wbiosrvc.dll
    2017-08-29 19:58 - 2017-07-28 01:19 - 000417792 _____ (Microsoft Corporation) C:\windows\system32\InstallAgentUserBroker.exe
    2017-08-29 19:58 - 2017-07-28 01:19 - 000147456 _____ (Microsoft Corporation) C:\windows\SysWOW64\VCardParser.dll
    2017-08-29 19:58 - 2017-07-28 01:19 - 000117760 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
    2017-08-29 19:58 - 2017-07-28 01:18 - 000139776 _____ (Microsoft Corporation) C:\windows\SysWOW64\BluetoothApis.dll
    2017-08-29 19:58 - 2017-07-28 01:16 - 000383488 _____ (Microsoft Corporation) C:\windows\system32\InstallAgent.exe
    2017-08-29 19:58 - 2017-07-28 01:16 - 000135680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qasf.dll
    2017-08-29 19:58 - 2017-07-28 01:15 - 000586752 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2017-08-29 19:58 - 2017-07-28 01:14 - 000331264 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastlsext.dll
    2017-08-29 19:58 - 2017-07-28 01:13 - 000932352 _____ (Microsoft Corporation) C:\windows\SysWOW64\GamePanel.exe
    2017-08-29 19:58 - 2017-07-28 01:12 - 000446464 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
    2017-08-29 19:58 - 2017-07-28 01:10 - 000564224 _____ (Microsoft Corporation) C:\windows\SysWOW64\shsvcs.dll
    2017-08-29 19:58 - 2017-07-28 01:08 - 000097792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthhfenum.sys
    2017-08-29 19:58 - 2017-07-28 01:05 - 000538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\untfs.dll
    2017-08-29 19:58 - 2017-07-28 01:02 - 000877056 _____ (Microsoft Corporation) C:\windows\SysWOW64\autoconv.exe
    2017-08-29 19:58 - 2017-07-28 01:02 - 000853504 _____ (Microsoft Corporation) C:\windows\SysWOW64\autofmt.exe
    2017-08-29 19:58 - 2017-07-28 01:02 - 000077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\spbcd.dll
    2017-08-29 19:58 - 2017-07-07 04:20 - 002021680 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll
    2017-08-29 19:58 - 2017-07-07 04:10 - 001670496 _____ (Microsoft Corporation) C:\windows\system32\winmde.dll
    2017-08-29 19:58 - 2017-07-07 03:57 - 000125344 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
    2017-08-29 19:58 - 2017-07-07 03:37 - 001339352 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmpmde.dll
    2017-08-29 19:58 - 2017-07-07 03:31 - 000129184 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
    2017-08-29 19:58 - 2017-07-07 03:30 - 000949920 _____ (Microsoft Corporation) C:\windows\SysWOW64\dcomp.dll
    2017-08-29 19:58 - 2017-07-07 03:29 - 000123520 _____ (Microsoft Corporation) C:\windows\SysWOW64\Clipc.dll
    2017-08-29 19:58 - 2017-07-07 03:25 - 000035232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininitext.dll
    2017-08-29 19:58 - 2017-07-07 03:18 - 000548864 _____ (Microsoft Corporation) C:\windows\system32\SensorService.dll
    2017-08-29 19:58 - 2017-07-07 03:14 - 003784704 _____ (Microsoft Corporation) C:\windows\system32\MapRouter.dll
    2017-08-29 19:58 - 2017-07-07 03:10 - 000025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\eapprovp.dll
    2017-08-29 19:58 - 2017-07-07 03:08 - 000285696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
    2017-08-29 19:58 - 2017-07-07 03:07 - 000117248 _____ (Microsoft Corporation) C:\windows\SysWOW64\raschap.dll
    2017-08-29 19:58 - 2017-07-07 03:06 - 000241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsExt.dll
    2017-08-29 19:58 - 2017-07-07 03:05 - 000502784 _____ (Microsoft Corporation) C:\windows\SysWOW64\DevicePairing.dll
    2017-08-29 19:58 - 2017-07-07 02:55 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
    2017-08-29 19:58 - 2017-07-07 02:53 - 000338432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msinfo32.exe
    2017-08-29 19:58 - 2017-06-20 03:02 - 001055648 _____ (Microsoft Corporation) C:\windows\system32\LicenseManager.dll
    2017-08-29 19:58 - 2017-06-20 02:59 - 001220072 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
    2017-08-29 19:58 - 2017-06-20 02:13 - 000787712 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
    2017-08-29 19:58 - 2017-06-20 02:13 - 000056832 _____ (Microsoft Corporation) C:\windows\system32\WinBioDataModelOOBE.exe
    2017-08-29 19:58 - 2017-06-20 02:12 - 000293376 _____ (Microsoft Corporation) C:\windows\system32\MusNotification.exe
    2017-08-29 19:58 - 2017-06-20 02:12 - 000264192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
    2017-08-29 19:58 - 2017-06-20 02:12 - 000086528 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys
    2017-08-29 19:58 - 2017-06-20 02:10 - 000722432 _____ (Microsoft Corporation) C:\windows\system32\MusUpdateHandlers.dll
    2017-08-29 19:58 - 2017-06-20 02:07 - 000632832 _____ (Microsoft Corporation) C:\windows\system32\tileobjserver.dll
    2017-08-29 19:58 - 2017-06-20 02:07 - 000510976 _____ (Microsoft Corporation) C:\windows\system32\TDLMigration.dll
    2017-08-29 19:58 - 2017-06-20 02:07 - 000346016 _____ (Microsoft Corporation) C:\windows\SysWOW64\CloudExperienceHostCommon.dll
    2017-08-29 19:58 - 2017-06-20 02:07 - 000138656 _____ (Microsoft Corporation) C:\windows\SysWOW64\CloudExperienceHostUser.dll
    2017-08-29 19:58 - 2017-06-20 02:06 - 000278944 _____ (Microsoft Corporation) C:\windows\SysWOW64\thumbcache.dll
    2017-08-29 19:58 - 2017-06-20 02:05 - 000364032 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
    2017-08-29 19:58 - 2017-06-20 02:04 - 001177600 _____ (Microsoft Corporation) C:\windows\system32\Unistore.dll
    2017-08-29 19:58 - 2017-06-20 02:04 - 000049656 _____ (Microsoft Corporation) C:\windows\SysWOW64\msasn1.dll
    2017-08-29 19:58 - 2017-06-20 01:56 - 000985600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
    2017-08-29 19:58 - 2017-06-20 01:49 - 000899072 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctfuimanager.dll
    2017-08-29 19:58 - 2017-06-20 01:49 - 000331776 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleacc.dll
    2017-08-29 19:58 - 2017-06-20 01:46 - 000132096 _____ (Microsoft Corporation) C:\windows\SysWOW64\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
    2017-08-29 19:58 - 2017-06-20 01:45 - 000111104 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.System.Profile.RetailInfo.dll
    2017-08-29 19:58 - 2017-06-20 01:43 - 000329728 _____ (Microsoft Corporation) C:\windows\SysWOW64\webplatstorageserver.dll
    2017-08-29 19:58 - 2017-06-20 01:43 - 000173568 _____ (Microsoft Corporation) C:\windows\SysWOW64\ClipboardServer.dll
    2017-08-29 19:58 - 2017-06-20 01:43 - 000151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredui.dll
    2017-08-29 19:58 - 2017-06-20 01:43 - 000052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\dataclen.dll
    2017-08-29 19:58 - 2017-06-20 01:42 - 000641024 _____ (Microsoft Corporation) C:\windows\SysWOW64\certca.dll
    2017-08-29 19:58 - 2017-06-20 01:42 - 000121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\sendmail.dll
    2017-08-29 19:58 - 2017-06-20 01:41 - 000734208 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcastdvr.exe
    2017-08-29 19:58 - 2017-06-20 01:41 - 000601088 _____ (Microsoft Corporation) C:\windows\SysWOW64\SndVolSSO.dll
    2017-08-29 19:58 - 2017-06-20 01:41 - 000201216 _____ (Microsoft Corporation) C:\windows\SysWOW64\credprovhost.dll
    2017-08-29 19:58 - 2017-06-20 01:40 - 000342016 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
    2017-08-29 19:58 - 2017-06-20 01:40 - 000247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\AboveLockAppHost.dll
    2017-08-29 19:58 - 2017-06-20 01:40 - 000230912 _____ (Microsoft Corporation) C:\windows\SysWOW64\edputil.dll
    2017-08-29 19:58 - 2017-06-20 01:40 - 000038400 _____ (Microsoft Corporation) C:\windows\SysWOW64\TokenBrokerUI.dll
    2017-08-29 19:58 - 2017-06-20 01:39 - 002814464 _____ (Microsoft Corporation) C:\windows\SysWOW64\themeui.dll
    2017-08-29 19:58 - 2017-06-20 01:39 - 000646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\mmsys.cpl
    2017-08-29 19:58 - 2017-06-20 01:39 - 000471040 _____ (Microsoft Corporation) C:\windows\SysWOW64\VAN.dll
    2017-08-29 19:58 - 2017-06-20 01:39 - 000312320 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
    2017-08-29 19:58 - 2017-06-20 01:38 - 001171968 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
    2017-08-29 19:58 - 2017-06-20 01:38 - 000648192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SmartcardCredentialProvider.dll
    2017-08-29 19:58 - 2017-06-20 01:31 - 000334848 _____ (Microsoft Corporation) C:\windows\SysWOW64\PlayToDevice.dll
    2017-08-29 19:58 - 2017-06-20 01:30 - 000209920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdmaud.drv
    2017-08-29 19:58 - 2017-06-20 01:30 - 000157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
    2017-08-29 19:58 - 2017-06-20 01:28 - 000584192 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
    2017-08-29 19:58 - 2017-06-03 07:09 - 001003624 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
    2017-08-29 19:58 - 2017-06-03 07:00 - 000219040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tpm.sys
    2017-08-29 19:58 - 2017-06-03 06:59 - 000259400 _____ (Microsoft Corporation) C:\windows\system32\MusNotifyIcon.exe
    2017-08-29 19:58 - 2017-06-03 06:26 - 000266640 _____ (Microsoft Corporation) C:\windows\SysWOW64\capauthz.dll
    2017-08-29 19:58 - 2017-06-03 06:23 - 000573856 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
    2017-08-29 19:58 - 2017-06-03 06:14 - 000099328 _____ (Microsoft Corporation) C:\windows\system32\utcutil.dll
    2017-08-29 19:58 - 2017-06-03 06:12 - 000119296 _____ (Microsoft Corporation) C:\windows\system32\UserDataTimeUtil.dll
    2017-08-29 19:58 - 2017-06-03 06:11 - 000052736 _____ (Microsoft Corporation) C:\windows\system32\musdialoghandlers.dll
    2017-08-29 19:58 - 2017-06-03 06:11 - 000035840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\BasicRender.sys
    2017-08-29 19:58 - 2017-06-03 06:10 - 000102400 _____ (Microsoft Corporation) C:\windows\system32\MusNotificationUx.exe
    2017-08-29 19:58 - 2017-06-03 06:09 - 000271872 _____ (Microsoft Corporation) C:\windows\system32\Windows.Security.Authentication.Identity.Provider.dll
    2017-08-29 19:58 - 2017-06-03 06:09 - 000221184 _____ (Microsoft Corporation) C:\windows\system32\devicengccredprov.dll
    2017-08-29 19:58 - 2017-06-03 06:07 - 000002560 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
    2017-08-29 19:58 - 2017-06-03 06:05 - 000198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
    2017-08-29 19:58 - 2017-06-03 06:00 - 000933376 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
    2017-08-29 19:58 - 2017-06-03 05:57 - 006535168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mspaint.exe
    2017-08-29 19:57 - 2017-07-31 23:16 - 000080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakradiag.dll
    2017-08-29 19:57 - 2017-07-31 22:41 - 000110592 _____ (Microsoft Corporation) C:\windows\system32\Chakradiag.dll
    2017-08-29 19:57 - 2017-07-31 22:35 - 000692736 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2017-08-29 19:57 - 2017-07-28 02:15 - 005302968 _____ (Microsoft Corporation) C:\windows\system32\Windows.StateRepository.dll
    2017-08-29 19:57 - 2017-07-28 02:13 - 006557520 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
    2017-08-29 19:57 - 2017-07-28 02:13 - 002604248 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
    2017-08-29 19:57 - 2017-07-28 02:12 - 001325968 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
    2017-08-29 19:57 - 2017-07-28 02:09 - 000529992 _____ (Microsoft Corporation) C:\windows\system32\TextInputFramework.dll
    2017-08-29 19:57 - 2017-07-28 01:25 - 000115712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bridge.sys
    2017-08-29 19:57 - 2017-07-28 01:21 - 008333312 _____ (Microsoft Corporation) C:\windows\system32\BingMaps.dll
    2017-08-29 19:57 - 2017-07-28 01:19 - 000847360 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
    2017-08-29 19:57 - 2017-07-28 01:19 - 000370688 _____ (Microsoft Corporation) C:\windows\system32\rastlsext.dll
    2017-08-29 19:57 - 2017-07-28 01:18 - 000586240 _____ (Microsoft Corporation) C:\windows\system32\AppReadiness.dll
    2017-08-29 19:57 - 2017-07-28 01:13 - 004535296 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
    2017-08-29 19:57 - 2017-07-28 01:12 - 002939392 _____ (Microsoft Corporation) C:\windows\system32\InputService.dll
    2017-08-29 19:57 - 2017-07-28 01:06 - 001833984 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll
    2017-08-29 19:57 - 2017-07-07 04:26 - 001065104 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
