Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-01-2017
Ran by greenhorn (administrator) on HOSKINSON (13-01-2017 17:43:59)
Running from C:\Users\greenhorn\Desktop
Loaded Profiles: UpdatusUser & greenhorn (Available Profiles: UpdatusUser & greenhorn)
Platform: Windows 10 Home Version 1511 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Suo12_StartupManager.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Tablet Driver) C:\Windows\System32\drivers\WTSrv.exe
() C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Tablet Driver) C:\Windows\SysWOW64\WTClient.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\AutoSweep.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\4.1.0\Scheduler.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(forum.viry.cz) C:\Users\greenhorn\Desktop\FRSTLauncher.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
() C:\Windows\vsnpstd3.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
() C:\Windows\tsnpstd3.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-18] (NVIDIA Corporation)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-11-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-11-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [164112 2015-05-16] (IvoSoft)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945672 2015-07-27] (Synaptics Incorporated)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [snpstd3] => C:\WINDOWS\vsnpstd3.exe [843776 2006-09-18] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [tsnpstd3] => C:\WINDOWS\tsnpstd3.exe [368640 2007-06-15] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-2946792676-692352388-3923824208-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\...\MountPoints2: {86cee49e-13df-11e5-8261-d07e35262bd0} - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\...\MountPoints2: {c6ecac66-21d5-11e6-82b4-68f72817cfaa} - "F:\Startme.exe" 
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} =>  -> No File
ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} =>  -> No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{33f388c0-c388-4615-9bf5-99c916630396}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131219687435732795&GUID=7626F7ED-724C-4C0B-8C0B-8E86A686CFE6
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131219687435741898&GUID=7626F7ED-724C-4C0B-8C0B-8E86A686CFE6
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131187718036221211&GUID=7626F7ED-724C-4C0B-8C0B-8E86A686CFE6
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2946792676-692352388-3923824208-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131187718036192808&GUID=7626F7ED-724C-4C0B-8C0B-8E86A686CFE6
HKU\S-1-5-21-2946792676-692352388-3923824208-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-21-2946792676-692352388-3923824208-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://seznam.cz/
HKU\S-1-5-21-2946792676-692352388-3923824208-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> DefaultScope {7F8F5F55-8845-4FAD-B307-B7AC5D6B8373} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {3057A6DB-97FE-4EC0-B77B-90045B7A60D0} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {3200DF61-BD9A-4725-B590-EFEEA495A807} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {7F8F5F55-8845-4FAD-B307-B7AC5D6B8373} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {9A04B138-3EBD-4D09-9F18-1FE1BB7FEA11} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {B3D942C7-A962-4082-934D-9A05C578ACB2} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {B902897A-C5E8-4F8C-90A0-F6B8220B6C63} URL = hxxp://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {C5B81876-2C5B-47AC-9C85-926546BB738F} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {EC34A05E-D314-4D05-894C-13C1A536EB18} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> {F8773F11-19B5-4B4A-B93A-C7C653085488} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2017-01-06] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2017-01-06] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2017-01-06] (Oracle Corporation)
BHO-x32: IObit Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2016-08-03] (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2017-01-06] (Oracle Corporation)
BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
Toolbar: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> No Name - {2C4F22C7-0CB9-4CBD-B405-2C8D953361F1} -  No File
Toolbar: HKU\S-1-5-21-2946792676-692352388-3923824208-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll [2016-08-29] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll [2016-08-29] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll [2016-08-29] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll [2016-08-29] (McAfee, Inc.)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-09-11] ()
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2017-01-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2017-01-06] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-09-11] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2017-01-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2017-01-06] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-09-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-09-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

Opera: 
=======
OPR StartupUrls:  "hxxp://Google.com/h?eq=U0EeCFZVBB8SRggSclhcBVgURRhAdg5eTA1CQwIOIgheABREE1MXJFsNUwpJE1EFIk0FA1oDB0VXfV5bFElXTwhuL1ddGG8YSlxNJw==" 
OPR Extension: (Translator) - C:\Users\greenhorn\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnbpedcoekjafichoehopgaaldogogch [2017-01-11]
OPR Extension: (Bookmarks by the Side) - C:\Users\greenhorn\AppData\Roaming\Opera Software\Opera Stable\Extensions\nfmcmkgigcijhkhpogobfhkdokdecjmb [2017-01-11]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AdvancedSystemCareService10; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [462624 2016-12-12] (IObit)
S3 Ext2Srv; C:\WINDOWS\SysWOW64\Ext2Srv.EXE [68608 2016-09-11] (www.ext2fsd.com) [File not signed]
S3 GSService; C:\windows\SysWOW64\GSService.exe [444640 2014-07-28] ()
R2 ibtsiva.exe; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [121288 2014-08-14] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1600800 2016-10-21] (IObit)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoPAWDService; C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe [133440 2014-11-28] ()
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-11-28] (Lenovo(beijing) Limited)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
S3 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [161536 2016-08-29] (McAfee, Inc.)
S3 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [321520 2014-11-28] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [338416 2014-11-28] (Lenovo)
S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-07-27] (Synaptics Incorporated)
S3 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2017-01-06] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-01-06] (Microsoft Corporation)
R2 WinTabService; C:\windows\System32\Drivers\WTSRV.EXE [69632 2008-12-15] (Tablet Driver) [File not signed]
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2015-06-28] (Disc Soft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [744072 2009-07-26] (www.ext2fsd.com)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-01-06] (REALiX(tm))
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [263952 2015-07-14] (Intel Corporation)
S4 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-04-01] (IObit)
R3 KMDFVirtualKbd; C:\WINDOWS\System32\drivers\KMDFVirtualKbd.sys [22264 2014-08-05] ()
R3 KMDFVirtualMouse; C:\WINDOWS\System32\drivers\KMDFVirtualMouse.sys [21240 2014-08-05] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2017-01-12] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [102856 2017-01-13] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-01-13] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [250816 2017-01-13] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2017-01-13] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2015-10-30] (Intel Corporation)
R3 PCWinSoft; C:\WINDOWS\system32\DRIVERS\scrcamhrdrv_x64.sys [241800 2012-10-11] (Windows (R) Server 2003 DDK provider)
R2 PfFilter; C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [39104 2015-03-10] (IObit Information Technology)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-07-27] (IObit.com)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-07-27] (Synaptics Incorporated)
R3 SNP2UVC; C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [3481696 2015-06-30] (Sonix Co. Ltd.)
S3 SNPSTD3; C:\WINDOWS\system32\DRIVERS\snpstd3.sys [10503168 2007-05-02] (Sonix Co. Ltd.)
S3 SNPSTD3; C:\Windows\SysWOW64\DRIVERS\snpstd3.sys [10222720 2007-05-02] (Sonix Co. Ltd.)
