Tabs closing, slow, black out screen with new display driver
Results 1 to 10 of 10

Thread: Tabs closing, slow, black out screen with new display driver

  1. #1
    Join Date
    Jul 2018
    Posts
    7

    Tabs closing, slow, black out screen with new display driver

    Hello

    Thank you.

    Issue: very slow browser, sometimes after a while I get a crashed tab message and occasionally the resolution of display changes
    System: Intel i5 CPU 2.27 GHZ, 4 GB RAM, Windows 10 64 bit

    I ran AVAST and did full scan...a couple issues found and resolved.

    Farbar logs (3 texts due to size limiitation ....1 of 3)

    C:\WINDOWS\system32\mf.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2018-07-14 06:21 - 2018-06-15 01:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2018-07-14 06:21 - 2018-06-15 01:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
    2018-07-14 06:21 - 2018-06-15 01:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
    2018-07-14 06:21 - 2018-06-15 01:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2018-07-14 06:21 - 2018-06-15 01:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2018-07-14 06:21 - 2018-06-15 01:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
    2018-07-14 06:21 - 2018-06-15 01:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
    2018-07-14 06:21 - 2018-06-15 01:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2018-07-14 06:21 - 2018-06-15 01:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
    2018-07-14 06:21 - 2018-06-15 01:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2018-07-14 06:21 - 2018-06-15 00:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2018-07-14 06:21 - 2018-06-15 00:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
    2018-07-14 06:21 - 2018-06-15 00:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
    2018-07-14 06:21 - 2018-06-15 00:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2018-07-14 06:21 - 2018-06-15 00:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2018-07-14 06:21 - 2018-06-15 00:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2018-07-14 06:21 - 2018-06-15 00:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2018-07-14 06:21 - 2018-06-15 00:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
    2018-07-14 06:21 - 2018-06-15 00:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
    2018-07-14 06:21 - 2018-06-15 00:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2018-07-14 06:21 - 2018-06-15 00:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2018-07-14 06:21 - 2018-06-15 00:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
    2018-07-14 06:21 - 2018-06-01 01:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(4).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(3).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(2).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(1).pdf
    2018-07-03 16:11 - 2018-07-03 16:11 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9.pdf
    2018-07-03 16:03 - 2018-07-20 06:06 - 000000000 ____D C:\ProgramData\Packages

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-07-20 08:33 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2018-07-20 08:28 - 2013-01-28 12:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2018-07-20 08:28 - 2013-01-28 12:38 - 000000000 ____D C:\Program Files (x86)\WinRAR
    2018-07-20 08:28 - 2013-01-19 00:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    2018-07-20 08:27 - 2012-08-31 21:56 - 000000000 ____D C:\Program Files\DivX
    2018-07-20 08:27 - 2012-08-31 21:55 - 000000000 ____D C:\ProgramData\DivX
    2018-07-20 08:27 - 2012-08-31 21:55 - 000000000 ____D C:\Program Files (x86)\DivX
    2018-07-20 08:10 - 2018-04-11 19:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2018-07-20 06:27 - 2017-08-26 13:55 - 000000000 ____D C:\Users\NCT Mens\Desktop\DAVE DOCS
    2018-07-20 06:27 - 2017-06-19 15:30 - 000000000 ____D C:\Users\NCT Mens\AppData\LocalLow\Mozilla
    2018-07-20 06:25 - 2018-06-06 18:54 - 000000000 ____D C:\Users\NCT Mens
    2018-07-20 06:25 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
    2018-07-20 06:24 - 2018-06-06 19:12 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2018-07-20 06:24 - 2018-06-06 18:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2018-07-20 06:19 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2018-07-20 06:06 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
    2018-07-20 06:00 - 2018-06-06 19:12 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{98AE576F-49F1-47B4-B24B-223AB0535ED5}
    2018-07-18 06:32 - 2013-01-03 20:48 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2018-07-17 10:01 - 2018-06-06 19:12 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2018-07-16 05:42 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
    2018-07-14 19:39 - 2018-06-11 11:13 - 000000000 ____D C:\Users\NCT Mens\AppData\Local\Deployment
    2018-07-14 11:23 - 2018-06-06 18:49 - 000968400 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2018-07-14 11:17 - 2017-11-07 19:17 - 000000000 ___RD C:\Users\NCT Mens\3D Objects
    2018-07-14 11:17 - 2017-06-19 15:00 - 000000000 __RHD C:\Users\Public\AccountPictures
    2018-07-14 11:16 - 2018-06-06 18:45 - 000417440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2018-07-14 11:15 - 2017-08-26 17:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2018-07-14 11:15 - 2017-06-19 15:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2018-07-14 11:12 - 2018-04-11 17:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\bcastdvr
    2018-07-14 10:59 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
    2018-07-14 06:13 - 2017-06-19 15:29 - 000001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2018-07-13 18:17 - 2018-06-06 19:12 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-416558941-4114933524-1477959264-1003
    2018-07-13 18:17 - 2018-06-06 18:54 - 000002422 _____ C:\Users\NCT Mens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2018-07-13 18:17 - 2017-06-19 15:04 - 000000000 ___RD C:\Users\NCT Mens\OneDrive
    2018-07-12 07:23 - 2013-11-05 14:52 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    2018-07-12 07:23 - 2009-07-13 22:34 - 000000478 _____ C:\WINDOWS\win.ini
    2018-07-11 16:18 - 2014-02-26 23:04 - 000000000 ____D C:\WINDOWS\system32\MRT
    2018-07-11 16:04 - 2014-02-26 23:04 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2018-07-11 16:00 - 2018-04-11 19:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
    2018-07-10 09:14 - 2018-06-06 19:12 - 000004588 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
    2018-07-10 09:13 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2018-07-10 09:13 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
    2018-06-28 21:13 - 2018-04-11 19:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2018-06-28 21:13 - 2018-04-11 19:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2018-06-26 17:08 - 2017-06-19 15:26 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2018-06-26 14:34 - 2018-02-23 15:53 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2018-06-20 08:42 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\NDF
    2018-06-20 08:22 - 2018-02-23 21:11 - 000000000 ____D C:\ProgramData\TEMP