    2017-08-29 19:57 - 2017-07-07 04:24 - 000117664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pdc.sys
    2017-08-29 19:57 - 2017-07-07 04:21 - 032688336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsRaw.dll
    2017-08-29 19:57 - 2017-07-07 04:14 - 001760264 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
    2017-08-29 19:57 - 2017-07-07 04:07 - 001106848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
    2017-08-29 19:57 - 2017-07-07 04:07 - 000058488 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
    2017-08-29 19:57 - 2017-07-07 03:37 - 031652264 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecsRaw.dll
    2017-08-29 19:57 - 2017-07-07 03:27 - 000557568 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2017-08-29 19:57 - 2017-07-07 03:27 - 000360960 _____ (Microsoft Corporation) C:\windows\system32\ConhostV2.dll
    2017-08-29 19:57 - 2017-07-07 03:20 - 000175616 _____ (Microsoft Corporation) C:\windows\system32\prntvpt.dll
    2017-08-29 19:57 - 2017-07-07 03:19 - 007149056 _____ (Microsoft Corporation) C:\windows\system32\mos.dll
    2017-08-29 19:57 - 2017-07-07 03:17 - 000588800 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2017-08-29 19:57 - 2017-07-07 03:14 - 000570880 _____ (Microsoft Corporation) C:\windows\system32\PhotoScreensaver.scr
    2017-08-29 19:57 - 2017-07-07 03:13 - 005892096 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
    2017-08-29 19:57 - 2017-07-07 03:11 - 002829824 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
    2017-08-29 19:57 - 2017-07-07 03:11 - 001888256 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
    2017-08-29 19:57 - 2017-07-07 03:07 - 000272896 _____ (Microsoft Corporation) C:\windows\system32\PlayToReceiver.dll
    2017-08-29 19:57 - 2017-07-07 03:06 - 000412160 _____ (Microsoft Corporation) C:\windows\system32\SensorsApi.dll
    2017-08-29 19:57 - 2017-07-07 03:06 - 000205824 _____ (Microsoft Corporation) C:\windows\system32\sensrsvc.dll
    2017-08-29 19:57 - 2017-07-07 03:02 - 000508416 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoScreensaver.scr
    2017-08-29 19:57 - 2017-06-20 03:11 - 001395152 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
    2017-08-29 19:57 - 2017-06-20 03:11 - 000411992 _____ (Microsoft Corporation) C:\windows\system32\MSAudDecMFT.dll
    2017-08-29 19:57 - 2017-06-20 03:00 - 000142752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wcifs.sys
    2017-08-29 19:57 - 2017-06-20 02:59 - 000467504 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll
    2017-08-29 19:57 - 2017-06-20 02:14 - 001150784 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
    2017-08-29 19:57 - 2017-06-20 02:09 - 000551424 _____ (Microsoft Corporation) C:\windows\system32\Windows.Payments.dll
    2017-08-29 19:57 - 2017-06-20 02:08 - 000328704 _____ (Microsoft Corporation) C:\windows\system32\PsmServiceExtHost.dll
    2017-08-29 19:57 - 2017-06-20 02:07 - 000823296 _____ (Microsoft Corporation) C:\windows\system32\MbaeApi.dll
    2017-08-29 19:57 - 2017-06-20 02:07 - 000626176 _____ (Microsoft Corporation) C:\windows\system32\Windows.Internal.Bluetooth.dll
    2017-08-29 19:57 - 2017-06-20 02:00 - 002171392 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Bluetooth.dll
    2017-08-29 19:57 - 2017-06-20 01:59 - 001674240 _____ (Microsoft Corporation) C:\windows\system32\wpncore.dll
    2017-08-29 19:56 - 2017-07-31 23:38 - 000382368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\clfs.sys
    2017-08-29 19:56 - 2017-07-31 23:32 - 000712600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms2.sys
    2017-08-29 19:56 - 2017-07-31 23:30 - 000411040 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
    2017-08-29 19:56 - 2017-07-31 23:30 - 000143736 _____ (Microsoft Corporation) C:\windows\system32\WerFaultSecure.exe
    2017-08-29 19:56 - 2017-07-31 22:33 - 001269760 _____ (Microsoft Corporation) C:\windows\system32\enterprisecsps.dll
    2017-08-29 19:56 - 2017-07-31 22:31 - 004445696 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_nt.dll
    2017-08-29 19:56 - 2017-07-31 22:30 - 001052160 _____ (Microsoft Corporation) C:\windows\system32\TokenBroker.dll
    2017-08-29 19:56 - 2017-07-28 02:30 - 001068720 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.dll
    2017-08-29 19:56 - 2017-07-28 02:24 - 002327456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
    2017-08-29 19:56 - 2017-07-28 02:24 - 000455584 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
    2017-08-29 19:56 - 2017-07-28 02:24 - 000116280 _____ (Microsoft Corporation) C:\windows\system32\bcd.dll
    2017-08-29 19:56 - 2017-07-28 02:17 - 000660680 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
    2017-08-29 19:56 - 2017-07-28 02:16 - 000961952 _____ (Microsoft Corporation) C:\windows\system32\efscore.dll
    2017-08-29 19:56 - 2017-07-28 02:13 - 001033544 _____ (Microsoft Corporation) C:\windows\system32\DolbyDecMFT.dll
    2017-08-29 19:56 - 2017-07-28 02:09 - 000527976 _____ (Microsoft Corporation) C:\windows\system32\services.exe
    2017-08-29 19:56 - 2017-07-28 01:48 - 000100232 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcd.dll
    2017-08-29 19:56 - 2017-07-28 01:24 - 000136192 _____ (Microsoft Corporation) C:\windows\system32\Windows.StateRepositoryUpgrade.dll
    2017-08-29 19:56 - 2017-07-28 01:22 - 000209408 _____ (Microsoft Corporation) C:\windows\system32\psmsrv.dll
    2017-08-29 19:56 - 2017-07-28 01:22 - 000197120 _____ (Microsoft Corporation) C:\windows\system32\bcdboot.exe
    2017-08-29 19:56 - 2017-07-28 01:21 - 000699904 _____ (Microsoft Corporation) C:\windows\system32\FlightSettings.dll
    2017-08-29 19:56 - 2017-07-28 01:20 - 000982016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
    2017-08-29 19:56 - 2017-07-28 01:20 - 000524800 _____ (Microsoft Corporation) C:\windows\system32\TileDataRepository.dll
    2017-08-29 19:56 - 2017-07-28 01:19 - 000687616 _____ (Microsoft Corporation) C:\windows\system32\LogonController.dll
    2017-08-29 19:56 - 2017-07-28 01:18 - 001468416 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.desktop.dll
    2017-08-29 19:56 - 2017-07-28 01:16 - 001046016 _____ (Microsoft Corporation) C:\windows\system32\comdlg32.dll
    2017-08-29 19:56 - 2017-07-28 01:15 - 003204608 _____ (Microsoft Corporation) C:\windows\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
    2017-08-29 19:56 - 2017-07-28 01:14 - 001305088 _____ (Microsoft Corporation) C:\windows\system32\dosvc.dll
    2017-08-29 19:56 - 2017-07-28 01:12 - 004707840 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
    2017-08-29 19:56 - 2017-07-28 01:11 - 001357312 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
    2017-08-29 19:56 - 2017-07-28 01:10 - 001706496 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Immersive.dll
    2017-08-29 19:56 - 2017-07-28 01:10 - 000625152 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
    2017-08-29 19:56 - 2017-07-28 01:07 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\MDMAppInstaller.exe
    2017-08-29 19:56 - 2017-07-28 01:07 - 000105472 _____ (Microsoft Corporation) C:\windows\system32\RjvMDMConfig.dll
    2017-08-29 19:56 - 2017-07-28 01:07 - 000074240 _____ (Microsoft Corporation) C:\windows\system32\EnterpriseDesktopAppMgmtCSP.dll
    2017-08-29 19:56 - 2017-07-28 01:07 - 000059392 _____ (Microsoft Corporation) C:\windows\system32\DmApiSetExtImplDesktop.dll
    2017-08-29 19:56 - 2017-07-28 01:05 - 001087488 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll
    2017-08-29 19:56 - 2017-07-07 11:00 - 000947712 _____ (Microsoft Corporation) C:\windows\system32\HoloSI.PCShell.dll
    2017-08-29 19:56 - 2017-07-07 04:25 - 000899824 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
    2017-08-29 19:56 - 2017-07-07 04:22 - 001186464 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
    2017-08-29 19:56 - 2017-07-07 03:19 - 000256000 _____ (Microsoft Corporation) C:\windows\system32\domgmt.dll
    2017-08-29 19:56 - 2017-07-07 03:18 - 000274944 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
    2017-08-29 19:56 - 2017-07-07 03:13 - 000840192 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll
    2017-08-29 19:56 - 2017-07-07 03:12 - 001713664 _____ (Microsoft Corporation) C:\windows\system32\ActiveSyncProvider.dll
    2017-08-29 19:56 - 2017-07-07 03:12 - 001420800 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.Maps.dll
    2017-08-29 19:56 - 2017-07-07 03:11 - 003139584 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
    2017-08-29 19:56 - 2017-07-07 03:11 - 002649600 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
    2017-08-29 19:56 - 2017-07-07 03:11 - 001812480 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
    2017-08-29 19:56 - 2017-07-07 03:04 - 000058368 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
    2017-08-29 19:56 - 2017-06-20 03:18 - 001564576 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
    2017-08-29 19:56 - 2017-06-20 03:16 - 001214880 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
    2017-08-29 19:56 - 2017-06-20 02:58 - 000406072 _____ (Microsoft Corporation) C:\windows\system32\MMDevAPI.dll
    2017-08-29 19:56 - 2017-06-20 02:10 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\SettingsEnvironment.Desktop.dll
    2017-08-29 19:56 - 2017-06-20 02:09 - 000427008 _____ (Microsoft Corporation) C:\windows\system32\provengine.dll
    2017-08-29 19:56 - 2017-06-20 02:09 - 000357888 _____ (Microsoft Corporation) C:\windows\system32\Narrator.exe
    2017-08-29 19:56 - 2017-06-20 02:08 - 000646656 _____ (Microsoft Corporation) C:\windows\system32\LockHostingFramework.dll
    2017-08-29 19:56 - 2017-06-20 02:07 - 000411136 _____ (Microsoft Corporation) C:\windows\system32\updatehandlers.dll
    2017-08-29 19:56 - 2017-06-20 02:06 - 000299520 _____ (Microsoft Corporation) C:\windows\system32\AboveLockAppHost.dll
    2017-08-29 19:56 - 2017-06-20 02:05 - 000406528 _____ (Microsoft Corporation) C:\windows\system32\InputSwitch.dll
    2017-08-29 19:56 - 2017-06-20 02:04 - 001818624 _____ (Microsoft Corporation) C:\windows\system32\UIAutomationCore.dll
    2017-08-29 19:56 - 2017-06-20 02:02 - 000681984 _____ (Microsoft Corporation) C:\windows\system32\usocore.dll
    2017-08-29 19:56 - 2017-06-20 02:01 - 003803136 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsThresholdAdminFlowUI.dll
    2017-08-29 19:56 - 2017-06-20 02:01 - 003332096 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
    2017-08-29 19:56 - 2017-06-20 02:00 - 003057664 _____ (Microsoft Corporation) C:\windows\system32\CertEnroll.dll
    2017-08-29 19:56 - 2017-06-03 07:15 - 000382368 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
    2017-08-29 19:56 - 2017-06-03 07:10 - 000130464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tm.sys
    2017-08-29 19:56 - 2017-06-03 06:14 - 000047104 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
    2017-08-29 19:56 - 2017-06-03 05:59 - 002625024 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll
    2017-08-29 19:56 - 2017-06-03 05:59 - 000975360 _____ (Microsoft Corporation) C:\windows\HelpPane.exe
    2017-08-29 19:56 - 2017-06-03 05:51 - 000064512 _____ (Microsoft Corporation) C:\windows\bfsvc.exe
    2017-08-29 19:55 - 2017-07-31 23:33 - 000473240 _____ (Microsoft Corporation) C:\windows\system32\policymanager.dll
    2017-08-29 19:55 - 2017-07-31 23:30 - 000082336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vmbkmcl.sys
    2017-08-29 19:55 - 2017-07-31 23:26 - 000204192 _____ (Microsoft Corporation) C:\windows\system32\basecsp.dll
    2017-08-29 19:55 - 2017-07-31 22:44 - 000083968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vmbkmclr.sys
    2017-08-29 19:55 - 2017-07-31 22:41 - 000180736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rfcomm.sys
    2017-08-29 19:55 - 2017-07-31 22:41 - 000130560 _____ (Microsoft Corporation) C:\windows\system32\policymanagerprecheck.dll
    2017-08-29 19:55 - 2017-07-31 22:41 - 000042496 _____ (Microsoft Corporation) C:\windows\system32\tokenbinding.dll
    2017-08-29 19:55 - 2017-07-31 22:40 - 000290816 _____ (Microsoft Corporation) C:\windows\system32\dmenterprisediagnostics.dll
    2017-08-29 19:55 - 2017-07-31 22:39 - 000046592 _____ (Microsoft Corporation) C:\windows\system32\sscore.dll
    2017-08-29 19:55 - 2017-07-31 22:38 - 000153088 _____ (Microsoft Corporation) C:\windows\system32\fdeploy.dll
    2017-08-29 19:55 - 2017-07-31 22:38 - 000143872 _____ (Microsoft Corporation) C:\windows\system32\profsvcext.dll
    2017-08-29 19:55 - 2017-07-31 22:37 - 000582656 _____ (Microsoft Corporation) C:\windows\system32\SmsRouterSvc.dll