R1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S1 asgeksda; \??\C:\WINDOWS\system32\drivers\asgeksda.sys [X]
S3 cpuz138; \??\C:\Users\GREENH~1\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-13 17:44 - 2017-01-13 17:44 - 00000258 __RSH C:\ProgramData\ntuser.pol
2017-01-13 17:43 - 2017-01-13 17:43 - 00023795 _____ C:\Users\greenhorn\Desktop\FRST.txt
2017-01-13 17:42 - 2017-01-13 17:42 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-13 05:16 - 2017-01-13 05:16 - 00157627 _____ C:\Users\greenhorn\Desktop\mbam.txt
2017-01-12 21:41 - 2017-01-12 21:41 - 00006847 _____ C:\Users\greenhorn\Desktop\log.7z
2017-01-12 21:31 - 2017-01-13 17:41 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-01-12 21:31 - 2017-01-13 17:39 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-01-12 21:31 - 2017-01-13 17:39 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-01-12 21:31 - 2017-01-13 17:39 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-01-12 21:31 - 2017-01-12 21:31 - 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-01-12 21:31 - 2017-01-12 21:31 - 00001931 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-12 21:31 - 2017-01-12 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-12 21:31 - 2017-01-12 21:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-12 21:31 - 2017-01-12 21:31 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-12 21:31 - 2016-12-14 12:55 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-01-12 20:50 - 2017-01-12 20:50 - 00003161 _____ C:\Users\greenhorn\Desktop\AdwCleaner[S5].7z
2017-01-12 20:48 - 2017-01-12 20:48 - 00003042 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (greenhorn)
2017-01-12 20:42 - 2017-01-12 20:42 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-01-12 20:41 - 2017-01-12 20:41 - 00000000 ____H C:\asc_rdflag
2017-01-12 20:37 - 2017-01-12 20:37 - 00025562 _____ C:\Users\greenhorn\Desktop\AdwCleaner[S5].txt
2017-01-12 20:15 - 2017-01-12 20:15 - 00030954 _____ C:\Users\greenhorn\Desktop\Logy.7z
2017-01-12 20:14 - 2017-01-12 20:14 - 00000000 ____D C:\Users\greenhorn\Desktop\Logy
2017-01-12 19:02 - 2017-01-13 17:43 - 00000000 ____D C:\FRST
2017-01-12 18:56 - 2017-01-12 18:56 - 00112640 _____ (forum.viry.cz) C:\Users\greenhorn\Desktop\FRSTLauncher.exe
2017-01-12 18:55 - 2017-01-12 18:55 - 02419200 _____ (Farbar) C:\Users\greenhorn\Desktop\FRST64.exe
2017-01-12 18:34 - 2017-01-12 18:34 - 00000000 ____D C:\Users\greenhorn\Desktop\Sia
2017-01-11 22:05 - 2016-12-22 23:48 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-01-11 22:05 - 2016-12-22 23:48 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-11 22:04 - 2017-01-11 22:04 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2017-01-11 22:04 - 2017-01-11 22:04 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2017-01-09 04:42 - 2017-01-09 04:44 - 00000000 ____D C:\Intel
2017-01-09 04:39 - 2017-01-09 04:39 - 00000000 ___HD C:\$WINDOWS.~BT
2017-01-08 21:53 - 2017-01-08 21:53 - 00000000 ____D C:\IObit
2017-01-08 17:34 - 2017-01-08 17:35 - 00002236 _____ C:\Users\greenhorn\Desktop\Rkill.txt
2017-01-08 14:14 - 2016-10-12 14:12 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll.113
2017-01-07 20:20 - 2017-01-07 20:20 - 00844994 _____ C:\Users\greenhorn\Desktop\ntdll.zip
2017-01-07 12:43 - 2017-01-07 12:43 - 00228112 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtusb.sys.28
2017-01-07 11:50 - 2017-01-07 11:50 - 00418784 _____ (Realsil Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtsUer.sys.52
2017-01-07 11:49 - 2017-01-07 11:49 - 01771872 _____ (Sonix Tech. Co., Ltd.) C:\WINDOWS\system32\Drivers\snp2uvc.sys.53
2017-01-07 11:49 - 2017-01-07 11:49 - 00632936 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys.56
2017-01-07 11:41 - 2017-01-07 11:41 - 01535680 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys.11
2017-01-07 08:27 - 2017-01-12 18:38 - 00000000 ____D C:\Users\greenhorn\Desktop\Ludovico Einaudi
2017-01-07 08:27 - 2017-01-11 20:45 - 00000000 ____D C:\Program Files (x86)\7-Zip
2017-01-06 23:52 - 2017-01-06 23:52 - 00001261 _____ C:\Users\greenhorn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Defrag.lnk
2017-01-06 23:05 - 2017-01-06 23:05 - 00003268 _____ C:\WINDOWS\System32\Tasks\SmartDefrag_AutoAnalyze
2017-01-06 23:05 - 2017-01-06 23:05 - 00003104 _____ C:\WINDOWS\System32\Tasks\SmartDefrag_Update
2017-01-06 23:05 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll
2017-01-06 22:54 - 2017-01-11 21:19 - 00000000 ____D C:\KMPlayer
2017-01-06 22:54 - 2017-01-11 21:03 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2017-01-06 22:54 - 2017-01-06 22:54 - 00000654 _____ C:\Users\greenhorn\Desktop\KMPlayer.lnk
2017-01-06 22:20 - 2017-01-11 20:49 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-01-06 22:12 - 2017-01-06 22:12 - 28851216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 22373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 19350016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 18670080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 14258688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 12590080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 07839232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 05658624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 04078592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 03663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02938408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2017-01-06 22:12 - 2017-01-06 22:12 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2017-01-06 22:12 - 2017-01-06 22:12 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-01-06 22:12 - 2017-01-06 22:12 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02062336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-01-06 22:12 - 2017-01-06 22:12 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01349632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 01017024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2017-01-06 22:12 - 2017-01-06 22:12 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-01-06 22:12 - 2017-01-06 22:12 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00847648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00709176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00588328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2017-01-06 22:12 - 2017-01-06 22:12 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2017-01-06 22:12 - 2017-01-06 22:12 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-01-06 22:12 - 2017-01-06 22:12 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00305808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-01-06 22:12 - 2017-01-06 22:12 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2017-01-06 22:12 - 2017-01-06 22:12 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 11544576 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 09920512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 07536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 07468384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06976512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 05325824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 05240952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03692040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03549696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 03081216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02607336 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02444800 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02054144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01988440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys.18