    =

  2. #2
    Join Date
    Jul 2018
    Posts
    7
    Farbar 2 0f 3\\


    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-07-20 08:33 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2018-07-20 08:28 - 2013-01-28 12:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2018-07-20 08:28 - 2013-01-28 12:38 - 000000000 ____D C:\Program Files (x86)\WinRAR
    2018-07-20 08:28 - 2013-01-19 00:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    2018-07-20 08:27 - 2012-08-31 21:56 - 000000000 ____D C:\Program Files\DivX
    2018-07-20 08:27 - 2012-08-31 21:55 - 000000000 ____D C:\ProgramData\DivX
    2018-07-20 08:27 - 2012-08-31 21:55 - 000000000 ____D C:\Program Files (x86)\DivX
    2018-07-20 08:10 - 2018-04-11 19:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2018-07-20 06:27 - 2017-08-26 13:55 - 000000000 ____D C:\Users\NCT Mens\Desktop\DAVE DOCS
    2018-07-20 06:27 - 2017-06-19 15:30 - 000000000 ____D C:\Users\NCT Mens\AppData\LocalLow\Mozilla
    2018-07-20 06:25 - 2018-06-06 18:54 - 000000000 ____D C:\Users\NCT Mens
    2018-07-20 06:25 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
    2018-07-20 06:24 - 2018-06-06 19:12 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2018-07-20 06:24 - 2018-06-06 18:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2018-07-20 06:19 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2018-07-20 06:06 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
    2018-07-20 06:00 - 2018-06-06 19:12 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{98AE576F-49F1-47B4-B24B-223AB0535ED5}
    2018-07-18 06:32 - 2013-01-03 20:48 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2018-07-17 10:01 - 2018-06-06 19:12 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2018-07-16 05:42 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
    2018-07-14 19:39 - 2018-06-11 11:13 - 000000000 ____D C:\Users\NCT Mens\AppData\Local\Deployment
    2018-07-14 11:23 - 2018-06-06 18:49 - 000968400 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2018-07-14 11:17 - 2017-11-07 19:17 - 000000000 ___RD C:\Users\NCT Mens\3D Objects
    2018-07-14 11:17 - 2017-06-19 15:00 - 000000000 __RHD C:\Users\Public\AccountPictures
    2018-07-14 11:16 - 2018-06-06 18:45 - 000417440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2018-07-14 11:15 - 2017-08-26 17:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2018-07-14 11:15 - 2017-06-19 15:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2018-07-14 11:12 - 2018-04-11 17:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
    2018-07-14 11:09 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2018-07-14 11:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\bcastdvr
    2018-07-14 10:59 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
    2018-07-14 06:13 - 2017-06-19 15:29 - 000001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2018-07-13 18:17 - 2018-06-06 19:12 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-416558941-4114933524-1477959264-1003
    2018-07-13 18:17 - 2018-06-06 18:54 - 000002422 _____ C:\Users\NCT Mens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2018-07-13 18:17 - 2017-06-19 15:04 - 000000000 ___RD C:\Users\NCT Mens\OneDrive
    2018-07-12 07:23 - 2013-11-05 14:52 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    2018-07-12 07:23 - 2009-07-13 22:34 - 000000478 _____ C:\WINDOWS\win.ini
    2018-07-11 16:18 - 2014-02-26 23:04 - 000000000 ____D C:\WINDOWS\system32\MRT
    2018-07-11 16:04 - 2014-02-26 23:04 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2018-07-11 16:00 - 2018-04-11 19:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
    2018-07-10 09:14 - 2018-06-06 19:12 - 000004588 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
    2018-07-10 09:13 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2018-07-10 09:13 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
    2018-06-28 21:13 - 2018-04-11 19:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2018-06-28 21:13 - 2018-04-11 19:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2018-06-26 17:08 - 2017-06-19 15:26 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2018-06-26 14:34 - 2018-02-23 15:53 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2018-06-20 08:42 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\NDF
    2018-06-20 08:22 - 2018-02-23 21:11 - 000000000 ____D C:\ProgramData\TEMP

  3. #3
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Welcome aboard

    Please, observe following rules:

    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.



    ==========================================

    I need to see complete logs.