    2017-08-29 19:55 - 2017-07-31 22:37 - 000255488 _____ (Microsoft Corporation) C:\windows\system32\scksp.dll
    2017-08-29 19:55 - 2017-07-31 22:33 - 000315904 _____ (Microsoft Corporation) C:\windows\system32\ncryptprov.dll
    2017-08-29 19:55 - 2017-07-31 22:30 - 000303104 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll
    2017-08-29 19:55 - 2017-07-31 22:27 - 000574464 _____ (Microsoft Corporation) C:\windows\system32\configmanager2.dll
    2017-08-29 19:55 - 2017-07-31 22:27 - 000482816 _____ (Microsoft Corporation) C:\windows\system32\dmenrollengine.dll
    2017-08-29 19:55 - 2017-07-31 22:26 - 000323584 _____ (Microsoft Corporation) C:\windows\system32\DeviceEnroller.exe
    2017-08-29 19:55 - 2017-07-31 22:25 - 000249344 _____ (Microsoft Corporation) C:\windows\system32\coredpus.dll
    2017-08-29 19:55 - 2017-07-31 22:25 - 000194048 _____ (Microsoft Corporation) C:\windows\system32\mdmregistration.dll
    2017-08-29 19:55 - 2017-07-31 22:25 - 000140800 _____ (Microsoft Corporation) C:\windows\system32\dmcsps.dll
    2017-08-29 19:55 - 2017-07-28 02:24 - 000119904 _____ (Microsoft Corporation) C:\windows\system32\dmcmnutils.dll
    2017-08-29 19:55 - 2017-07-28 02:14 - 000318232 _____ (Microsoft Corporation) C:\windows\system32\wininit.exe
    2017-08-29 19:55 - 2017-07-28 02:13 - 001054280 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
    2017-08-29 19:55 - 2017-07-28 02:13 - 000192264 _____ (Microsoft Corporation) C:\windows\system32\mfsensorgroup.dll
    2017-08-29 19:55 - 2017-07-28 02:13 - 000104432 _____ (Microsoft Corporation) C:\windows\system32\msacm32.dll
    2017-08-29 19:55 - 2017-07-28 02:12 - 001337856 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
    2017-08-29 19:55 - 2017-07-28 02:12 - 000323936 _____ (Microsoft Corporation) C:\windows\system32\shlwapi.dll
    2017-08-29 19:55 - 2017-07-28 02:10 - 001114528 _____ (Microsoft Corporation) C:\windows\system32\ReAgent.dll
    2017-08-29 19:55 - 2017-07-28 01:31 - 003995136 _____ (Microsoft Corporation) C:\windows\system32\UIRibbon.dll
    2017-08-29 19:55 - 2017-07-28 01:30 - 001722880 _____ (Microsoft Corporation) C:\windows\system32\dui70.dll
    2017-08-29 19:55 - 2017-07-28 01:29 - 000142848 _____ (Microsoft Corporation) C:\windows\system32\dwmredir.dll
    2017-08-29 19:55 - 2017-07-28 01:26 - 000102912 _____ (Microsoft Corporation) C:\windows\system32\officecsp.dll
    2017-08-29 19:55 - 2017-07-28 01:26 - 000090112 _____ (Microsoft Corporation) C:\windows\system32\ofdeploy.exe
    2017-08-29 19:55 - 2017-07-28 01:26 - 000022528 _____ (Microsoft Corporation) C:\windows\system32\IpNatHlpClient.dll
    2017-08-29 19:55 - 2017-07-28 01:25 - 003464704 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIRibbon.dll
    2017-08-29 19:55 - 2017-07-28 01:25 - 000231936 _____ (Microsoft Corporation) C:\windows\system32\DolbyMATEnc.dll
    2017-08-29 19:55 - 2017-07-28 01:25 - 000105472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthenum.sys
    2017-08-29 19:55 - 2017-07-28 01:25 - 000097280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
    2017-08-29 19:55 - 2017-07-28 01:23 - 000778240 _____ (Microsoft Corporation) C:\windows\system32\DolbyHrtfEnc.dll
    2017-08-29 19:55 - 2017-07-28 01:23 - 000189440 _____ (Microsoft Corporation) C:\windows\system32\BluetoothApis.dll
    2017-08-29 19:55 - 2017-07-28 01:22 - 000778240 _____ C:\windows\system32\MBR2GPT.EXE
    2017-08-29 19:55 - 2017-07-28 01:22 - 000500224 _____ (Microsoft Corporation) C:\windows\system32\Windows.Shell.BlueLightReduction.dll
    2017-08-29 19:55 - 2017-07-28 01:22 - 000491520 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_Display.dll
    2017-08-29 19:55 - 2017-07-28 01:22 - 000259072 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_Flights.dll
    2017-08-29 19:55 - 2017-07-28 01:21 - 000365056 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_Notifications.dll
    2017-08-29 19:55 - 2017-07-28 01:21 - 000150528 _____ (Microsoft Corporation) C:\windows\system32\qasf.dll
    2017-08-29 19:55 - 2017-07-28 01:20 - 001015296 _____ (Microsoft Corporation) C:\windows\system32\XblAuthManager.dll
    2017-08-29 19:55 - 2017-07-28 01:19 - 000817664 _____ (Microsoft Corporation) C:\windows\system32\Windows.Security.Authentication.Web.Core.dll
    2017-08-29 19:55 - 2017-07-28 01:19 - 000566784 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.UX.EapRequestHandler.dll
    2017-08-29 19:55 - 2017-07-28 01:18 - 001298432 _____ (Microsoft Corporation) C:\windows\system32\lpasvc.dll
    2017-08-29 19:55 - 2017-07-28 01:18 - 000536064 _____ (Microsoft Corporation) C:\windows\system32\Windows.Internal.Management.dll
    2017-08-29 19:55 - 2017-07-28 01:17 - 000497152 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
    2017-08-29 19:55 - 2017-07-28 01:17 - 000420864 _____ (Microsoft Corporation) C:\windows\system32\facecredentialprovider.dll
    2017-08-29 19:55 - 2017-07-28 01:15 - 000612864 _____ (Microsoft Corporation) C:\windows\system32\shsvcs.dll
    2017-08-29 19:55 - 2017-07-28 01:13 - 000972288 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
    2017-08-29 19:55 - 2017-07-28 01:09 - 000971264 _____ (Microsoft Corporation) C:\windows\system32\autochk.exe
    2017-08-29 19:55 - 2017-07-28 01:09 - 000579072 _____ (Microsoft Corporation) C:\windows\system32\untfs.dll
    2017-08-29 19:55 - 2017-07-28 01:08 - 000600576 _____ (Microsoft Corporation) C:\windows\system32\FrameServer.dll
    2017-08-29 19:55 - 2017-07-28 01:06 - 000593408 _____ (Microsoft Corporation) C:\windows\system32\BootMenuUX.dll
    2017-08-29 19:55 - 2017-07-28 01:06 - 000093696 _____ (Microsoft Corporation) C:\windows\system32\spbcd.dll
    2017-08-29 19:55 - 2017-07-28 01:05 - 001525760 _____ (Microsoft Corporation) C:\windows\system32\RecoveryDrive.exe
    2017-08-29 19:55 - 2017-07-28 01:05 - 000954368 _____ (Microsoft Corporation) C:\windows\system32\autoconv.exe
    2017-08-29 19:55 - 2017-07-28 01:05 - 000926208 _____ (Microsoft Corporation) C:\windows\system32\autofmt.exe
    2017-08-29 19:55 - 2017-07-28 01:05 - 000078848 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
    2017-08-29 19:55 - 2017-07-07 04:27 - 000965024 _____ (Microsoft Corporation) C:\windows\system32\hvloader.efi
    2017-08-29 19:55 - 2017-07-07 04:17 - 001017760 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
    2017-08-29 19:55 - 2017-07-07 04:14 - 001171032 _____ (Microsoft Corporation) C:\windows\system32\dcomp.dll
    2017-08-29 19:55 - 2017-07-07 04:13 - 000147800 _____ (Microsoft Corporation) C:\windows\system32\Clipc.dll
    2017-08-29 19:55 - 2017-07-07 04:10 - 000372128 _____ (Microsoft Corporation) C:\windows\system32\CloudExperienceHost.dll
    2017-08-29 19:55 - 2017-07-07 04:09 - 000041376 _____ (Microsoft Corporation) C:\windows\system32\wininitext.dll
    2017-08-29 19:55 - 2017-07-07 03:27 - 000859136 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
    2017-08-29 19:55 - 2017-07-07 03:27 - 000577024 _____ (Microsoft Corporation) C:\windows\system32\duser.dll
    2017-08-29 19:55 - 2017-07-07 03:27 - 000443392 _____ (Microsoft Corporation) C:\windows\system32\PerceptionSimulationExtensions.dll
    2017-08-29 19:55 - 2017-07-07 03:23 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\eapprovp.dll
    2017-08-29 19:55 - 2017-07-07 03:21 - 000096256 _____ (Microsoft Corporation) C:\windows\system32\ActiveSyncCsp.dll
    2017-08-29 19:55 - 2017-07-07 03:19 - 000137216 _____ (Microsoft Corporation) C:\windows\system32\raschap.dll
    2017-08-29 19:55 - 2017-07-07 03:18 - 000563712 _____ (Microsoft Corporation) C:\windows\system32\DevicePairing.dll
    2017-08-29 19:55 - 2017-07-07 03:18 - 000353280 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
    2017-08-29 19:55 - 2017-07-07 03:07 - 000430080 _____ (Microsoft Corporation) C:\windows\system32\PlayToDevice.dll
    2017-08-29 19:55 - 2017-07-07 03:07 - 000391168 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
    2017-08-29 19:55 - 2017-07-07 03:05 - 000370176 _____ (Microsoft Corporation) C:\windows\system32\msinfo32.exe
    2017-08-29 19:55 - 2017-07-07 03:04 - 001703424 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
    2017-08-29 19:55 - 2017-07-07 03:04 - 001403392 _____ (Microsoft Corporation) C:\windows\system32\wdc.dll
    2017-08-29 19:55 - 2017-06-20 03:18 - 000096672 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
    2017-08-29 19:55 - 2017-06-20 03:17 - 000629152 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
    2017-08-29 19:55 - 2017-06-20 03:17 - 000544160 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
    2017-08-29 19:55 - 2017-06-20 03:17 - 000334240 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
    2017-08-29 19:55 - 2017-06-20 03:17 - 000136096 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
    2017-08-29 19:55 - 2017-06-20 03:17 - 000034720 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe
    2017-08-29 19:55 - 2017-06-20 03:16 - 000335776 _____ (Microsoft Corporation) C:\windows\system32\dcntel.dll
    2017-08-29 19:55 - 2017-06-20 03:15 - 000233376 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
    2017-08-29 19:55 - 2017-06-20 03:03 - 000179608 _____ (Microsoft Corporation) C:\windows\system32\CloudExperienceHostUser.dll
    2017-08-29 19:55 - 2017-06-20 03:03 - 000102312 _____ (Microsoft Corporation) C:\windows\system32\CredentialUIBroker.exe
    2017-08-29 19:55 - 2017-06-20 03:02 - 000426912 _____ (Microsoft Corporation) C:\windows\system32\CloudExperienceHostCommon.dll
    2017-08-29 19:55 - 2017-06-20 03:00 - 000558920 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.dll
    2017-08-29 19:55 - 2017-06-20 02:59 - 000583304 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
    2017-08-29 19:55 - 2017-06-20 02:58 - 000833160 _____ (Microsoft Corporation) C:\windows\system32\EditionUpgradeManagerObj.dll
    2017-08-29 19:55 - 2017-06-20 02:58 - 000203168 _____ (Microsoft Corporation) C:\windows\system32\CloudExperienceHostBroker.dll
    2017-08-29 19:55 - 2017-06-20 02:16 - 000970752 _____ (Microsoft Corporation) C:\windows\system32\msctfuimanager.dll
    2017-08-29 19:55 - 2017-06-20 02:16 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\oleacc.dll
    2017-08-29 19:55 - 2017-06-20 02:14 - 000032768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mskssrv.sys
    2017-08-29 19:55 - 2017-06-20 02:13 - 000216064 _____ (Microsoft Corporation) C:\windows\system32\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
    2017-08-29 19:55 - 2017-06-20 02:13 - 000081408 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
    2017-08-29 19:55 - 2017-06-20 02:13 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\WFDSConMgr.dll
    2017-08-29 19:55 - 2017-06-20 02:12 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\Windows.System.Profile.RetailInfo.dll
    2017-08-29 19:55 - 2017-06-20 02:11 - 000200192 _____ (Microsoft Corporation) C:\windows\system32\ScDeviceEnum.dll
    2017-08-29 19:55 - 2017-06-20 02:10 - 000188928 _____ (Microsoft Corporation) C:\windows\system32\wincredui.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000555008 _____ (Microsoft Corporation) C:\windows\system32\WFDSConMgrSvc.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000250368 _____ (Microsoft Corporation) C:\windows\system32\SCardSvr.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000205312 _____ (Microsoft Corporation) C:\windows\system32\ClipboardServer.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000189952 _____ (Microsoft Corporation) C:\windows\system32\certprop.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sendmail.dll
    2017-08-29 19:55 - 2017-06-20 02:09 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\dataclen.dll
    2017-08-29 19:55 - 2017-06-20 02:08 - 000791040 _____ (Microsoft Corporation) C:\windows\system32\certca.dll
    2017-08-29 19:55 - 2017-06-20 02:07 - 000916992 _____ (Microsoft Corporation) C:\windows\system32\bcastdvr.exe
    2017-08-29 19:55 - 2017-06-20 02:07 - 000757248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdiWiFi.sys
    2017-08-29 19:55 - 2017-06-20 02:07 - 000621056 _____ (Microsoft Corporation) C:\windows\system32\SndVolSSO.dll
    2017-08-29 19:55 - 2017-06-20 02:06 - 000455680 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
    2017-08-29 19:55 - 2017-06-20 02:06 - 000335872 _____ (Microsoft Corporation) C:\windows\system32\CloudDomainJoinDataModelServer.dll
    2017-08-29 19:55 - 2017-06-20 02:06 - 000253440 _____ (Microsoft Corporation) C:\windows\system32\edputil.dll
    2017-08-29 19:55 - 2017-06-20 02:06 - 000045056 _____ (Microsoft Corporation) C:\windows\system32\TokenBrokerUI.dll