2017-01-06 22:11 - 2017-01-06 22:11 - 01988440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01824272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01813504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01777280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01568256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01562624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll.116
2017-01-06 22:11 - 2017-01-06 22:11 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01522672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01399216 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-01-06 22:11 - 2017-01-06 22:11 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01142560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01098648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01083648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-01-06 22:11 - 2017-01-06 22:11 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00875480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00845568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00836752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-01-06 22:11 - 2017-01-06 22:11 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00775336 _____ C:\WINDOWS\SysWOW64\locale.nls
2017-01-06 22:11 - 2017-01-06 22:11 - 00775336 _____ C:\WINDOWS\system32\locale.nls
2017-01-06 22:11 - 2017-01-06 22:11 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00766464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2017-01-06 22:11 - 2017-01-06 22:11 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00712032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00636296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00569752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00546968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-01-06 22:11 - 2017-01-06 22:11 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2017-01-06 22:11 - 2017-01-06 22:11 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys.67
2017-01-06 22:11 - 2017-01-06 22:11 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00445873 _____ C:\WINDOWS\system32\ApnDatabase.xml
2017-01-06 22:11 - 2017-01-06 22:11 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00439136 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2017-01-06 22:11 - 2017-01-06 22:11 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00376528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-01-06 22:11 - 2017-01-06 22:11 - 00295776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00273760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00256704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-01-06 22:11 - 2017-01-06 22:11 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00159640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00125280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys.23
2017-01-06 22:11 - 2017-01-06 22:11 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00075448 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys.63
2017-01-06 22:11 - 2017-01-06 22:11 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-01-06 22:11 - 2017-01-06 22:11 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-01-06 22:11 - 2017-01-06 22:11 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys
2017-01-06 22:11 - 2017-01-06 22:11 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2017-01-06 22:06 - 2017-01-06 22:06 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2017-01-06 21:24 - 2017-01-06 21:24 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll
2017-01-06 21:24 - 2017-01-06 21:24 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-01-06 21:24 - 2017-01-06 21:23 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-01-06 19:08 - 2017-01-06 19:08 - 00000000 ____D C:\SUPERDelete
2017-01-06 19:07 - 2017-01-11 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-01-06 19:04 - 2017-01-11 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCommander XE
2017-01-06 19:04 - 2017-01-06 19:04 - 00001180 _____ C:\Users\greenhorn\Desktop\FreeCommander XE.lnk
2017-01-06 18:53 - 2017-01-11 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4
2017-01-06 18:53 - 2017-01-06 18:53 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS.115
2017-01-06 18:53 - 2017-01-06 18:53 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-01-06 18:53 - 2017-01-06 18:53 - 00003390 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2017-01-05 21:14 - 2017-01-05 21:14 - 00000000 ____D C:\$SysReset
2017-01-05 20:41 - 2017-01-05 20:41 - 00000000 ____D C:\48de0bd189c34aadc2
2017-01-05 20:12 - 2017-01-05 20:12 - 00000000 ____D C:\56f66d4312b2aaa0bbdc96ce635237
2017-01-05 19:49 - 2017-01-05 19:49 - 00000000 ____D C:\526bca8f0d4590aeddc6e9
2017-01-05 19:38 - 2017-01-05 19:38 - 00000000 ____D C:\8648ca5cd658e815742913f3def501
2017-01-05 17:04 - 2017-01-05 17:04 - 00000000 ____D C:\8e2002f5d5a81859b5ad24000ed596
2017-01-04 22:28 - 2017-01-04 22:28 - 00000000 ____D C:\1f0737f64dd715e40e0d1ecb8de65220
2017-01-04 22:01 - 2017-01-04 22:01 - 00000000 ____D C:\e4f3e3e4f3f0d7ff3617698105
2017-01-04 18:28 - 2017-01-04 18:28 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\FcContextMenu64
2017-01-03 20:24 - 2017-01-06 17:58 - 00000000 ___RD C:\Users\greenhorn\Hudba
2017-01-03 20:19 - 2017-01-03 20:19 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\FreeCommander
2017-01-03 20:17 - 2017-01-11 21:03 - 00000000 ____D C:\Program Files (x86)\FreeCommander XE
2017-01-03 20:17 - 2017-01-11 19:08 - 00000000 ____D C:\Users\greenhorn\AppData\Local\FreeCommanderXE
2017-01-03 18:37 - 2017-01-11 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2017-01-03 18:36 - 2017-01-11 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2017-01-02 22:41 - 2017-01-11 19:47 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-01-02 21:23 - 2017-01-02 21:23 - 00000000 ____D C:\WINDOWS\IObit
2017-01-02 19:49 - 2017-01-11 21:10 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-01-02 19:49 - 2017-01-11 19:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2017-01-02 19:49 - 2017-01-02 19:49 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\SUPERAntiSpyware.com