  4. #4
    Join Date
    Jul 2018
    Posts
    7
    sorry...I thought I did...resending all

    Farbar 1 0f 4

    FRST:

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.07.2018
    Ran by NCT Mens (administrator) on MENS-LAPTOP2 (20-07-2018 08:47:55)
    Running from C:\Users\NCT Mens\Downloads
    Loaded Profiles: NCT Mens & DefaultAppPool (Available Profiles: NCT Mens & DefaultAppPool)
    Platform: Windows 10 Home Version 1803 17134.165 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" -- "%1")
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    () C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
    (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
    (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
    (Microsoft Corporation) C:\Windows\System32\mqsvc.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.0_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
    (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
    (AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
    (AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-23] (Synaptics Incorporated)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-29] (IDT, Inc.)
    HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5712896 2010-02-02] (Dell Inc.)
    HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-07-20] (AVAST Software)
    HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-13] (Flexera Software LLC.)
    HKLM-x32\...\Run: [DNS7reminder] => "C:\Program Files (x86)\Nuance\NaturallySpeaking13\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking13\Ereg.ini"
    HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1057240 2017-11-17] (DivX, LLC)
    Winlogon\Notify\FastAccess-x32: c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll [X]
    HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
    HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
    HKU\S-1-5-21-416558941-4114933524-1477959264-1003\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-13] (Flexera Software LLC.)
    HKU\S-1-5-21-416558941-4114933524-1477959264-1003\...\Run: [AvastBrowserAutoLaunch_D995A1BBB3F1845312137C1CA32FFBF3] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1721560 2018-07-06] (AVAST Software)
    HKU\S-1-5-21-416558941-4114933524-1477959264-1003\...\RunOnce: [Application Restart #0] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-13] (Flexera Software LLC.)
    HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{37f3a67f-b2f1-4087-8c8f-718184cc6580}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{95e493f6-201a-4ab5-a85b-55150b4d6247}: [DhcpNameServer] 128.205.106.106 128.205.7.1 128.205.1.2
    Tcpip\..\Interfaces\{a771d614-4198-4a7c-a8af-a75f3ff57ab0}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    SearchScopes: HKLM -> DefaultScope {31512B91-ACF0-4B66-83B2-175473C8B5E3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM -> {31512B91-ACF0-4B66-83B2-175473C8B5E3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {441BAF3E-4B13-47F6-80EC-0E391AE3B110} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {441BAF3E-4B13-47F6-80EC-0E391AE3B110} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
    SearchScopes: HKU\S-1-5-21-416558941-4114933524-1477959264-1003 -> DefaultScope {31512B91-ACF0-4B66-83B2-175473C8B5E3} URL =
    BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2018-02-15] (Microsoft Corporation)
    BHO: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\x64\dgnriaie_x64.dll [2014-07-23] (Nuance Communications, Inc.)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-21] (Sun Microsystems, Inc.)
    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-09-12] (Microsoft Corporation)
    BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
    BHO-x32: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\dgnriaie.dll [2014-07-23] (Nuance Communications, Inc.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08] (Oracle Corporation)
    BHO-x32: FAIESSOHelper Class -> {A2F122DA-055F-4df7-8F24-7354DBDBA85B} -> c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll => No File
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08] (Oracle Corporation)
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2017-08-15] (Microsoft Corporation)

    FireFox:
    ========
    FF DefaultProfile: po6yx9ew.default
    FF ProfilePath: C:\Users\NCT Mens\AppData\Roaming\Mozilla\Firefox\Profiles\po6yx9ew.default [2018-07-20]
    FF Homepage: Mozilla\Firefox\Profiles\po6yx9ew.default -> hxxps://mail.google.com/mail/u/0/?tab=wm#inbox
    hxxps://www.landgrantholyland.com/
    FF HomepageOverride: Mozilla\Firefox\Profiles\po6yx9ew.default -> Disabled: web@Maps
    FF NewTabOverride: Mozilla\Firefox\Profiles\po6yx9ew.default -> Disabled: web@Maps
    FF Extension: (Maps) - C:\Users\NCT Mens\AppData\Roaming\Mozilla\Firefox\Profiles\po6yx9ew.default\Extensions\web@Maps.xpi [2018-02-19]
    FF Extension: (WebCompat Reporter) - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2018-07-14] [Legacy] [not signed]
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll [2018-07-10] ()
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
    FF Plugin: nuance.com/DgnRia2_x86_64 -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\x64\npDgnRia2_x64.dll [2014-07-23] (Nuance Communications, Inc.)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_134.dll [2018-07-10] ()
    FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2017-11-21] (DivX, LLC)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-10-08] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-10-08] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-09-12] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
    FF Plugin-x32: nuance.com/DgnRia2 -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\npDgnRia2.dll [2014-07-23] (Nuance Communications, Inc.)

    Chrome:
    =======
    CHR Profile: C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default [2018-07-20]
    CHR Extension: (Slides) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-15]
    CHR Extension: (Docs) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-15]
    CHR Extension: (Google Drive) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-19]
    CHR Extension: (YouTube) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-19]
    CHR Extension: (Sheets) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-15]
    CHR Extension: (Google Docs Offline) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-15]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
    CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2017-06-19]
    CHR Extension: (Socksharedownloader) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlfohjgijhjlpidbbnmcdooegafnnnm [2017-06-19] [UpdateUrl: hxxp://cdn.socksharedownloader.com/Extensions/socksharedownloader/chrome/update.xml] <==== ATTENTION
    CHR Extension: (Gmail) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-19]
    CHR Extension: (Chrome Media Router) - C:\Users\NCT Mens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-20]
    CHR HKLM-x32\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\Kushal Suryamohan\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx <not found>
    CHR HKLM-x32\...\Chrome\Extension: [ohlfohjgijhjlpidbbnmcdooegafnnnm] - C:\Program Files (x86)\SockshareDownloader\SockshareDownloader10.crx [2012-11-15]
    StartMenuInternet: Google Chrome.HSJYDK56FQMJYL3RB4DK3C4EXA - C:\Users\Kushal Suryamohan\AppData\Local\Google\Chrome\Application\chrome.exe