    2017-08-29 19:55 - 2017-06-20 02:05 - 002873344 _____ (Microsoft Corporation) C:\windows\system32\themeui.dll
    2017-08-29 19:55 - 2017-06-20 02:05 - 000696320 _____ (Microsoft Corporation) C:\windows\system32\mmsys.cpl
    2017-08-29 19:55 - 2017-06-20 02:04 - 001425920 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
    2017-08-29 19:55 - 2017-06-20 02:04 - 000899072 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
    2017-08-29 19:55 - 2017-06-20 02:04 - 000400896 _____ (Microsoft Corporation) C:\windows\system32\RDXTaskFactory.dll
    2017-08-29 19:55 - 2017-06-20 02:04 - 000178176 _____ (Microsoft Corporation) C:\windows\system32\EditionUpgradeHelper.dll
    2017-08-29 19:55 - 2017-06-20 02:02 - 000081920 _____ (Microsoft Corporation) C:\windows\system32\CloudDomainJoinAUG.dll
    2017-08-29 19:55 - 2017-06-20 01:57 - 000290816 _____ (Microsoft Corporation) C:\windows\system32\omadmclient.exe
    2017-08-29 19:55 - 2017-06-20 01:57 - 000138752 _____ (Microsoft Corporation) C:\windows\system32\DMPushRouterCore.dll
    2017-08-29 19:55 - 2017-06-20 01:56 - 000241152 _____ (Microsoft Corporation) C:\windows\system32\wdmaud.drv
    2017-08-29 19:55 - 2017-06-03 07:00 - 000321376 _____ (Microsoft Corporation) C:\windows\system32\capauthz.dll
    2017-08-29 19:55 - 2017-06-03 06:58 - 000660384 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
    2017-08-29 19:55 - 2017-06-03 06:11 - 000002560 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
    2017-08-29 19:55 - 2017-06-03 06:10 - 000076800 _____ (Microsoft Corporation) C:\windows\system32\DeviceCredentialDeployment.exe
    2017-08-29 19:55 - 2017-06-03 06:01 - 006726656 _____ (Microsoft Corporation) C:\windows\system32\mspaint.exe
    2017-08-29 18:46 - 2017-08-29 18:46 - 000000219 _____ C:\Users\gabri\Desktop\Counter-Strike Global Offensive.url
    2017-08-28 21:03 - 2017-09-18 17:59 - 000004180 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{A33694B3-F7AD-4FA4-B6F8-CA79E0277518}
    2017-08-28 20:47 - 2017-08-30 21:14 - 000000000 ____D C:\Users\gabri\AppData\Local\PointBlank
    2017-08-28 20:34 - 2017-08-28 20:34 - 000000788 _____ C:\Users\gabri\Desktop\PointBlank.lnk
    2017-08-28 20:34 - 2017-08-28 20:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PointBlank
    2017-08-28 20:28 - 2017-08-28 20:28 - 000000000 ____D C:\ongame
    2017-08-28 19:32 - 2017-08-28 19:32 - 000000000 ____D C:\windows\System32\Tasks\S-1-5-21-1227778907-1800773084-68729552-1002
    2017-08-28 18:47 - 2017-08-28 18:47 - 000001049 _____ C:\Users\gabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recursos Opcionais.lnk
    2017-08-28 18:39 - 2017-09-07 23:56 - 000000000 ____D C:\Users\gabri\AppData\Local\Steam
    2017-08-28 18:39 - 2017-08-28 18:39 - 000000000 ____D C:\Users\gabri\AppData\Local\CEF
    2017-08-28 18:36 - 2017-09-17 11:04 - 000920418 _____ C:\windows\system32\prfh0416.dat
    2017-08-28 18:36 - 2017-09-17 11:04 - 000191814 _____ C:\windows\system32\prfc0416.dat
    2017-08-28 18:36 - 2017-08-28 18:34 - 000328664 _____ C:\windows\system32\prfi0416.dat
    2017-08-28 18:36 - 2017-08-28 18:34 - 000040858 _____ C:\windows\system32\prfd0416.dat
    2017-08-28 18:35 - 2017-09-17 10:55 - 000000000 ____D C:\Program Files (x86)\Steam
    2017-08-28 18:35 - 2017-08-28 18:35 - 000001034 _____ C:\Users\Public\Desktop\Steam.lnk
    2017-08-28 18:35 - 2017-08-28 18:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2017-08-28 18:27 - 2017-08-28 18:27 - 000001049 _____ C:\Users\gabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
    2017-08-28 18:27 - 2017-03-17 21:58 - 005091328 _____ (Microsoft Corporation) C:\windows\system32\NlsLexicons0416.dll
    2017-08-28 18:27 - 2017-03-17 21:55 - 000164864 _____ (Microsoft Corporation) C:\windows\system32\NlsData0416.dll
    2017-08-28 18:27 - 2017-03-17 21:52 - 004434944 _____ (Microsoft Corporation) C:\windows\system32\MLS6.dll
    2017-08-28 18:27 - 2017-03-17 21:43 - 005091328 _____ (Microsoft Corporation) C:\windows\SysWOW64\NlsLexicons0416.dll
    2017-08-28 18:27 - 2017-03-17 21:40 - 000128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\NlsData0416.dll
    2017-08-28 18:27 - 2017-03-17 21:38 - 004383232 _____ (Microsoft Corporation) C:\windows\SysWOW64\MLS6.dll
    2017-08-28 18:23 - 2017-08-28 18:23 - 000002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2017-08-28 18:23 - 2017-08-28 18:23 - 000002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2017-08-28 18:22 - 2017-08-28 18:33 - 000000000 ____D C:\Users\gabri\AppData\Local\Google
    2017-08-28 18:22 - 2017-08-28 18:23 - 000000000 ____D C:\Program Files (x86)\Google
    2017-08-28 18:22 - 2017-08-28 18:22 - 000003586 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2017-08-28 18:22 - 2017-08-28 18:22 - 000003462 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2017-08-28 18:19 - 2017-08-28 18:19 - 000000000 ____D C:\Users\gabri\AppData\Local\MicrosoftEdge
    2017-08-28 18:18 - 2017-09-15 02:44 - 000003374 _____ C:\windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1227778907-1800773084-68729552-1002
    2017-08-28 18:18 - 2017-08-28 18:18 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Skype
    2017-08-28 18:18 - 2017-08-28 18:18 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Macromedia
    2017-08-28 18:17 - 2017-09-18 17:59 - 000004034 _____ C:\windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
    2017-08-28 18:17 - 2017-09-17 15:52 - 000004222 _____ C:\windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
    2017-08-28 18:17 - 2017-09-17 11:01 - 000000000 ___RD C:\Users\gabri\OneDrive
    2017-08-28 18:17 - 2017-09-15 02:44 - 000002371 _____ C:\Users\gabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2017-08-28 18:17 - 2017-08-28 18:17 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Intel Corporation
    2017-08-28 18:16 - 2017-08-29 21:25 - 000000000 ____D C:\Users\gabri\AppData\Local\Comms
    2017-08-28 18:15 - 2017-08-28 19:10 - 000000000 ____D C:\Users\gabri\AppData\Local\Publishers
    2017-08-28 18:15 - 2017-08-28 18:15 - 000000000 ____D C:\Users\gabri\AppData\Local\Power2Go8
    2017-08-28 18:14 - 2017-09-17 10:55 - 000000000 __SHD C:\Users\gabri\IntelGraphicsProfiles
    2017-08-28 18:14 - 2017-09-12 19:22 - 000000000 ____D C:\Users\gabri\AppData\Local\Packages
    2017-08-28 18:14 - 2017-09-09 15:43 - 000000000 ____D C:\Users\gabri\AppData\Local\VirtualStore
    2017-08-28 18:14 - 2017-08-28 18:47 - 000000000 ____D C:\Users\gabri\AppData\Local\ConnectedDevicesPlatform
    2017-08-28 18:14 - 2017-08-28 18:14 - 000000000 ____D C:\Users\gabri\AppData\Roaming\Adobe
    2017-08-28 18:14 - 2017-08-28 18:14 - 000000000 ____D C:\Users\gabri\AppData\Local\TileDataLayer
    2017-08-28 18:12 - 2017-09-07 19:18 - 000003446 _____ C:\windows\System32\Tasks\McAfee Remediation (Prepare)
    2017-08-28 18:10 - 2017-08-28 18:10 - 000003322 _____ C:\windows\System32\Tasks\SystemToolsDailyTest
    2017-08-28 18:08 - 2017-09-17 10:54 - 000000000 ____D C:\Users\gabri
    2017-08-28 18:08 - 2017-08-28 18:08 - 000000020 ___SH C:\Users\gabri\ntuser.ini
    2017-06-28 21:45 - 2017-08-28 16:57 - 000002304 _____ C:\windows\System32\Tasks\RtHDVBg_PushButton
    2017-06-28 21:45 - 2017-06-28 21:45 - 000000000 ____D C:\ProgramData\NVIDIA
    2017-06-28 21:45 - 2017-06-28 21:45 - 000000000 ____D C:\Program Files\Realtek
    2017-06-28 21:45 - 2017-06-28 20:27 - 000000000 ____D C:\windows\SysWOW64\RTCOM
    2017-06-28 21:44 - 2017-06-28 21:44 - 000000000 ____H C:\windows\system32\Drivers\Msft_User_esif_umdf2_02_00_00.Wdf
    2017-06-28 21:44 - 2017-06-28 21:44 - 000000000 ____H C:\windows\system32\Drivers\Msft_Kernel_esif_lf_01011.Wdf
    2017-06-28 21:44 - 2017-06-28 21:44 - 000000000 ____D C:\windows\system32\Intel
    2017-06-28 21:44 - 2017-06-28 21:44 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
    2017-06-28 21:44 - 2017-06-28 21:44 - 000000000 ____D C:\Program Files\NVIDIA Corporation
    2017-06-28 21:44 - 2016-10-23 09:57 - 006385720 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 002475576 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 001764408 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 001362368 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
    2017-06-28 21:44 - 2016-10-23 09:57 - 000546752 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 000393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 000083512 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
    2017-06-28 21:44 - 2016-10-23 09:57 - 000071224 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
    2017-06-28 21:44 - 2016-10-19 08:39 - 007500035 _____ C:\windows\system32\nvcoproc.bin
    2017-06-28 21:43 - 2017-09-18 17:56 - 000000000 ____D C:\windows\system32\SleepStudy
    2017-06-28 21:43 - 2017-09-17 10:55 - 000251960 _____ C:\windows\system32\FNTCACHE.DAT
    2017-06-28 21:43 - 2017-09-17 10:55 - 000000006 ____H C:\windows\Tasks\SA.DAT
    2017-06-28 21:43 - 2017-06-28 21:43 - 000000000 ____D C:\windows\ServiceProfiles
    2017-06-28 21:07 - 2017-06-28 21:20 - 000022863 _____ C:\windows\diagwrn.xml
    2017-06-28 21:07 - 2017-06-28 21:20 - 000022863 _____ C:\windows\diagerr.xml
    2017-06-28 20:42 - 2017-06-28 20:42 - 000000000 ____D C:\windows\SysWOW64\sda
    2017-06-28 20:41 - 2017-09-09 15:18 - 000000000 ____D C:\windows\Panther
    2017-06-28 20:37 - 2016-12-23 11:39 - 008104122 _____ C:\windows\system32\Drivers\RTAIODAT.DAT
    2017-06-28 20:37 - 2016-12-23 11:39 - 005804772 _____ C:\windows\system32\Drivers\rtvienna.dat
    2017-06-28 20:37 - 2016-12-23 11:39 - 005556224 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHD64.sys
    2017-06-28 20:37 - 2016-12-23 11:39 - 003581816 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApi64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 003203584 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtPgEx64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 003202040 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RltkAPO64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 003014144 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSnMg64.cpl
    2017-06-28 20:37 - 2016-12-23 11:39 - 001353824 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTCOM64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 000689872 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtDataProc64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 000571376 _____ (Intel Corporation) C:\windows\system32\tbb_waves.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 000343704 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtlCPAPI64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 000192976 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCfg64.dll
    2017-06-28 20:37 - 2016-12-23 11:39 - 000023688 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCoLDR64.dll
    2017-06-28 20:37 - 2016-12-23 11:38 - 023547544 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioRenderAVX64.dll
    2017-06-28 20:37 - 2016-12-23 11:38 - 023447352 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioRender64.dll
    2017-06-28 20:37 - 2016-12-23 11:38 - 017398616 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioCapture64.dll
    2017-06-28 20:37 - 2016-12-23 11:38 - 003786712 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioMeters64.exe