2016-12-31 18:39 - 2017-01-06 22:23 - 05615616 _____ C:\WINDOWS\system32\config\DRIVERS.iodefrag.bak
2016-12-31 18:01 - 2017-01-06 18:53 - 00000306 _____ C:\WINDOWS\Tasks\Uninstaller_SkipUac_greenhorn.job
2016-12-31 18:01 - 2016-12-31 18:01 - 00002508 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_greenhorn
2016-12-31 18:00 - 2016-12-31 18:00 - 00003118 _____ C:\WINDOWS\System32\Tasks\ASC10_PerformanceMonitor
2016-12-31 18:00 - 2016-12-31 18:00 - 00002920 _____ C:\WINDOWS\System32\Tasks\ASC10_SkipUac_greenhorn
2016-12-31 18:00 - 2016-12-31 18:00 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}
2016-12-31 17:57 - 2016-12-31 17:59 - 51720600 _____ (IObit ) C:\Users\greenhorn\Downloads\advanced-systemcare-setup.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-13 17:43 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-13 17:42 - 2016-03-13 10:29 - 01893162 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-13 17:42 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2017-01-13 17:42 - 2015-06-09 22:46 - 00000000 __SHD C:\Users\greenhorn\IntelGraphicsProfiles
2017-01-13 17:42 - 2014-11-28 10:51 - 00847602 _____ C:\WINDOWS\system32\perfh005.dat
2017-01-13 17:42 - 2014-11-28 10:51 - 00173096 _____ C:\WINDOWS\system32\perfc005.dat
2017-01-13 17:38 - 2016-03-13 10:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-13 17:37 - 2016-03-13 10:15 - 00000000 ____D C:\Users\greenhorn
2017-01-13 17:37 - 2015-10-30 07:28 - 02097152 ___SH C:\WINDOWS\system32\config\BBI
2017-01-13 17:37 - 2015-06-22 16:43 - 00000000 ____D C:\Users\greenhorn\AppData\Local\ClassicShell
2017-01-13 17:37 - 2015-06-09 23:51 - 00004206 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D8E2A4B4-225A-4C22-977E-D9655C5606F6}
2017-01-13 05:15 - 2015-10-30 08:18 - 00001578 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
2017-01-13 05:12 - 2015-06-20 14:51 - 00000000 ____D C:\ProgramData\Ashampoo
2017-01-12 20:48 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-12 20:41 - 2016-10-13 16:02 - 90042368 _____ C:\WINDOWS\system32\config\SOFTWARE.iodefrag.bak
2017-01-12 20:41 - 2016-10-13 16:02 - 00438272 _____ C:\WINDOWS\system32\config\DEFAULT.iodefrag.bak
2017-01-12 20:41 - 2016-10-13 16:02 - 00065536 _____ C:\WINDOWS\system32\config\SAM.iodefrag.bak
2017-01-12 20:41 - 2016-10-13 16:02 - 00028672 _____ C:\WINDOWS\system32\config\SECURITY.iodefrag.bak
2017-01-12 20:41 - 2016-03-13 10:15 - 00000000 ____D C:\Users\UpdatusUser
2017-01-12 20:37 - 2015-06-21 18:24 - 00000000 ____D C:\AdwCleaner
2017-01-11 22:17 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-11 22:11 - 2015-06-17 18:38 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-11 22:05 - 2015-06-17 18:38 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-11 21:59 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-01-11 21:34 - 2016-03-24 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4
2017-01-11 21:34 - 2015-06-24 19:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle Studio 14
2017-01-11 21:10 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Defender
2017-01-11 21:03 - 2016-09-17 16:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-01-11 21:03 - 2016-09-17 16:46 - 00000000 ____D C:\Program Files\CCleaner
2017-01-11 21:03 - 2016-09-17 12:36 - 00000000 ____D C:\Users\greenhorn\Downloads\VirtualDub-1.10.4-AMD64
2017-01-11 21:03 - 2016-08-31 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2017-01-11 21:03 - 2016-08-12 19:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperEZ Wave Editor Pro
2017-01-11 21:03 - 2016-08-12 19:02 - 00000000 ____D C:\Program Files (x86)\SuperEZ Wave Editor Pro
2017-01-11 21:03 - 2016-07-10 19:19 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Yousician Launcher
2017-01-11 21:03 - 2016-07-10 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yousician Launcher
2017-01-11 21:03 - 2016-06-23 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KB Piano 2
2017-01-11 21:03 - 2016-06-23 16:09 - 00000000 ____D C:\Program Files (x86)\KB Piano 2
2017-01-11 21:03 - 2016-06-01 16:40 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chord Pickout 3.0
2017-01-11 21:03 - 2016-06-01 16:40 - 00000000 ____D C:\Program Files (x86)\Chord Pickout 3.0
2017-01-11 21:03 - 2016-05-25 19:54 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\MyPhoneExplorer
2017-01-11 21:03 - 2016-05-25 19:54 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2017-01-11 21:03 - 2016-05-13 16:26 - 00000000 ____D C:\Users\Public\Documents\Heimdal Security
2017-01-11 21:03 - 2016-04-06 16:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Filter Forge 4
2017-01-11 21:03 - 2016-04-06 16:39 - 00000000 ____D C:\Program Files (x86)\Filter Forge 4
2017-01-11 21:03 - 2016-03-31 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epubor
2017-01-11 21:03 - 2016-03-28 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Folder
2017-01-11 21:03 - 2016-03-23 21:07 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\ProductData
2017-01-11 21:03 - 2016-03-23 21:07 - 00000000 ____D C:\ProgramData\ProductData
2017-01-11 21:03 - 2016-03-23 21:06 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\IObit
2017-01-11 21:03 - 2016-03-23 21:06 - 00000000 ____D C:\Users\greenhorn\AppData\LocalLow\IObit
2017-01-11 21:03 - 2016-03-23 21:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2017-01-11 21:03 - 2016-03-23 21:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
2017-01-11 21:03 - 2016-03-23 21:05 - 00000000 ____D C:\ProgramData\IObit
2017-01-11 21:03 - 2016-03-14 21:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2017-01-11 21:03 - 2016-03-14 21:10 - 00000000 ____D C:\Program Files\Dolby Digital Plus
2017-01-11 21:03 - 2016-03-13 10:20 - 00000000 ____D C:\Users\Default\AppData\Local\Pokki
2017-01-11 21:03 - 2016-03-13 10:20 - 00000000 ____D C:\Users\Default User\AppData\Local\Pokki
2017-01-11 21:03 - 2016-03-13 10:11 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-01-11 21:03 - 2016-01-05 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator
2017-01-11 21:03 - 2016-01-05 19:03 - 00000000 ____D C:\Program Files (x86)\UnHackMe
2017-01-11 21:03 - 2015-11-09 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3 Toolkit
2017-01-11 21:03 - 2015-11-09 17:34 - 00000000 ____D C:\MP3Toolkit
2017-01-11 21:03 - 2015-11-03 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inpaint
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 __RSD C:\WINDOWS\Media
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\Nui
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\setup
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\icsxml
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\L2Schemas
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\IME
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-01-11 21:03 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-01-11 21:03 - 2015-10-30 07:31 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-01-11 21:03 - 2015-10-30 07:31 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-01-11 21:03 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-01-11 21:03 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-01-11 21:03 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\servicing