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7780400 2018-07-20] (AVAST Software)
    S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-07-20] (AVAST Software)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-07-20] (AVAST Software)
    S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-07-20] (AVAST Software)
    R2 DragonLoggerService; C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe [137280 2014-07-23] (Nuance Communications, Inc.)
    R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.5\my.ini [8919 2012-11-01] () [File not signed]
    S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
    S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
    S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
    R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5088256 2010-02-02] (Dell Inc.) [File not signed]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [197160 2018-07-20] (AVAST Software)
    R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [229392 2018-07-20] (AVAST Software)
    R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [201328 2018-07-20] (AVAST Software)
    R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [346664 2018-07-20] (AVAST Software)
    R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [59592 2018-07-20] (AVAST Software)
    S3 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15360 2018-07-20] (AVAST Software)
    R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239680 2018-07-20] (AVAST Software)
    S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2018-07-20] (AVAST Software)
    R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159640 2018-07-20] (AVAST Software)
    R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111872 2018-07-20] (AVAST Software)
    S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-07-20] (AVAST Software)
    R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027728 2018-07-20] (AVAST Software)
    R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [463080 2018-07-20] (AVAST Software)
    R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [211160 2018-07-20] (AVAST Software)
    R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381584 2018-07-20] (AVAST Software)
    R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-11] (Realtek )
    U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [44544 2018-04-11] (Microsoft Corporation)
    S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
    S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
    U3 idsvc; no ImagePath

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-07-20 08:46 - 2018-07-20 08:46 - 002412544 _____ (Farbar) C:\Users\NCT Mens\Downloads\FRST64(2).exe
    2018-07-20 08:39 - 2018-07-20 08:40 - 000046017 _____ C:\Users\NCT Mens\Downloads\Addition.txt
    2018-07-20 08:37 - 2018-07-20 08:48 - 000019119 _____ C:\Users\NCT Mens\Downloads\FRST.txt
    2018-07-20 08:37 - 2018-07-20 08:47 - 000000000 ____D C:\FRST
    2018-07-20 08:37 - 2018-07-20 08:37 - 000000000 _____ C:\Users\NCT Mens\Desktop\New Text Document.txt
    2018-07-20 08:36 - 2018-07-20 08:36 - 002412544 _____ (Farbar) C:\Users\NCT Mens\Downloads\FRST64(1).exe
    2018-07-20 08:34 - 2018-07-20 08:34 - 002412544 _____ (Farbar) C:\Users\NCT Mens\Downloads\FRST64.exe
    2018-07-20 08:28 - 2018-07-20 08:28 - 000000000 ____D C:\Users\NCT Mens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2018-07-20 08:27 - 2018-07-20 08:27 - 000003708 _____ C:\WINDOWS\System32\Tasks\DivXUpdate
    2018-07-20 08:26 - 2018-07-20 08:27 - 000000000 ____D C:\Users\NCT Mens\AppData\Roaming\DivX
    2018-07-20 08:26 - 2018-07-20 08:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
    2018-07-20 08:25 - 2018-07-20 08:26 - 000000000 ____D C:\ProgramData\Package Cache
    2018-07-20 08:18 - 2018-07-20 08:18 - 000002577 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
    2018-07-20 08:16 - 2018-07-20 08:16 - 000003458 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineUA
    2018-07-20 08:16 - 2018-07-20 08:16 - 000003334 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineCore
    2018-07-20 08:16 - 2018-07-20 08:16 - 000000000 ____D C:\Program Files (x86)\AVAST Software
    2018-07-20 08:14 - 2018-07-20 08:31 - 000000000 ____D C:\Users\NCT Mens\AppData\Local\AVAST Software
    2018-07-20 08:14 - 2018-07-20 08:14 - 000000000 ____D C:\Users\NCT Mens\AppData\Roaming\AVAST Software
    2018-07-20 08:14 - 2018-07-20 08:14 - 000000000 ____D C:\Users\NCT Mens\AppData\Local\CEF
    2018-07-20 08:13 - 2018-07-20 08:13 - 000001986 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
    2018-07-20 08:13 - 2018-07-20 08:13 - 000001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
    2018-07-20 08:12 - 2018-07-20 08:12 - 000000000 ____D C:\WINDOWS\System32\Tasks\Avast Software
    2018-07-20 08:11 - 2018-07-20 08:11 - 000003990 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