    2017-06-28 20:37 - 2016-12-23 11:38 - 002201600 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RCoInstII64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 040070200 _____ C:\windows\system32\nvcompiler.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 035182648 _____ C:\windows\SysWOW64\nvcompiler.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 034849848 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 028243904 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 010868288 _____ (NVIDIA Corporation) C:\windows\system32\nvptxJitCompiler.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 010775736 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 010325984 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 009113296 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 008877992 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvptxJitCompiler.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 008716216 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 003916280 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 003458632 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 002912704 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 002551352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 001937464 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6437320.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 001586744 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6437320.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 001019328 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000959032 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000944696 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000893888 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000802768 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFTH264.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000801560 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFThevc.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000688784 _____ (NVIDIA Corporation) C:\windows\system32\nvfatbinaryLoader.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000643928 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFTH264.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000642392 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFThevc.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000578056 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvfatbinaryLoader.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000439352 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000394888 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000388544 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000327224 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
    2017-06-28 20:37 - 2016-10-24 01:17 - 000041033 _____ C:\windows\system32\nvinfo.pb
    2017-06-28 20:37 - 2016-10-24 01:17 - 000000669 _____ C:\windows\SysWOW64\nv-vk32.json
    2017-06-28 20:37 - 2016-10-24 01:17 - 000000669 _____ C:\windows\system32\nv-vk64.json
    2017-06-28 20:37 - 2016-10-19 14:14 - 000946696 _____ (Realtek ) C:\windows\system32\Drivers\rt640x64.sys
    2017-06-28 20:37 - 2016-10-19 14:14 - 000082544 _____ (Realtek Semiconductor Corporation) C:\windows\system32\RtNicProp64.dll
    2017-06-28 20:37 - 2016-09-13 13:08 - 010017236 _____ C:\windows\system32\Drivers\Netwfw04.dat
    2017-06-28 20:37 - 2016-09-13 13:08 - 007308560 _____ (Intel Corporation) C:\windows\system32\Drivers\Netwtw04.sys
    2017-06-28 20:37 - 2016-08-16 15:09 - 000054800 _____ (Intel Corporation) C:\windows\system32\Drivers\HidEventFilter.sys
    2017-06-28 20:37 - 2016-08-12 19:40 - 001804688 _____ (Microsoft Corporation) C:\windows\system32\WdfCoInstaller01011.dll
    2017-06-28 20:37 - 2016-08-12 19:40 - 000350272 _____ (Intel Corporation) C:\windows\system32\Drivers\esif_lf.sys
    2017-06-28 20:37 - 2016-08-12 19:39 - 000071232 _____ (Intel Corporation) C:\windows\system32\Drivers\dptf_acpi.sys
    2017-06-28 20:37 - 2016-08-12 19:39 - 000066624 _____ (Intel Corporation) C:\windows\system32\Drivers\dptf_cpu.sys
    2017-06-28 20:37 - 2016-08-05 11:09 - 000418784 _____ (Realsil Semiconductor Corporation) C:\windows\system32\Drivers\RtsUer.sys
    2017-06-28 20:37 - 2016-07-31 08:00 - 001730312 _____ (Microsoft Corporation) C:\windows\system32\WdfCoInstaller01009.dll
    2017-06-28 20:37 - 2016-07-31 07:59 - 000035272 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\nvswcfilter.sys
    2017-06-28 20:37 - 2016-07-14 11:40 - 009891328 _____ (Realtek Semiconductor Corp.) C:\windows\SysWOW64\RsCRIcon.dll
    2017-06-28 20:37 - 2016-07-14 11:27 - 000084480 _____ (Realtek Semiconductor.) C:\windows\system32\RtCRX64.dll
    2017-06-28 20:37 - 2016-07-14 11:23 - 004332032 _____ (Realtek Semiconductor Corp.) C:\windows\RtCRU64.exe
    2017-06-28 20:36 - 2017-06-28 21:06 - 000000000 ____D C:\MININT
    2017-06-28 20:36 - 2016-10-15 08:56 - 000174200 _____ (Intel Corporation) C:\windows\system32\ibtsiva.exe
    2017-06-28 20:36 - 2016-10-07 04:52 - 000762632 _____ (Intel Corporation) C:\windows\system32\Drivers\ibtuart.sys
    2017-06-28 20:36 - 2016-10-07 04:52 - 000598088 _____ C:\windows\system32\Drivers\370b12060002340e00.bseq
    2017-06-28 20:36 - 2016-10-07 04:52 - 000580824 _____ C:\windows\system32\Drivers\370b12060002340e00.sfi
    2017-06-28 20:36 - 2016-10-07 04:52 - 000000057 _____ C:\windows\system32\Drivers\370b12230034271000.bseq
    2017-06-28 20:36 - 2016-10-07 04:51 - 000379152 _____ (Intel Corporation) C:\windows\system32\ibtproppage.dll
    2017-06-28 20:36 - 2016-10-07 04:51 - 000249104 _____ (Intel Corporation) C:\windows\system32\Drivers\ibtusb.sys
    2017-06-28 20:36 - 2016-09-20 13:04 - 000795640 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStorA.sys
    2017-06-28 20:36 - 2016-08-29 22:53 - 000282424 _____ (Intel Corporation) C:\windows\system32\Drivers\iaLPSS2_UART2.sys
    2017-06-28 20:36 - 2016-08-29 22:53 - 000184632 _____ (Intel Corporation) C:\windows\system32\Drivers\iaLPSS2_I2C.sys
    2017-06-28 20:36 - 2016-08-29 22:53 - 000151352 _____ (Intel Corporation) C:\windows\system32\Drivers\iaLPSS2_SPI.sys
    2017-06-28 20:36 - 2016-08-29 22:53 - 000089912 _____ (Intel Corporation) C:\windows\system32\Drivers\iaLPSS2_GPIO2.sys
    2017-06-28 20:35 - 2017-06-28 20:35 - 000018812 _____ C:\windows\system32\results.xml
    2017-06-28 20:32 - 2017-06-28 20:32 - 000000000 ____D C:\Program Files (x86)\VulkanRT
    2017-06-28 20:32 - 2017-06-28 20:32 - 000000000 _____ C:\windows\system32\GfxValDisplayLog.bin
    2017-06-28 20:32 - 2017-01-09 18:54 - 000122360 _____ (Khronos Group) C:\windows\system32\OpenCL.DLL
    2017-06-28 20:32 - 2017-01-09 18:54 - 000104448 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.DLL
    2017-06-28 20:32 - 2016-11-22 21:23 - 000271648 _____ C:\windows\SysWOW64\vulkan-1.dll
    2017-06-28 20:32 - 2016-11-22 21:23 - 000110880 _____ C:\windows\SysWOW64\vulkaninfo.exe
    2017-06-28 20:32 - 2016-11-22 21:22 - 000265504 _____ C:\windows\system32\vulkan-1.dll
    2017-06-28 20:32 - 2016-11-22 21:22 - 000125216 _____ C:\windows\system32\vulkaninfo.exe
    2017-06-28 20:30 - 2017-06-28 20:32 - 000000000 ____D C:\Intel
    2017-06-28 20:30 - 2017-06-28 20:30 - 000866130 _____ C:\windows\SysWOW64\PerfStringBackup.INI
    2017-06-28 20:30 - 2017-06-28 20:30 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2017-06-28 20:29 - 2017-08-28 16:57 - 000003118 _____ C:\windows\System32\Tasks\Intel PTT EK Recertification
    2017-06-28 20:28 - 2017-06-28 20:32 - 000000000 ____D C:\Program Files\Intel
    2017-06-28 20:28 - 2017-06-28 20:32 - 000000000 ____D C:\Program Files (x86)\Intel
    2017-06-28 20:28 - 2017-06-28 20:29 - 000000000 ____D C:\ProgramData\Intel
    2017-06-28 20:27 - 2017-06-28 20:28 - 000000000 ___HD C:\Program Files (x86)\Temp
    2017-06-28 20:27 - 2017-06-28 20:27 - 000001115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waves MaxxAudioPro.lnk
    2017-06-28 20:27 - 2017-06-28 20:27 - 000000000 ____D C:\Program Files\Waves
    2017-06-28 20:27 - 2017-06-28 20:27 - 000000000 ____D C:\Program Files (x86)\Realtek
    2017-06-28 20:27 - 2016-09-22 17:55 - 002839520 _____ (Realtek Semiconductor Corp.) C:\windows\RtlExUpd.dll
    2017-06-28 20:26 - 2017-06-28 20:26 - 000001536 _____ C:\windows\SysWOW64\RtkMsgs.dll
    2017-06-28 20:26 - 2017-06-28 20:26 - 000000000 ____D C:\ProgramData\Dell
    2017-06-28 20:23 - 2017-08-07 22:43 - 000209608 _____ (McAfee, Inc.) C:\windows\system32\Drivers\HipShieldK.sys
    2017-06-28 20:22 - 2017-09-06 21:40 - 000003126 _____ C:\windows\System32\Tasks\McAfeeLogon
    2017-06-28 20:22 - 2017-09-06 21:38 - 000000000 ____D C:\windows\System32\Tasks\McAfee
    2017-06-28 20:22 - 2017-06-28 20:22 - 000000000 ____D C:\ProgramData\Intel Security
    2017-06-28 20:21 - 2017-06-21 17:10 - 000350160 _____ (McAfee, Inc.) C:\windows\system32\mfevtps.exe
    2017-06-28 20:20 - 2017-09-09 02:44 - 000000000 ____D C:\Program Files\mcafee
    2017-06-28 20:20 - 2017-09-09 02:44 - 000000000 ____D C:\Program Files\Common Files\McAfee
    2017-06-28 20:20 - 2017-09-09 02:44 - 000000000 ____D C:\Program Files (x86)\McAfee
    2017-06-28 20:20 - 2017-09-08 02:51 - 000000000 ____D C:\ProgramData\McAfee
    2017-06-28 20:20 - 2017-08-28 18:12 - 000000000 ____D C:\Program Files\Common Files\AV
    2017-06-28 20:20 - 2017-06-28 20:20 - 000000000 ____D C:\Program Files\mcafee.com
    2017-06-28 20:20 - 2017-06-28 20:20 - 000000000 ____D C:\Program Files\Common Files\Intel Security
    2017-06-28 20:17 - 2017-08-28 18:10 - 000000000 ____D C:\ProgramData\PCDr
    2017-06-28 20:17 - 2017-06-28 20:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
    2017-06-28 20:17 - 2017-06-28 20:26 - 000000000 ____D C:\Program Files\Dell
    2017-06-28 20:17 - 2017-06-28 20:17 - 000000000 ____D C:\ProgramData\PC-Doctor for Windows
    2017-06-28 20:17 - 2017-06-28 20:17 - 000000000 ____D C:\Program Files\Dell Support Center
    2017-06-28 20:15 - 2017-06-28 20:26 - 000000000 ____D C:\dell
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\ProgramData\proDAD
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\Program Files\NewBlue
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\Program Files\Common Files\NewBlue
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\Program Files (x86)\proDAD
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000000 ____D C:\Program Files (x86)\NewBlue
    2017-06-28 20:14 - 2016-04-27 06:24 - 000506392 _____ (proDAD GmbH) C:\windows\SysWOW64\prodad-codec.dll
    2017-06-28 20:14 - 2016-04-27 06:24 - 000335896 _____ (proDAD GmbH) C:\windows\SysWOW64\proDAD-PA-Support.dll
    2017-06-28 20:10 - 2017-09-17 10:55 - 000190664 ____N (CyberLink Corp.) C:\windows\system32\Drivers\rikvm_3CD7F304.sys
    2017-06-28 20:10 - 2017-06-28 20:10 - 000000000 ____D C:\ProgramData\PDVD
    2017-06-28 20:09 - 2017-06-28 20:14 - 000000000 ____D C:\Program Files (x86)\NSIS Uninstall Information
    2017-06-28 20:07 - 2017-06-28 20:15 - 000000000 ____D C:\ProgramData\SUPPORTDIR
    2017-06-28 20:07 - 2017-06-28 20:11 - 000000000 ____D C:\ProgramData\Package Cache
    2017-06-28 20:05 - 2017-08-28 16:57 - 000002528 _____ C:\windows\System32\Tasks\CLVDLauncher
    2017-06-28 20:05 - 2017-08-28 16:57 - 000002528 _____ C:\windows\System32\Tasks\CLMLSvc_P2G8
    2017-06-28 20:05 - 2013-11-12 16:25 - 000091912 _____ (CyberLink) C:\windows\system32\Drivers\CLVirtualDrive.sys
    2017-06-28 20:03 - 2017-06-28 20:05 - 000000000 ____D C:\Program Files (x86)\CyberLink
    2017-06-28 20:01 - 2017-06-28 20:27 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2017-06-28 20:01 - 2017-06-28 20:14 - 000000000 ____D C:\ProgramData\install_clap
    2017-06-28 20:01 - 2017-06-28 20:14 - 000000000 ____D C:\ProgramData\CyberLink
    2017-06-28 20:01 - 2017-06-28 20:07 - 000000000 ____D C:\ProgramData\Temp
    2017-06-28 20:01 - 2017-06-28 20:07 - 000000000 ____D C:\ProgramData\CLSK
    2017-06-28 19:59 - 2017-06-28 19:59 - 000000000 ____D C:\ProgramData\USOShared
    2017-06-28 19:55 - 2017-06-28 19:55 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
    2017-06-28 19:55 - 2017-06-28 19:55 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
    2017-06-28 19:55 - 2017-06-28 19:55 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
    2017-06-28 19:55 - 2017-06-28 19:55 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
    2017-06-28 19:55 - 2017-06-28 19:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
    2017-06-28 19:54 - 2017-09-17 11:04 - 002250516 _____ C:\windows\system32\PerfStringBackup.INI
    2017-06-28 19:54 - 2017-09-03 10:56 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
    2017-06-28 19:54 - 2017-08-28 16:57 - 000002766 _____ C:\windows\System32\Tasks\OneDrive Standalone Update Task v2
    2017-06-28 19:54 - 2017-06-28 19:54 - 000000000 ____D C:\Program Files\Microsoft Office 15
    2017-06-28 19:53 - 2017-06-28 21:03 - 000000051 _____ C:\windows\smsts.ini
    2017-06-28 19:53 - 2017-06-28 19:53 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2017-06-28 19:51 - 2017-09-12 19:22 - 000000000 __RHD C:\Users\Public\AccountPictures
    2017-06-28 19:51 - 2017-06-28 21:03 - 000000000 _____ C:\windows\authtest.txt
    2017-06-28 19:51 - 2017-03-18 17:56 - 002233344 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintConfig.dll
    2017-06-28 19:49 - 2017-06-28 19:49 - 000000000 _SHDL C:\Documents and Settings
    2017-06-27 19:13 - 2017-06-27 19:13 - 000504792 _____ (McAfee LLC.) C:\windows\system32\Drivers\mfencbdc.sys
    2017-06-27 19:13 - 2017-06-27 19:13 - 000108504 _____ (McAfee LLC.) C:\windows\system32\Drivers\mfencrk.sys
    2017-06-27 19:13 - 2017-06-27 19:13 - 000031192 _____ (McAfee LLC.) C:\windows\system32\Drivers\mfeclnrk.sys
    2017-06-26 09:25 - 2017-06-26 09:25 - 000116208 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mfeplk.sys