2017-01-11 21:03 - 2015-10-26 19:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR Password Unlocker
2017-01-11 21:03 - 2015-10-11 08:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Watermark Pro
2017-01-11 21:03 - 2015-10-10 08:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sothink Media Toolkit
2017-01-11 21:03 - 2015-10-10 08:05 - 00000000 ____D C:\Program Files (x86)\Sothink Media Toolkit
2017-01-11 21:03 - 2015-10-06 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStitcher
2017-01-11 21:03 - 2015-10-06 16:42 - 00000000 ____D C:\Program Files\PhotoStitcher
2017-01-11 21:03 - 2015-08-25 17:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 12
2017-01-11 21:03 - 2015-08-24 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
2017-01-11 21:03 - 2015-07-01 18:23 - 00000000 ____D C:\Program Files (x86)\Google
2017-01-11 21:03 - 2015-06-20 09:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-01-11 21:03 - 2015-06-20 09:19 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\PSpad
2017-01-11 21:03 - 2014-11-28 11:02 - 00000000 ____D C:\Program Files\Lenovo PhotoMasterImport
2017-01-11 21:03 - 2014-11-28 11:00 - 00000000 ____D C:\Program Files\Lenovo PhoneCompanion
2017-01-11 21:03 - 2014-11-28 11:00 - 00000000 ____D C:\Program Files (x86)\Lenovo PhoneCompanion
2017-01-11 21:03 - 2014-11-28 10:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 10
2017-01-11 21:03 - 2014-11-28 10:52 - 00000000 ____D C:\ProgramData\OneKey Recovery
2017-01-11 21:03 - 2014-11-28 10:28 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2017-01-11 21:03 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-01-11 21:03 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\MediaViewer
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\dsc
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\es-MX
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ras
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ias
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\et-EE
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\es-MX
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-01-11 21:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Com
2017-01-11 21:01 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-01-11 21:01 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-01-11 21:01 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\downlevel
2017-01-11 21:01 - 2014-11-28 10:50 - 00000000 ____D C:\WINDOWS\SysWOW64\cs
2017-01-11 21:01 - 2014-11-28 10:50 - 00000000 ____D C:\WINDOWS\system32\cs
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Cursors
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\addins
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System
2017-01-11 21:00 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\Services
2017-01-11 21:00 - 2015-06-09 22:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-01-11 20:49 - 2016-03-04 20:59 - 00000000 ____D C:\WINDOWS\System32\Tasks\Symantec
2017-01-11 20:49 - 2015-10-30 10:03 - 00000000 ____D C:\WINDOWS\SKB
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\system32\winrm
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\system32\slmgr
2017-01-11 20:49 - 2015-10-30 10:02 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-01-11 20:49 - 2015-10-30 08:26 - 00000000 ____D C:\WINDOWS\Setup
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Licenses
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SystemResources
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SystemApps
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Licenses
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME
2017-01-11 20:49 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\System
2017-01-11 20:49 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\SMI
2017-01-11 20:49 - 2015-06-17 18:22 - 00000000 ____D C:\WINDOWS\SysWOW64\reaper_data
2017-01-11 20:49 - 2014-11-28 10:52 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2017-01-11 20:49 - 2014-11-28 10:50 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-01-11 20:49 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2017-01-11 20:49 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2017-01-11 20:48 - 2015-10-30 10:03 - 00000000 ____D C:\WINDOWS\OCR
2017-01-11 20:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\schemas
2017-01-11 20:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Resources
2017-01-11 20:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\PLA
2017-01-11 20:48 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod
2017-01-11 20:47 - 2016-08-31 16:59 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\ADBDriverInstaller
2017-01-11 20:47 - 2016-04-14 17:24 - 00000000 ____D C:\Users\Public\Documents\Reallusion
2017-01-11 20:47 - 2016-03-13 10:36 - 00000000 ____D C:\Users\greenhorn\AppData\Local\TileDataLayer
2017-01-11 20:47 - 2016-03-04 18:40 - 00000000 ____D C:\Users\greenhorn\AppData\Local\PokerStars.EU
2017-01-11 20:47 - 2016-01-29 17:46 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Icecream
2017-01-11 20:47 - 2016-01-05 19:06 - 00000000 ____D C:\Users\greenhorn\Documents\RegRun2
2017-01-11 20:47 - 2015-12-14 17:53 - 00000000 ____D C:\Users\greenhorn\Projects Series
2017-01-11 20:47 - 2015-12-14 17:53 - 00000000 ____D C:\Users\greenhorn\Color Projects Pro
2017-01-11 20:47 - 2015-10-30 19:49 - 00000000 ____D C:\Users\Public\Documents\Wondershare
2017-01-11 20:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InfusedApps
2017-01-11 20:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help
2017-01-11 20:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Globalization
2017-01-11 20:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Branding
2017-01-11 20:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\appcompat
2017-01-11 20:47 - 2015-08-25 18:05 - 00000000 ___RD C:\Users\greenhorn\Documents\Notes
2017-01-11 20:47 - 2015-07-27 16:54 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WonderFox Soft
2017-01-11 20:47 - 2015-06-30 18:24 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Downloaded Installations
2017-01-11 20:47 - 2015-06-28 08:50 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Seznam.cz
2017-01-11 20:47 - 2015-06-25 19:27 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Skype
2017-01-11 20:47 - 2015-06-24 19:24 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Readon_Technology
2017-01-11 20:47 - 2015-06-22 17:17 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Wondershare
2017-01-11 20:47 - 2015-06-20 13:52 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\CoffeeCup Software
2017-01-11 20:47 - 2015-06-20 08:55 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Audacity