    2018-07-20 08:11 - 2018-07-20 08:10 - 001027728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000463080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000381584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000346664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000239680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000229392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000211160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000201328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000197160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000159640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000111872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000059592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
    2018-07-20 08:11 - 2018-07-20 08:10 - 000015360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
    2018-07-20 08:10 - 2018-07-20 08:10 - 000378072 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
    2018-07-20 08:10 - 2018-07-20 08:10 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
    2018-07-20 08:09 - 2018-07-20 08:09 - 000000000 ____D C:\Program Files\AVAST Software
    2018-07-20 08:08 - 2018-07-20 08:10 - 000000000 ____D C:\ProgramData\AVAST Software
    2018-07-20 08:08 - 2018-07-20 08:08 - 007397256 _____ (AVAST Software) C:\Users\NCT Mens\Downloads\avast_free_antivirus_setup_online.exe
    2018-07-14 06:22 - 2018-07-06 10:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
    2018-07-14 06:22 - 2018-07-06 10:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
    2018-07-14 06:22 - 2018-07-06 10:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2018-07-14 06:22 - 2018-07-06 10:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2018-07-14 06:22 - 2018-07-06 09:56 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
    2018-07-14 06:22 - 2018-07-06 09:51 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2018-07-14 06:22 - 2018-07-06 08:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2018-07-14 06:22 - 2018-07-06 07:26 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
    2018-07-14 06:22 - 2018-07-06 07:25 - 023863296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
    2018-07-14 06:22 - 2018-07-06 03:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
    2018-07-14 06:22 - 2018-07-06 03:25 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2018-07-14 06:22 - 2018-07-06 03:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2018-07-14 06:22 - 2018-07-06 03:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2018-07-14 06:22 - 2018-07-06 03:25 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2018-07-14 06:22 - 2018-07-06 03:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
    2018-07-14 06:22 - 2018-07-06 03:10 - 025845760 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2018-07-14 06:22 - 2018-07-06 03:07 - 022006272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2018-07-14 06:22 - 2018-07-06 03:04 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2018-07-14 06:22 - 2018-07-06 03:03 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
    2018-07-14 06:22 - 2018-07-06 03:02 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2018-07-14 06:22 - 2018-07-06 03:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2018-07-14 06:22 - 2018-07-06 03:01 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2018-07-14 06:22 - 2018-07-06 03:00 - 019403264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2018-07-14 06:22 - 2018-07-06 02:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2018-07-14 06:22 - 2018-07-06 02:57 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2018-07-14 06:22 - 2018-07-06 02:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2018-07-14 06:22 - 2018-07-06 02:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2018-07-14 06:22 - 2018-07-06 02:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2018-07-14 06:22 - 2018-07-06 02:55 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2018-07-14 06:22 - 2018-06-15 13:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2018-07-14 06:22 - 2018-06-15 13:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
    2018-07-14 06:22 - 2018-06-15 13:34 - 008623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2018-07-14 06:22 - 2018-06-15 13:33 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2018-07-14 06:22 - 2018-06-15 11:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2018-07-14 06:22 - 2018-06-15 11:07 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2018-07-14 06:22 - 2018-06-15 01:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
    2018-07-14 06:22 - 2018-06-15 01:19 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
    2018-07-14 06:22 - 2018-06-15 01:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2018-07-14 06:22 - 2018-06-15 01:11 - 006817872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2018-07-14 06:22 - 2018-06-15 01:09 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll

  5. #5
    Join Date
    Jul 2018
    Posts
    7
    Farber 2of 4

    FRST:


    2018-07-14 06:22 - 2018-06-15 01:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2018-07-14 06:22 - 2018-06-15 01:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2018-07-14 06:22 - 2018-06-15 01:08 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
    2018-07-14 06:22 - 2018-06-15 01:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2018-07-14 06:22 - 2018-06-15 01:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2018-07-14 06:22 - 2018-06-15 01:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2018-07-14 06:22 - 2018-06-15 01:07 - 001145696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
    2018-07-14 06:22 - 2018-06-15 01:04 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 006528600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 006043600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 001144120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
    2018-07-14 06:22 - 2018-06-15 01:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2018-07-14 06:22 - 2018-06-15 00:48 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2018-07-14 06:22 - 2018-06-15 00:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2018-07-14 06:22 - 2018-06-15 00:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
    2018-07-14 06:22 - 2018-06-15 00:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2018-07-14 06:22 - 2018-06-15 00:42 - 002367488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
    2018-07-14 06:22 - 2018-06-15 00:41 - 004561920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2018-07-14 06:22 - 2018-06-15 00:41 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2018-07-14 06:22 - 2018-06-15 00:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2018-07-14 06:22 - 2018-06-15 00:39 - 002903040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2018-07-14 06:21 - 2018-07-06 10:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2018-07-14 06:21 - 2018-07-06 10:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2018-07-14 06:21 - 2018-07-06 10:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2018-07-14 06:21 - 2018-07-06 10:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2018-07-14 06:21 - 2018-07-06 10:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
    2018-07-14 06:21 - 2018-07-06 10:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
    2018-07-14 06:21 - 2018-07-06 10:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
    2018-07-14 06:21 - 2018-07-06 09:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
    2018-07-14 06:21 - 2018-07-06 09:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
    2018-07-14 06:21 - 2018-07-06 09:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
    2018-07-14 06:21 - 2018-07-06 09:52 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2018-07-14 06:21 - 2018-07-06 09:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2018-07-14 06:21 - 2018-07-06 09:51 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
    2018-07-14 06:21 - 2018-07-06 09:51 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
    2018-07-14 06:21 - 2018-07-06 09:51 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
    2018-07-14 06:21 - 2018-07-06 09:51 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2018-07-14 06:21 - 2018-07-06 09:50 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2018-07-14 06:21 - 2018-07-06 09:49 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
    2018-07-14 06:21 - 2018-07-06 07:54 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
    2018-07-14 06:21 - 2018-07-06 07:54 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2018-07-14 06:21 - 2018-07-06 07:53 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
    2018-07-14 06:21 - 2018-07-06 07:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
    2018-07-14 06:21 - 2018-07-06 07:52 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2018-07-14 06:21 - 2018-07-06 07:52 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
    2018-07-14 06:21 - 2018-07-06 07:52 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2018-07-14 06:21 - 2018-07-06 07:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
    2018-07-14 06:21 - 2018-07-06 07:51 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
    2018-07-14 06:21 - 2018-07-06 07:01 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
    2018-07-14 06:21 - 2018-07-06 03:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
    2018-07-14 06:21 - 2018-07-06 03:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2018-07-14 06:21 - 2018-07-06 03:29 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
    2018-07-14 06:21 - 2018-07-06 03:29 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
    2018-07-14 06:21 - 2018-07-06 03:27 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2018-07-14 06:21 - 2018-07-06 03:27 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2018-07-14 06:21 - 2018-07-06 03:27 - 001012632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2018-07-14 06:21 - 2018-07-06 03:27 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2018-07-14 06:21 - 2018-07-06 03:27 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
    2018-07-14 06:21 - 2018-07-06 03:27 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
    2018-07-14 06:21 - 2018-07-06 03:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
    2018-07-14 06:21 - 2018-07-06 03:26 - 002712992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2018-07-14 06:21 - 2018-07-06 03:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2018-07-14 06:21 - 2018-07-06 03:26 - 000930720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2018-07-14 06:21 - 2018-07-06 03:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2018-07-14 06:21 - 2018-07-06 03:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2018-07-14 06:21 - 2018-07-06 03:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2018-07-14 06:21 - 2018-07-06 03:25 - 001018616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 000885856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 000483048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2018-07-14 06:21 - 2018-07-06 03:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
    2018-07-14 06:21 - 2018-07-06 03:16 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2018-07-14 06:21 - 2018-07-06 03:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2018-07-14 06:21 - 2018-07-06 03:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2018-07-14 06:21 - 2018-07-06 03:14 - 001175568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
    2018-07-14 06:21 - 2018-07-06 03:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2018-07-14 06:21 - 2018-07-06 03:14 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2018-07-14 06:21 - 2018-07-06 03:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2018-07-14 06:21 - 2018-07-06 03:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2018-07-14 06:21 - 2018-07-06 03:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
    2018-07-14 06:21 - 2018-07-06 03:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
    2018-07-14 06:21 - 2018-07-06 03:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
    2018-07-14 06:21 - 2018-07-06 02:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2018-07-14 06:21 - 2018-07-06 02:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
    2018-07-14 06:21 - 2018-07-06 02:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2018-07-14 06:21 - 2018-07-06 02:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
    2018-07-14 06:21 - 2018-07-06 02:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2018-07-14 06:21 - 2018-07-06 02:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2018-07-14 06:21 - 2018-07-06 02:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
    2018-07-14 06:21 - 2018-07-06 02:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
    2018-07-14 06:21 - 2018-07-06 02:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2018-07-14 06:21 - 2018-07-06 02:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2018-07-14 06:21 - 2018-07-06 02:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2018-07-14 06:21 - 2018-07-06 02:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2018-07-14 06:21 - 2018-07-06 02:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2018-07-14 06:21 - 2018-07-06 01:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
    2018-07-14 06:21 - 2018-06-29 00:16 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