    ==================== Three Months Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-09-17 22:11 - 2017-03-18 18:03 - 000000000 ___HD C:\Program Files\WindowsApps
    2017-09-17 22:11 - 2017-03-18 18:03 - 000000000 ____D C:\windows\AppReadiness
    2017-09-17 10:54 - 2017-03-18 08:40 - 001048576 _____ C:\windows\system32\config\BBI
    2017-09-17 09:31 - 2017-03-18 18:01 - 000000000 ____D C:\windows\INF
    2017-09-12 21:27 - 2017-03-18 18:03 - 000000000 ____D C:\windows\rescache
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ___SD C:\windows\SysWOW64\F12
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ___SD C:\windows\system32\F12
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\setup
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\WinBioPlugIns
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\setup
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\windows\ShellExperiences
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2017-09-12 19:17 - 2017-03-18 18:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2017-09-12 19:03 - 2017-03-18 17:51 - 000000000 ____D C:\windows\CbsTemp
    2017-09-06 21:38 - 2017-03-18 18:03 - 000000000 ___HD C:\windows\ELAMBKUP
    2017-09-04 18:31 - 2017-03-18 08:40 - 000032768 _____ C:\windows\system32\config\ELAM
    2017-09-02 22:41 - 2017-03-18 18:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2017-09-02 12:15 - 2017-03-18 18:06 - 000835576 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
    2017-09-02 12:15 - 2017-03-18 18:06 - 000177656 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
    2017-08-30 20:30 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\MUI
    2017-08-30 20:30 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\MUI
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ___RD C:\windows\ImmersiveControlPanel
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ___RD C:\Program Files\Windows Defender
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\WinMetadata
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\WinMetadata
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\oobe
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\migwiz
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\appraiser
    2017-08-29 21:09 - 2017-03-18 18:03 - 000000000 ____D C:\Program Files (x86)\Windows Defender
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\SysWOW64\winrm
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\SysWOW64\WCN
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\SysWOW64\slmgr
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\SysWOW64\Printing_Admin_Scripts
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\system32\winrm
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\system32\WCN
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\system32\slmgr
    2017-08-28 18:35 - 2017-03-18 23:29 - 000000000 ____D C:\windows\system32\Printing_Admin_Scripts
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ___SD C:\windows\SysWOW64\DiagSvcs
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ___SD C:\windows\system32\dsc
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ___SD C:\windows\system32\DiagSvcs
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\oobe
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\Dism
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\SysWOW64\Com
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\SystemResetPlatform
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\system32\Com
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\PolicyDefinitions
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\IME
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\windows\Help
    2017-08-28 18:35 - 2017-03-18 18:03 - 000000000 ____D C:\Program Files\Common Files\System
    2017-08-28 18:35 - 2017-03-18 08:40 - 000000000 ____D C:\windows\system32\Sysprep
    2017-08-28 18:35 - 2017-03-18 08:40 - 000000000 ____D C:\windows\system32\Dism
    2017-08-28 18:35 - 2017-03-18 08:40 - 000000000 ____D C:\windows\servicing
    2017-08-28 18:28 - 2017-03-18 23:30 - 000000000 ____D C:\windows\OCR
    2017-08-28 18:11 - 2017-03-18 18:03 - 000000000 ____D C:\windows\appcompat