2017-01-11 20:47 - 2015-06-17 17:20 - 00000000 ____D C:\Users\greenhorn\Documents\Opera 12.16
2017-01-11 20:47 - 2015-06-10 04:49 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\WebApp
2017-01-11 20:47 - 2015-06-09 22:47 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2017-01-11 20:47 - 2015-06-09 22:47 - 00000000 ____D C:\Users\greenhorn\AppData\Local\VirtualStore
2017-01-11 20:47 - 2015-06-09 22:46 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Packages
2017-01-11 20:47 - 2014-11-28 10:52 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2017-01-11 20:46 - 2016-10-26 18:08 - 00000000 ____D C:\ProgramData\Tencent
2017-01-11 20:46 - 2016-10-22 15:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2017-01-11 20:46 - 2016-09-17 13:50 - 00000000 ____D C:\ProgramData\Avira
2017-01-11 20:46 - 2016-09-17 13:50 - 00000000 ____D C:\ProgramData\AVAST Software
2017-01-11 20:46 - 2016-07-21 16:18 - 00000000 ____D C:\Users\greenhorn\AppData\Local\DicoLab
2017-01-11 20:46 - 2016-05-13 16:22 - 00000000 ____D C:\ProgramData\Heimdal Security
2017-01-11 20:46 - 2016-04-14 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reallusion
2017-01-11 20:46 - 2016-03-15 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Artisteer 4
2017-01-11 20:46 - 2016-03-15 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2017-01-11 20:46 - 2016-03-15 20:03 - 00000000 ____D C:\Program Files\7-Zip
2017-01-11 20:46 - 2016-03-13 18:51 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-01-11 20:46 - 2016-03-13 18:51 - 00000000 ____D C:\Program Files\MSBuild
2017-01-11 20:46 - 2016-03-13 10:11 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-11 20:46 - 2016-03-13 10:11 - 00000000 ____D C:\Program Files\CONEXANT
2017-01-11 20:46 - 2016-03-13 10:10 - 00000000 ____D C:\Program Files\Intel
2017-01-11 20:46 - 2016-03-04 20:39 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2017-01-11 20:46 - 2016-03-04 18:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.EU
2017-01-11 20:46 - 2016-01-29 17:44 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Icecream
2017-01-11 20:46 - 2016-01-29 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream PDF Split and Merge
2017-01-11 20:46 - 2016-01-01 13:48 - 00000000 ____D C:\ProgramData\Licenses
2017-01-11 20:46 - 2015-12-27 18:27 - 00000000 ____D C:\Users\greenhorn\AppData\Local\DIAL_GmbH
2017-01-11 20:46 - 2015-12-26 14:58 - 00000000 ____D C:\Program Files\DIAL GmbH
2017-01-11 20:46 - 2015-12-19 13:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiseesoft
2017-01-11 20:46 - 2015-11-15 19:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pdf Editor
2017-01-11 20:46 - 2015-11-03 17:41 - 00000000 ____D C:\Program Files\Inpaint
2017-01-11 20:46 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-01-11 20:46 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows NT
2017-01-11 20:46 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-01-11 20:46 - 2015-10-27 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real-Draw PRO
2017-01-11 20:46 - 2015-10-27 20:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synthesia
2017-01-11 20:46 - 2015-10-18 08:32 - 00000000 ____D C:\ProgramData\ScreenCamera
2017-01-11 20:46 - 2015-10-18 08:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScreenCamera
2017-01-11 20:46 - 2015-10-17 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet
2017-01-11 20:46 - 2015-09-28 16:43 - 00000000 ____D C:\ProgramData\1AVCenter
2017-01-11 20:46 - 2015-09-20 08:07 - 00000000 ____D C:\ProgramData\1AVCapture
2017-01-11 20:46 - 2015-08-25 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
2017-01-11 20:46 - 2015-08-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apex All in One PDF Tools
2017-01-11 20:46 - 2015-08-11 17:02 - 00000000 ____D C:\Program Files\Apex All in One PDF Tools
2017-01-11 20:46 - 2015-07-26 06:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F1 2015
2017-01-11 20:46 - 2015-07-14 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CSE HTML Validator v12.0
2017-01-11 20:46 - 2015-07-01 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topfield
2017-01-11 20:46 - 2015-06-30 18:24 - 00000000 ____D C:\ProgramData\BinaryNow
2017-01-11 20:46 - 2015-06-30 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WOW Slider
2017-01-11 20:46 - 2015-06-30 18:10 - 00000000 ____D C:\Program Files (x86)\WOW Slider
2017-01-11 20:46 - 2015-06-28 08:21 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Disc_Soft_Ltd
2017-01-11 20:46 - 2015-06-26 19:50 - 00000000 ____D C:\Users\greenhorn\AppData\Local\JDownloader 2.0
2017-01-11 20:46 - 2015-06-25 19:27 - 00000000 ____D C:\ProgramData\Skype
2017-01-11 20:46 - 2015-06-25 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-11 20:46 - 2015-06-25 17:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Krita (x64)
2017-01-11 20:46 - 2015-06-25 17:11 - 00000000 ____D C:\Program Files\Krita (x64)
2017-01-11 20:46 - 2015-06-24 18:58 - 00000000 ____D C:\ProgramData\Studio 14
2017-01-11 20:46 - 2015-06-24 18:42 - 00000000 ____D C:\ProgramData\Pinnacle
2017-01-11 20:46 - 2015-06-24 18:39 - 00000000 ____D C:\ProgramData\Studio14Trial
2017-01-11 20:46 - 2015-06-22 17:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2017-01-11 20:46 - 2015-06-22 16:35 - 00000000 ____D C:\ProgramData\ClassicShell
2017-01-11 20:46 - 2015-06-22 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2017-01-11 20:46 - 2015-06-22 16:34 - 00000000 ____D C:\Program Files\Classic Shell
2017-01-11 20:46 - 2015-06-21 09:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoner Callisto 5 FREE
2017-01-11 20:46 - 2015-06-20 19:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPEG Video Wizard DVD 5.0
2017-01-11 20:46 - 2015-06-20 14:23 - 00000000 ___RD C:\Programy
2017-01-11 20:46 - 2015-06-20 13:55 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Just Color Picker
2017-01-11 20:46 - 2015-06-20 09:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPad editor
2017-01-11 20:46 - 2015-06-20 09:14 - 00000000 ____D C:\ProgramData\Baidu
2017-01-11 20:46 - 2015-06-19 16:48 - 00000000 ____D C:\ProgramData\Norton
2017-01-11 20:46 - 2014-11-28 11:03 - 00000000 ____D C:\ProgramData\Energy Manager
2017-01-11 20:46 - 2014-11-28 11:03 - 00000000 ____D C:\Program Files\DIFX
2017-01-11 20:46 - 2014-11-28 11:00 - 00000000 ____D C:\ProgramData\Downloaded Installations
2017-01-11 20:46 - 2014-11-28 10:58 - 00000000 ____D C:\ProgramData\CyberLink
2017-01-11 20:46 - 2014-11-28 10:55 - 00000000 ____D C:\Program Files\CyberLink
2017-01-11 20:46 - 2014-11-28 10:53 - 00000000 ____D C:\ProgramData\McAfee
2017-01-11 20:46 - 2014-11-28 10:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2017-01-11 20:46 - 2014-11-28 10:27 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-11 20:46 - 2014-11-28 10:27 - 00000000 ____D C:\ProgramData\Intel.sav