    2018-07-14 06:21 - 2018-06-15 13:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
    2018-07-14 06:21 - 2018-06-15 13:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
    2018-07-14 06:21 - 2018-06-15 13:53 - 000094104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2018-07-14 06:21 - 2018-06-15 13:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2018-07-14 06:21 - 2018-06-15 13:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
    2018-07-14 06:21 - 2018-06-15 13:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
    2018-07-14 06:21 - 2018-06-15 13:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
    2018-07-14 06:21 - 2018-06-15 13:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
    2018-07-14 06:21 - 2018-06-15 13:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
    2018-07-14 06:21 - 2018-06-15 13:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
    2018-07-14 06:21 - 2018-06-15 13:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
    2018-07-14 06:21 - 2018-06-15 13:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
    2018-07-14 06:21 - 2018-06-15 13:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
    2018-07-14 06:21 - 2018-06-15 13:31 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2018-07-14 06:21 - 2018-06-15 13:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
    2018-07-14 06:21 - 2018-06-15 13:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2018-07-14 06:21 - 2018-06-15 13:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
    2018-07-14 06:21 - 2018-06-15 13:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
    2018-07-14 06:21 - 2018-06-15 13:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
    2018-07-14 06:21 - 2018-06-15 13:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2018-07-14 06:21 - 2018-06-15 13:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2018-07-14 06:21 - 2018-06-15 13:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
    2018-07-14 06:21 - 2018-06-15 13:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2018-07-14 06:21 - 2018-06-15 13:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2018-07-14 06:21 - 2018-06-15 13:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
    2018-07-14 06:21 - 2018-06-15 13:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
    2018-07-14 06:21 - 2018-06-15 13:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
    2018-07-14 06:21 - 2018-06-15 13:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
    2018-07-14 06:21 - 2018-06-15 11:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2018-07-14 06:21 - 2018-06-15 11:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
    2018-07-14 06:21 - 2018-06-15 11:06 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2018-07-14 06:21 - 2018-06-15 11:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
    2018-07-14 06:21 - 2018-06-15 11:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
    2018-07-14 06:21 - 2018-06-15 11:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
    2018-07-14 06:21 - 2018-06-15 11:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
    2018-07-14 06:21 - 2018-06-15 11:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2018-07-14 06:21 - 2018-06-15 11:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2018-07-14 06:21 - 2018-06-15 11:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2018-07-14 06:21 - 2018-06-15 11:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
    2018-07-14 06:21 - 2018-06-15 09:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
    2018-07-14 06:21 - 2018-06-15 03:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2018-07-14 06:21 - 2018-06-15 03:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
    2018-07-14 06:21 - 2018-06-15 03:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
    2018-07-14 06:21 - 2018-06-15 01:21 - 000761440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
    2018-07-14 06:21 - 2018-06-15 01:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
    2018-07-14 06:21 - 2018-06-15 01:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
    2018-07-14 06:21 - 2018-06-15 01:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
    2018-07-14 06:21 - 2018-06-15 01:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2018-07-14 06:21 - 2018-06-15 01:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2018-07-14 06:21 - 2018-06-15 01:15 - 002563960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
    2018-07-14 06:21 - 2018-06-15 01:13 - 000510904 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2018-07-14 06:21 - 2018-06-15 01:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2018-07-14 06:21 - 2018-06-15 01:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
    2018-07-14 06:21 - 2018-06-15 01:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2018-07-14 06:21 - 2018-06-15 01:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2018-07-14 06:21 - 2018-06-15 01:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2018-07-14 06:21 - 2018-06-15 01:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
    2018-07-14 06:21 - 2018-06-15 01:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
    2018-07-14 06:21 - 2018-06-15 01:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2018-07-14 06:21 - 2018-06-15 01:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2018-07-14 06:21 - 2018-06-15 01:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
    2018-07-14 06:21 - 2018-06-15 01:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2018-07-14 06:21 - 2018-06-15 01:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2018-07-14 06:21 - 2018-06-15 01:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
    2018-07-14 06:21 - 2018-06-15 01:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2018-07-14 06:21 - 2018-06-15 01:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
    2018-07-14 06:21 - 2018-06-15 01:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
    2018-07-14 06:21 - 2018-06-15 01:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
    2018-07-14 06:21 - 2018-06-15 01:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2018-07-14 06:21 - 2018-06-15 00:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2018-07-14 06:21 - 2018-06-15 00:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
    2018-07-14 06:21 - 2018-06-15 00:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
    2018-07-14 06:21 - 2018-06-15 00:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
    2018-07-14 06:21 - 2018-06-15 00:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
    2018-07-14 06:21 - 2018-06-15 00:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
    2018-07-14 06:21 - 2018-06-15 00:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
    2018-07-14 06:21 - 2018-06-15 00:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2018-07-14 06:21 - 2018-06-15 00:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2018-07-14 06:21 - 2018-06-15 00:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2018-07-14 06:21 - 2018-06-15 00:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2018-07-14 06:21 - 2018-06-15 00:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
    2018-07-14 06:21 - 2018-06-15 00:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
    2018-07-14 06:21 - 2018-06-15 00:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
    2018-07-14 06:21 - 2018-06-15 00:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
    2018-07-14 06:21 - 2018-06-15 00:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
    2018-07-14 06:21 - 2018-06-15 00:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2018-07-14 06:21 - 2018-06-15 00:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
    2018-07-14 06:21 - 2018-06-15 00:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2018-07-14 06:21 - 2018-06-15 00:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2018-07-14 06:21 - 2018-06-15 00:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2018-07-14 06:21 - 2018-06-15 00:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
    2018-07-14 06:21 - 2018-06-01 01:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(4).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(3).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(2).pdf
    2018-07-03 16:12 - 2018-07-03 16:12 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9(1).pdf
    2018-07-03 16:11 - 2018-07-03 16:11 - 000154128 _____ C:\Users\NCT Mens\Downloads\064190_0a3ed8369183402a912e3a87f69070a9.pdf
    2018-07-03 16:03 - 2018-07-20 06:06 - 000000000 ____D C:\ProgramData\Packages