    ==================== Files in the root of some directories =======

    2017-06-28 20:02 - 2017-06-28 20:07 - 000000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
    2017-06-28 20:10 - 2017-06-28 20:10 - 000000105 _____ () C:\ProgramData\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}.log
    2017-06-28 20:14 - 2017-06-28 20:14 - 000000100 _____ () C:\ProgramData\{6BADCD73-E925-46F7-A295-FF2448632728}.log
    2017-06-28 20:15 - 2017-06-28 20:15 - 000000098 _____ () C:\ProgramData\{CEF5334F-B91A-4327-ACAE-AA50DCE3F995}.log

    Some files in TEMP:
    ====================
    2017-09-12 18:18 - 2017-09-12 18:18 - 000476672 _____ () C:\Users\gabri\AppData\Local\Temp\7za.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000388608 _____ (Trend Micro Inc.) C:\Users\gabri\AppData\Local\Temp\hijackthis.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000030720 _____ (NirSoft) C:\Users\gabri\AppData\Local\Temp\NirCmd.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000256512 _____ () C:\Users\gabri\AppData\Local\Temp\PEVZ.EXE
    2017-09-12 18:18 - 2017-09-12 18:18 - 000069632 _____ () C:\Users\gabri\AppData\Local\Temp\remove.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000098816 _____ () C:\Users\gabri\AppData\Local\Temp\sed.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000057344 _____ (Optimum X) C:\Users\gabri\AppData\Local\Temp\shortcut.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000161792 _____ (SteelWerX) C:\Users\gabri\AppData\Local\Temp\swreg.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000217088 _____ (SteelWerX) C:\Users\gabri\AppData\Local\Temp\swxcacls.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000154232 _____ (Noël Danjou) C:\Users\gabri\AppData\Local\Temp\wget.exe

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-09-14 01:48

    ==================== End of FRST.txt ============================

    Addition.txt

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Bom dia! :)

     

    Etapa 1

     

    Somente 1 AV e 1 FW instalado/ativado no Windows.

     

    Citação

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: McAfee VirusScan (Disabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
    FW: McAfee Firewall (Disabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7}

     

    Etapa 2

     

    Desinstale os seguintes programas:

     

    PointBlank (caso não use ou desconheça)
    Zemana AntiMalware

     

    Etapa 3

     

    Ative o firewall do Windows.

     

    Etapa 4

     

    Desative temporariamente seu antivírus, antispywares e firewall, para não causar conflitos.

     

    Baixe o arquivo (fixlist.txt) no anexo deste post e salve-o na Área de Trabalho (Desktop).

    Execute o FRST.exe (ou FRST64.exe) e clique no botão Corrigir.

    Aguarde... ao final será gerado o log Fixlog.txt  salvo em sua Área de Trabalho (Desktop).

    Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

     

    Abraços :D

    fixlist.txt

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Boa noite, @diego_moicano!

     

    Referente a etapa 1 eu utilizo apenas o AV e o FW do McAfee. Recomenda que eu desative este e utilize o Windows Defender?

     

    Segue Fixlog.txt:

     

    Fix result of Farbar Recovery Scan Tool (x64) Version: 17-09-2017 01
    Ran by gabri (19-09-2017 18:29:54) Run:1
    Running from C:\Users\gabri\Desktop
    Loaded Profiles: gabri (Available Profiles: gabri)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************

    CreateRestorePoint:
    CloseProcesses:
    CMD: bitsadmin /util /setieproxy localsystem NO_PROXY RESET
    SearchScopes: HKU\S-1-5-21-1227778907-1800773084-68729552-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    S3 NcdAutoSetup; C:\windows\System32\svchost.exe [47664 2017-03-18] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
    S3 NcdAutoSetup; C:\windows\SysWOW64\svchost.exe [40904 2017-03-18] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
    R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
    S3 xhunter1; \??\C:\windows\xhunter1.sys [X]
    S3 xspirit; \??\C:\windows\xspirit.sys [X]
    2017-09-12 18:18 - 2017-09-12 18:18 - 000476672 _____ () C:\Users\gabri\AppData\Local\Temp\7za.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000388608 _____ (Trend Micro Inc.) C:\Users\gabri\AppData\Local\Temp\hijackthis.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000030720 _____ (NirSoft) C:\Users\gabri\AppData\Local\Temp\NirCmd.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000256512 _____ () C:\Users\gabri\AppData\Local\Temp\PEVZ.EXE
    2017-09-12 18:18 - 2017-09-12 18:18 - 000069632 _____ () C:\Users\gabri\AppData\Local\Temp\remove.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000098816 _____ () C:\Users\gabri\AppData\Local\Temp\sed.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000057344 _____ (Optimum X) C:\Users\gabri\AppData\Local\Temp\shortcut.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000161792 _____ (SteelWerX) C:\Users\gabri\AppData\Local\Temp\swreg.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000217088 _____ (SteelWerX) C:\Users\gabri\AppData\Local\Temp\swxcacls.exe
    2017-09-12 18:18 - 2017-09-12 18:18 - 000154232 _____ (Noël Danjou) C:\Users\gabri\AppData\Local\Temp\wget.exe
    CMD: ipconfig /flushdns
    EmptyTemp:

    *****************

    Restore point was successfully created.
    Processes closed successfully.

    ========= bitsadmin /util /setieproxy localsystem NO_PROXY RESET =========


    BITSADMIN version 3.0
    BITS administration utility.
    (C) Copyright 2000-2006 Microsoft Corp.

    BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
    Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

    Internet proxy settings for account localsystem set to NO_PROXY.
    (connection = default)


    ========= End of CMD: =========

    HKU\S-1-5-21-1227778907-1800773084-68729552-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    HKLM\System\CurrentControlSet\Services\NcdAutoSetup => key removed successfully
    NcdAutoSetup => service removed successfully
    NcdAutoSetup => service not found.
    HKLM\System\CurrentControlSet\Services\ibtsiva => key removed successfully
    ibtsiva => service removed successfully
    HKLM\System\CurrentControlSet\Services\xhunter1 => key removed successfully
    xhunter1 => service removed successfully
    HKLM\System\CurrentControlSet\Services\xspirit => key removed successfully
    xspirit => service removed successfully
    C:\Users\gabri\AppData\Local\Temp\7za.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\hijackthis.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\NirCmd.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\PEVZ.EXE => moved successfully
    C:\Users\gabri\AppData\Local\Temp\remove.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\sed.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\shortcut.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\swreg.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\swxcacls.exe => moved successfully
    C:\Users\gabri\AppData\Local\Temp\wget.exe => moved successfully

    ========= ipconfig /flushdns =========


    Configura‡ao de IP do Windows

    Libera‡ao do Cache do DNS Resolver bem-sucedida.

    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    BITS transfer queue => 7888896 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 16978559 B
    Java, Flash, Steam htmlcache => 31873207 B
    Windows/system/drivers => 2024813 B
    Edge => 0 B
    Chrome => 606711527 B
    Firefox => 0 B
    Opera => 0 B

    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    Users => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 132053 B
    systemprofile32 => 128 B
    LocalService => 15582 B
    NetworkService => 0 B
    gabri => 65525374 B

    RecycleBin => 132150 B
    EmptyTemp: => 697.4 MB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 18:30:38 ====

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Citação

    Recomenda que eu desative este e utilize o Windows Defender?