2017-01-11 20:46 - 2014-11-28 10:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2017-01-11 20:46 - 2014-11-28 10:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-01-11 20:45 - 2016-08-12 19:04 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-01-11 20:45 - 2016-03-15 20:49 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
2017-01-11 20:45 - 2016-03-13 18:51 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-01-11 20:45 - 2016-03-13 10:11 - 00000000 ____D C:\Program Files (x86)\Lenovo
2017-01-11 20:45 - 2016-03-04 18:39 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU
2017-01-11 20:45 - 2016-01-29 17:44 - 00000000 ____D C:\Program Files (x86)\Icecream PDF Split and Merge
2017-01-11 20:45 - 2016-01-05 20:14 - 00000000 ____D C:\@RestoreQuarantine
2017-01-11 20:45 - 2015-12-08 17:37 - 00000000 ____D C:\Program Files (x86)\PDFImpress 10
2017-01-11 20:45 - 2015-11-15 19:04 - 00000000 ____D C:\Program Files (x86)\Pdf Editor
2017-01-11 20:45 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-01-11 20:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows NT
2017-01-11 20:45 - 2015-10-27 21:03 - 00000000 ____D C:\Program Files (x86)\RealDrawPRO4
2017-01-11 20:45 - 2015-10-27 20:49 - 00000000 ____D C:\Program Files (x86)\Synthesia
2017-01-11 20:45 - 2015-10-26 19:13 - 00000000 ____D C:\Program Files (x86)\RAR Password Unlocker
2017-01-11 20:45 - 2015-10-26 18:42 - 00000000 ____D C:\Program Files (x86)\NetMeter
2017-01-11 20:45 - 2015-10-18 08:32 - 00000000 ____D C:\Program Files (x86)\ScreenCamera
2017-01-11 20:45 - 2015-10-17 08:22 - 00000000 ____D C:\Program Files (x86)\TABLET
2017-01-11 20:45 - 2015-10-16 17:59 - 00000000 ____D C:\Program Files (x86)\IQmango 3D Player
2017-01-11 20:45 - 2015-09-27 08:30 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-01-11 20:45 - 2015-08-24 17:10 - 00000000 ____D C:\Program Files (x86)\SopCast
2017-01-11 20:45 - 2015-07-26 05:51 - 00000000 ____D C:\Program Files (x86)\F1 2015
2017-01-11 20:45 - 2015-07-14 17:47 - 00000000 ____D C:\Program Files (x86)\HTMLValidator120
2017-01-11 20:45 - 2015-07-01 17:57 - 00000000 ____D C:\Program Files (x86)\ESTsoft
2017-01-11 20:45 - 2015-07-01 17:45 - 00000000 ____D C:\Program Files (x86)\Topfield
2017-01-11 20:45 - 2015-07-01 17:37 - 00000000 ____D C:\Program Files (x86)\A4DeskPro
2017-01-11 20:45 - 2015-06-25 19:27 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-11 20:45 - 2015-06-24 18:58 - 00000000 ____D C:\Program Files (x86)\Pinnacle
2017-01-11 20:45 - 2015-06-21 15:50 - 00000000 ____D C:\Program Files (x86)\KMPlayer
2017-01-11 20:45 - 2015-06-20 09:19 - 00000000 ____D C:\Program Files (x86)\PSPad editor
2017-01-11 20:45 - 2015-06-20 09:02 - 00000000 ____D C:\Program Files (x86)\Hanz
2017-01-11 20:45 - 2015-06-20 08:55 - 00000000 ____D C:\Program Files (x86)\Audacity
2017-01-11 20:45 - 2015-06-17 18:45 - 00000000 ____D C:\Program Files (x86)\Opera
2017-01-11 20:45 - 2014-11-28 10:18 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-11 20:41 - 2016-09-17 12:48 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-11 20:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\registration
2017-01-11 19:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Web
2017-01-11 19:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Vss
2017-01-11 19:51 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-01-11 19:40 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2017-01-11 19:39 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-11 19:25 - 2015-10-30 10:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-01-11 19:25 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\security
2017-01-11 19:25 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Performance
2017-01-11 19:12 - 2015-07-27 16:55 - 00000000 ____D C:\Users\greenhorn\Documents\WonderFox Soft
2017-01-11 19:12 - 2015-06-17 17:18 - 00000000 ___SD C:\Users\greenhorn\Documents\Weby
2017-01-11 19:11 - 2016-09-17 13:52 - 00000000 ____D C:\Users\greenhorn\AppData\Local\UCBrowser
2017-01-11 19:11 - 2016-03-13 10:38 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Publishers
2017-01-11 19:11 - 2015-10-11 08:51 - 00000000 ____D C:\Users\greenhorn\Documents\AoaoPhoto Digital Studio
2017-01-11 19:11 - 2015-07-14 17:52 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\AI Internet Solutions
2017-01-11 19:11 - 2015-06-25 19:27 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Skype
2017-01-11 19:11 - 2015-06-24 18:19 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Apowersoft
2017-01-11 19:11 - 2015-06-21 18:58 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Mozilla
2017-01-11 19:11 - 2015-06-21 15:54 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Opera Software
2017-01-11 19:11 - 2015-06-20 19:39 - 00000000 ____D C:\Users\greenhorn\AppData\Local\womble
2017-01-11 19:11 - 2015-06-20 09:43 - 00000000 ____D C:\Users\greenhorn\AppData\LocalLow\Oracle
2017-01-11 19:11 - 2015-06-20 09:42 - 00000000 ____D C:\Users\greenhorn\AppData\LocalLow\Sun
2017-01-11 19:11 - 2015-06-18 18:54 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\LibreOffice
2017-01-11 19:11 - 2015-06-17 18:45 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Opera
2017-01-11 19:11 - 2015-06-10 04:49 - 00000000 ____D C:\Users\greenhorn\Documents\CyberLink
2017-01-11 19:11 - 2015-06-10 04:49 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\CyberLink
2017-01-11 19:11 - 2015-06-09 22:47 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Adobe
2017-01-11 19:11 - 2015-06-09 22:46 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\Intel
2017-01-11 19:08 - 2016-10-22 15:14 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Ivideon
2017-01-11 19:08 - 2015-06-17 18:45 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Opera
2017-01-11 19:08 - 2015-06-16 05:20 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Adobe
2017-01-11 19:08 - 2015-06-10 04:49 - 00000000 ____D C:\Users\greenhorn\AppData\Local\Cyberlink
2017-01-11 19:07 - 2015-06-20 09:42 - 00000000 ____D C:\ProgramData\Oracle
2017-01-11 19:07 - 2015-06-19 17:00 - 00000000 ____D C:\ProgramData\TuneUp Software
2017-01-11 19:06 - 2016-03-13 10:11 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-11 19:06 - 2016-03-13 10:11 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-11 19:06 - 2015-12-14 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis
2017-01-11 19:06 - 2015-10-16 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IQmango Pack
2017-01-11 19:05 - 2016-06-23 16:09 - 00000000 ____D C:\ProgramData\KB Piano
2017-01-11 19:05 - 2014-11-28 10:22 - 00000000 ____D C:\ProgramData\Intel
2017-01-11 19:04 - 2016-05-10 16:28 - 00000000 ____D C:\ProgramData\A-PDF
2017-01-11 19:04 - 2016-03-13 10:11 - 00000000 ____D C:\Program Files\Synaptics
2017-01-11 19:04 - 2015-06-20 14:30 - 00000000 ____D C:\Program Files\Zoner
2017-01-11 19:04 - 2014-11-28 10:57 - 00000000 ____D C:\ProgramData\Adobe
2017-01-11 19:03 - 2015-08-25 18:02 - 00000000 ____D C:\Program Files\LibreOffice 5
2017-01-11 19:03 - 2015-06-20 09:42 - 00000000 ____D C:\Program Files\Java