     

    É uma escolha pessoal, mas posso te indicar sites que avaliam AVs e então você poderá encontrar sua resposta. ;)

     

    https://www.av-comparatives.org/

     

    https://www.av-test.org/en/

     

    Acesse o site Malwarebytes, clique em Download Gratuito e baixe o arquivo para sua Área de Trabalho (Desktop).

     

    Desative antivírus, antispywares, enfim, programas de prevenção para não causar conflitos.

     

    Clique com o botão direito do mouse no arquivo setup.exe e escolha: Executar como Administrador

     

    • Siga os passos para a instalação;
    • Ao clicar em Concluir aguarde o programa ser aberto;
    • No alto à direita clique em Atualizar agora;
    • O navegador irá abrir, pode fechá-lo e aguarde o término das atualizações;
    • No painel à esquerda clique em Configurações;
    • Na aba Proteção ative Procurar rootkits;
    • Depois clique em Análise no painel à esquerda;
    • Então clique no botão Iniciar Análise e aguarde;
    • Quando o scan terminar uma janela irá se abrir próximo ao relógio;
    • Nela clique em Ver Resultado;
    • Deixe todas as entradas marcadas e clique no botão Colocar em Quarentena;
    • Na janela que abrir clique em Sim para que o computador seja reiniciado;
    • Uma vez reiniciado, abra novamente o Malwarebytes e clique em Histórico e cliquem em Excluir Tudo (opcional);
    • O log será salvo automaticamente pelo programa.
    • Para exportá-lo, clique na aba Histórico > Registros do aplicativo na janela principal do programa;
    • Clique duas vezes em cima do log mais atual e exporte em .TXT;
    • Poste em sua próxima resposta.

    Abraços :D

    • Curtir 1

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Bom dia, @diego_moicano

     

    Segue o log:

     

    Malwarebytes
    www.malwarebytes.com

    -Detalhes de registro-
    Data da análise: 23/09/17
    Hora da análise: 06:51
    Arquivo de registro: cd77edcc-a044-11e7-a893-64006afc039a.json
    Administrador: Sim

    -Informação do software-
    Versão: 3.2.2.2029
    Versão de componentes: 1.0.188
    Versão do pacote de definições: 1.0.2869
    Licença: Versão de Avaliação

    -Informação do sistema-
    Sistema operacional: Windows 10 (Build 15063.608)
    CPU: x64
    Sistema de arquivos: NTFS
    Usuário: WINDOWS-8C63VIO\gabri

    -Resumo da análise-
    Tipo de análise: Análise de Ameaças
    Resultado: Concluído
    Objetos verificados: 337055
    Ameaças detectadas: 0
    (Nenhum item malicioso detectado)
    Ameaças em quarentena: 0
    (Nenhum item malicioso detectado)
    Tempo decorrido: 2 min, 19 seg

    -Opções da análise-
    Memória: Habilitado
    Inicialização: Habilitado
    Sistema de arquivos: Habilitado
    Arquivos compactados: Habilitado
    Rootkits: Habilitado
    Heurística: Habilitado
    PUP: Detectar
    PUM: Detectar

    -Detalhes da análise-
    Processo: 0
    (Nenhum item malicioso detectado)

    Módulo: 0
    (Nenhum item malicioso detectado)

    Chave de registro: 0
    (Nenhum item malicioso detectado)

    Valor de registro: 0
    (Nenhum item malicioso detectado)

    Dados de registro: 0
    (Nenhum item malicioso detectado)

    Fluxo de dados: 0
    (Nenhum item malicioso detectado)

    Pasta: 0
    (Nenhum item malicioso detectado)

    Arquivo: 0
    (Nenhum item malicioso detectado)

    Setor físico: 0
    (Nenhum item malicioso detectado)


    (end)

     

    Abraços :thumbsup:

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

    Baixe o Stinger e salve em sua Área de trabalho (Desktop).
    32 bit (x86) ou 64 bit (x64)

    • Execute o arquivo Stinger.exe como Administrador.
    • Clique no botão “I Accept”


    Stinger%20a.png

    Na nova janela clique em “Advanced” e depois “Settings”

    Stinger%20b.png

    Na janela configurações deixe conforme imagem abaixo e clique no botão “Save”

    9hnsyu.png

    Clique em “Customize my Scan”

    Stinger%20f.png

    Selecione as unidades do sistema e em seguida clique no botão “Scan”

    Stinger%20g.png

    Ao final clique em “View log”, será aberto uma janela com o log em seu navegador.
    Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

     

    Abraços :D

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Boa noite, @diego_moicano

     

    Segue o log:

     

    McAfee Stinger Scan Results

    McAfee® Labs Stinger™ Version 12.1.0.2504 built on Sep 22 2017 at 02:45:33

    Copyright© 2015, McAfee, Inc. All Rights Reserved.

     

    AV Engine version v5900.7806 for Windows.

    Virus data file v1000.0 created on Sep 22, 2017

    Ready to scan for 10226 viruses, trojans and variants.

     

    Custom scan initiated on Saturday, September 23, 2017 17:12:14

     

    Rootkit scan result : Clean.

     

    Summary Report on C:

    File(s)

    TotalFiles:............ 319291

    Clean:................. 223914

    Not Scanned:........... 95377

    Possibly Infected:..... 0

     

    Time: 00:54:43

     

    Scan completed on Saturday, September 23, 2017 18:06:57

     

    Abraço :thumbsup:

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Baixe Security Check, by glax24 e salve em sua Área de trabalho (Desktop).

     

    Execute o arquivo como Administrador

    • Aguarde enquanto a ferramenta faz o exame.
    • Ao final salve log como SecurityCheck.html
    • Abra o arquivo com o bloco de notas;
    • Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

    Abraços :D

    • Curtir 1

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Boa noite @diego_moicano

     

    Segue o log:

     

    SecurityCheck by glax24 & Severnyj v.1.4.0.52 [25.07.17]
    WebSite: www.safezone.cc
    DateLog: 28.09.2017 18:11:28
    Path starting: C:\Users\gabri\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
    Log directory: C:\SecurityCheck\
    IsAdmin: True
    User: gabri
    VersionXML: 4.50s-22.07.2017
    ___________________________________________________________________________

    Windows 10(6.3.15063) (x64) Core Release: 1703 Lang: English(0409)
    Installation date OS: 28.08.2017 19:58:22
    LicenseStatus: Office 16, Office16HomeStudentR_Grace edition Windows is in Notification mode
    LicenseStatus: Windows(R), Core edition The machine is permanently activated.
    Boot Mode: Normal
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    SystemDrive: C: FS: [NTFS] Capacity: [930.5 Gb] Used: [63.8 Gb] Free: [866.7 Gb]
    ------------------------------- [ Windows ] -------------------------------
    Internet Explorer 11.608.15063.0 [+]
    User Account Control enabled
    Windows Update (wuauserv) - The service is running
    Central de Segurança (wscsvc) - The service is running
    Registro remoto (RemoteRegistry) - The service has stopped
    Descoberta SSDP (SSDPSRV) - The service is running
    Serviços de Área de Trabalho Remota (TermService) - The service has stopped
    Windows Remote Management (WS-Management) (WinRM) - The service has stopped
    ---------------------------- [ Antivirus_WMI ] ----------------------------
    Windows Defender (disabled and up to date)
    Malwarebytes (enabled and up to date)
    McAfee VirusScan (enabled)
    ---------------------------- [ Firewall_WMI ] -----------------------------
    McAfee Firewall
    --------------------------- [ AntiSpyware_WMI ] ---------------------------
    Malwarebytes (enabled and up to date)
    Windows Defender (disabled and up to date)
    McAfee VirusScan (enabled)
    ---------------------- [ AntiVirusFirewallInstall ] -----------------------
    McAfee LiveSafe v.16.0.3
    McAfee WebAdvisor v.4.0.161
    -------------------------- [ SecurityUtilities ] --------------------------
    Malwarebytes versão 3.2.2.2029 v.3.2.2.2029
    --------------------------- [ OtherUtilities ] ----------------------------
    WinRAR 5.50 (32-bit) v.5.50.0 [+]
    ------------------------------- [ Browser ] -------------------------------
    Google Chrome v.61.0.3163.100 [+]
    --------------------------- [ RunningProcess ] ----------------------------
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe v.61.0.3163.100
    ------------------ [ AntivirusFirewallProcessServices ] -------------------
    C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe v.3.0.0.1169
    Malwarebytes Service (MBAMService) - The service is running
    C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.1.0.556
    C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.7.0.521
    McAfee Validation Trust Protection Service (mfevtp) - The service is running
    C:\Windows\System32\mfevtps.exe
    C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe v.1.5.0.4974
    McAfee Firewall Core Service (mfefire) - The service is running
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe v.15.7.0.521
    McAfee AP Service (McAPExe) - The service is running
    C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe v.7.3.158.0
    McAfee Personal Firewall Service (McMPFSvc) - The service is running
    C:\Program Files\Common Files\McAfee\platform\mcsvchost\McSvHost.exe v.6.4.4016.0
    C:\Program Files\Common Files\McAfee\platform\McUICnt.exe v.9.1.151.0
    McAfee CSP Service (mccspsvc) - The service is running
    C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe v.2.5.312.0
    McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) - The service is running
    C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe v.4.0.6.161
    McAfee Service Controller (mfemms) - The service is running
    C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.7.0.521
    McAfee Module Core Service (ModuleCoreService) - The service is running
    C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe v.2.0.104.0
    McAfee Home Network (HomeNetSvc) - The service is running
    McAfee Platform Services (mcpltsvc) - The service is running
    McAfee Proxy Service (McProxy) - The service is running
    McAfee Boot Delay Start Service (McBootDelayStartSvc) - The service is running
    McAfee Platform Services (mcpltsvc) - The service is running
    C:\Program Files\Windows Defender\MSASCuiL.exe v.4.11.15063.0
    Serviço Windows Defender Antivirus (WinDefend) - The service has stopped
    Serviço de Inspeção de Rede do Windows Defender Antivirus (WdNisSvc) - The service has stopped
    ----------------------------- [ End of Log ] ------------------------------
     

    Abraço :thumbsup:

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Caro @Gabriel Bernardes de Almeida

     

    Como está seu Windows?

     

    # Etapa nº 1 #

     

    Baixe o Delfix by Xplode e salve na sua área de trabalho.

     

    Clique duas vezes no delfix.exe para executá-lo. Marque as caixas conforme imagem.

     

    ** Usuários do Windows Vista ou Windows 7 clique com o direito sobre o arquivo delfix.exe, depois clique em execadmin.png.

     

    2mez6ld.png

     

    Clique no botão Executar.

     

    Ao final será gerado um log, mas não é necessário postar.

    # Etapa nº 2 #
     

    O Ccleaner é um excelente utilitário de limpeza para o computador.

     

    Faça o download dele aqui Ccleaner

     

    • Após a instalação vá até o local onde o programa foi instalado, geralmente em C:\Arquivos de programas\CCleaner.
    • Clique duas vezes nesta pasta;
    • Numa área vazia desta janela, clique com o botão direito do mouse e escolha Novo > pasta e crie uma nova pasta;
    • Coloque o nome de backups.
    • Abra o programa e clique em Executar Limpeza;
    • Clique no botão Registro > Procurar Erros > Corrigir erro(s) seleciona(s)...
    • Observação: Não se esqueça de aceitar o backup das correções, e salvá-los nas pasta criada acima!

    Abraços :D

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    Crie uma conta ou entre para comentar

    Você precisar ser um membro para fazer um comentário






    Sobre o Clube do Hardware

    No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas publicações sobre tecnologia do Brasil. Leia mais

    Direitos autorais

    Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

    ×