2017-01-11 19:03 - 2014-11-28 10:52 - 00000000 ____D C:\Program Files\Lenovo
2017-01-11 19:02 - 2015-12-14 17:52 - 00000000 ____D C:\Program Files\Franzis
2017-01-11 18:59 - 2016-03-20 19:15 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2017-01-11 18:59 - 2015-12-08 17:37 - 00000000 ____D C:\Program Files\Common Files\BinaryNow
2017-01-11 18:59 - 2015-08-07 18:09 - 00000000 ____D C:\Program Files (x86)\USB Vibration
2017-01-11 18:59 - 2015-07-30 17:39 - 00000000 ____D C:\Program Files (x86)\USB_Vibration
2017-01-11 18:59 - 2015-07-27 16:54 - 00000000 ____D C:\Program Files (x86)\WonderFox Soft
2017-01-11 18:59 - 2015-06-22 17:17 - 00000000 ____D C:\Program Files (x86)\Wondershare
2017-01-11 18:59 - 2015-06-21 09:05 - 00000000 ____D C:\Program Files (x86)\Zoner
2017-01-11 18:59 - 2015-06-20 19:39 - 00000000 ____D C:\Program Files (x86)\Womble Multimedia
2017-01-11 18:58 - 2016-03-13 18:51 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-01-11 18:58 - 2015-06-28 08:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2017-01-11 18:58 - 2014-11-28 10:26 - 00000000 ____D C:\Program Files (x86)\Realtek
2017-01-11 18:56 - 2015-06-24 19:37 - 00000000 ____D C:\Program Files (x86)\JDownloader
2017-01-11 18:56 - 2015-06-21 09:17 - 00000000 ____D C:\Program Files (x86)\Java
2017-01-11 18:56 - 2015-06-18 18:52 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2017-01-11 18:55 - 2016-03-23 21:05 - 00000000 ____D C:\Program Files (x86)\IObit
2017-01-11 18:55 - 2014-11-28 10:11 - 00000000 ____D C:\Program Files (x86)\Intel
2017-01-11 18:54 - 2016-03-31 16:09 - 00000000 ____D C:\Program Files (x86)\Epubor
2017-01-11 18:54 - 2016-03-15 21:13 - 00000000 ____D C:\Program Files (x86)\Artisteer 4
2017-01-11 18:54 - 2016-01-01 13:44 - 00000000 ____D C:\Program Files (x86)\Engelmann Media
2017-01-11 18:54 - 2015-12-19 13:37 - 00000000 ____D C:\Program Files (x86)\Aiseesoft Studio
2017-01-11 18:54 - 2015-07-05 08:11 - 00000000 ____D C:\Program Files (x86)\AoaoPhoto Digital Studio
2017-01-11 18:54 - 2015-06-20 14:51 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2017-01-11 18:54 - 2015-06-20 13:52 - 00000000 ____D C:\Program Files (x86)\CoffeeCup Software
2017-01-11 18:54 - 2014-11-28 10:56 - 00000000 ____D C:\Program Files (x86)\Cyberlink
2017-01-11 18:53 - 2014-11-28 10:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-01-09 04:39 - 2016-03-13 19:04 - 00000000 ___DC C:\WINDOWS\Panther
2017-01-08 18:27 - 2016-11-02 21:05 - 00000000 ____D C:\WINDOWS\system32\log
2017-01-08 16:46 - 2015-11-19 19:58 - 00000000 ___RD C:\Users\greenhorn\OneDrive
2017-01-06 22:24 - 2016-05-04 18:25 - 00309752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-01-06 22:11 - 2016-03-13 10:09 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-01-06 21:50 - 2016-09-17 13:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoReDo
2017-01-06 21:50 - 2016-09-11 20:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ext2Fsd
2017-01-06 21:50 - 2016-07-06 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrazyTalk7
2017-01-06 21:50 - 2016-07-03 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EOP Video Recorder
2017-01-06 21:50 - 2016-07-03 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EOP NMN Master
2017-01-06 21:50 - 2016-07-03 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EOPSheetMusic
2017-01-06 21:50 - 2016-07-03 20:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EOP Audio Recorder
2017-01-06 21:50 - 2016-07-03 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EveryonePiano
2017-01-06 19:26 - 2016-08-12 19:03 - 00000000 ____D C:\Users\greenhorn\AppData\Roaming\New Version Available
2017-01-06 17:58 - 2016-07-21 16:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DicoLab
2017-01-06 17:58 - 2016-03-19 09:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
2017-01-02 20:50 - 2016-01-10 13:30 - 00000000 ____D C:\Users\greenhorn\Documents\PDF

==================== Files in the root of some directories =======

2016-09-17 16:45 - 2016-09-17 16:45 - 50063360 _____ () C:\Program Files (x86)\GUT5D06.tmp
2015-06-20 13:56 - 2015-06-20 13:56 - 0562220 _____ () C:\Program Files (x86)\jcpicker.zip
2015-06-19 17:21 - 2015-06-19 17:29 - 151152305 _____ () C:\Program Files (x86)\Norton-360-+-crack.rar
2015-06-20 13:59 - 2015-06-20 13:59 - 0526727 _____ () C:\Program Files (x86)\pravitko.zip
2016-03-15 20:36 - 2016-03-15 20:36 - 0005120 _____ () C:\Users\greenhorn\AppData\Roaming\GiftBag.db
2015-06-20 13:52 - 2015-08-25 19:40 - 0153600 _____ () C:\Users\greenhorn\AppData\Roaming\SharedSettings.ccs
2015-06-28 16:43 - 2016-01-31 17:30 - 0065024 _____ () C:\Users\greenhorn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-09 23:50 - 2015-10-31 17:54 - 0007605 _____ () C:\Users\greenhorn\AppData\Local\resmon.resmoncfg
2016-10-04 18:47 - 2016-10-04 18:47 - 0000000 _____ () C:\Users\greenhorn\AppData\Local\{4F69CD05-F459-4112-BA95-6CEE8C57910F}
2016-06-04 08:02 - 2016-06-04 08:02 - 0000000 _____ () C:\Users\greenhorn\AppData\Local\{63576CCA-E165-40DD-A21F-12E1FD9F36C1}
2016-09-11 16:40 - 2016-09-11 16:40 - 0000000 _____ () C:\Users\greenhorn\AppData\Local\{66142911-795E-4163-875B-2C046D3EC3B7}
2016-05-12 16:23 - 2016-05-12 16:23 - 0000000 _____ () C:\Users\greenhorn\AppData\Local\{74777FFA-4FE7-4EB7-A6D3-7B0FD5747BEE}
2016-03-13 10:11 - 2016-03-13 10:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\greenhorn\AppData\Local\Temp\jre-8u111-windows-au.exe


Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\pcalua.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_197_pepper.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_greenhorn.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)

  
***** Velikost "Plochy" *****

Velikost slozky "C:\Users\greenhorn\Desktop" je 2635 MB.
 
 
***** Startup Programs *****
 
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"c:\users\greenhorn\appdata\roaming\seznam.cz\szninstall.exe" -c [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"c:\users\greenhorn\appdata\roaming\seznam.cz\bin\wszndesktop.exe" -q [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneDrive
"c:\users\greenhorn\appdata\local\microsoft\onedrive\onedrive.exe" /background [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhoneCompanion
c:\program files\lenovo phonecompanion\phone companion.exe 

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"c:\program files (x86)\seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe
c:\program files (x86)\common files\wondershare\wondershare helper compact\wshelper.exe 

 
***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    DisableNotifications    REG_DWORD    0x0
    EnableFirewall    REG_DWORD    0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    DisableNotifications    REG_DWORD    0x0
    EnableFirewall    REG_DWORD    0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
 
***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

 
==================== End Of Log ==============================