    ==================== Files in the root of some directories =======

    2018-02-25 16:43 - 2018-05-02 14:05 - 000001795 _____ () C:\Users\NCT Mens\AppData\Roaming\SAS7_000.DAT

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2018-06-06 18:45

    ==================== End of FRST.txt ============================

  6. #6
    Join Date
    Jul 2018
    Posts
    7
    Farber 3 of 4

    Addition:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.07.2018
    Ran by NCT Mens (20-07-2018 08:49:01)
    Running from C:\Users\NCT Mens\Downloads
    Windows 10 Home Version 1803 17134.165 (X64) (2018-06-06 23:13:09)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-416558941-4114933524-1477959264-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-416558941-4114933524-1477959264-503 - Limited - Disabled)
    Guest (S-1-5-21-416558941-4114933524-1477959264-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-416558941-4114933524-1477959264-1002 - Limited - Enabled)
    NCT Mens (S-1-5-21-416558941-4114933524-1477959264-1003 - Administrator - Enabled) => C:\Users\NCT Mens
    WDAGUtilityAccount (S-1-5-21-416558941-4114933524-1477959264-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Accelrys Draw 4.1 (HKLM-x32\...\{44653096-3E44-402E-B68E-37D77240BFA8}) (Version: 4.1.0 - Accelrys Software Inc.)
    Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.134 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.23) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.23 - Adobe Systems Incorporated)
    Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    AMD Catalyst Install Manager (HKLM\...\{914F7627-B645-9895-F723-BAEAAC865E75}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
    ATI Catalyst Control Center (HKLM-x32\...\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.009.0908.2224 - )
    Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.5.2342 - AVAST Software)
    Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 67.0.640.99 - AVAST Software)
    Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.154.333 - AVAST Software) Hidden
    Banctec Service Agreement (HKLM-x32\...\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    ccc-core-static (HKLM-x32\...\{6EC756AA-7AEB-7CCB-7129-CCD7E54E8D0F}) (Version: 2009.0908.2225.38429 - ATI) Hidden
    Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 14.0.2.0 - Synaptics Incorporated)
    Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
    Dictate (HKLM-x32\...\{8475267E-D7DF-4A6D-A126-2C6B519E6F74}) (Version: 5.00.0000 - Microsoft)
    DivX Setup (HKLM\...\DivX Setup) (Version: 3.0.0.224 - DivX, LLC)
    doPDF 7.3 printer (HKLM\...\doPDF 7 printer_is1) (Version: 7.3.393 - Softland)
    Dragon NaturallySpeaking 13 (HKLM-x32\...\{33EA20FB-5389-4938-BA59-2BCD9BB68F41}) (Version: 13.00.000 - Nuance Communications Inc.)
    DW WLAN Card Utility (HKLM\...\DW WLAN Card Utility) (Version: 5.60.48.35 - Dell Inc.)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
    Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.450 - Oracle)
    Java(TM) 6 Update 14 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416014FF}) (Version: 6.0.140 - Sun Microsystems, Inc.)
    Java(TM) 6 Update 14 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216014FF}) (Version: 6.0.140 - Sun Microsystems, Inc.)
    Junk Mail filter update (HKLM-x32\...\{E2DFE069-083E-4631-9B6C-43C48E991DE5}) (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
    KB4023057 (HKLM\...\{B977A833-7734-41A5-B820-1F23D81DC87B}) (Version: 2.6.0.0 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-416558941-4114933524-1477959264-1003\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
    Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual J# 2.0 Redistributable Package (HKLM-x32\...\Microsoft Visual J# 2.0 Redistributable Package) (Version: - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
    Mozilla Firefox 61.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 61.0.1 (x64 en-US)) (Version: 61.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0 - Mozilla)
    MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
    MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.8 - F.J. Wechselberger)
    MySQL Server 5.5 (HKLM\...\{5CA882E6-4BF0-4E55-B290-6C4EAD6E586E}) (Version: 5.5.28 - Oracle Corporation)
    Outils de vérification linguistique 2013 de Microsoft Office*- Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
    Programmer's Notepad (HKLM-x32\...\{52CF142B-7B0E-41E7-98F5-B834122523E7}_is1) (Version: 2.3.4.2350 - Simon Steele)
    ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - )
    Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
    Skins (HKLM-x32\...\{56E09BFC-D4A4-7FE4-02A9-A919D02B488D}) (Version: 2009.0908.2225.38429 - ATI) Hidden
    SnapGene Viewer (HKLM-x32\...\SnapGene Viewer) (Version: 2.2.2 - GSL Biotech LLC)
    UpdateAssistant (HKLM-x32\...\{DE45508F-369E-4476-8F19-088F4933340E}) (Version: 1.8.0.0 - Microsoft Corporation) Hidden
    VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden
    VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.3 - VideoLAN)
    Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22243 - Microsoft Corporation)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    WinRAR 5.60 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-20] (AVAST Software)
    ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-20] (AVAST Software)
    ContextMenuHandlers1: [DivXShellExtensionItem] -> {48A8A3B0-57E8-4F2B-A49D-19E02B92377B} => C:\Program Files (x86)\Common Files\DivX Shared\DivXShellExtension64.dll [2017-10-05] (DivX, LLC)
    ContextMenuHandlers1: [DivXShellExtensionItem64] -> {6B49A276-0DBA-43F4-BC96-A841AD11B40B} => C:\Program Files (x86)\Common Files\DivX Shared\DivXShellExtension64.dll [2017-10-05] (DivX, LLC)
    ContextMenuHandlers1-x32: [MyPhoneExplorer] -> {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF} => C:\Users\NCT Mens\Desktop\MyPhoneExplorer\DLL\ShellMgr.dll -> No File
    ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (Alexander Roshal)
    ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)
    ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-20] (AVAST Software)
    ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
    ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
    ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-07-20] (AVAST Software)
    ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {18DA5A66-BB0D-4229-B8D5-3C9BF35AB1AD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-07-10] (Adobe Systems Incorporated)
    Task: {1B61E091-5027-4D9E-9823-0C5811D8D277} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {1F38413D-CC54-459C-BDB1-C76E46BED1B3} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {21634FA7-F283-4F50-BE28-3ED438EC589E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
    Task: {22ADAD1D-7B71-464B-BC56-7E5D663BEF6C} - System32\Tasks\D32GWKL1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
    Task: {4C446F3F-9786-41ED-8DDD-10A830A2D13B} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {51762641-C662-4ECD-8712-66D1659636E7} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [2018-07-20] (AVAST Software)
    Task: {537E33EB-02BA-422A-AB71-68215C53842D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-19] (Google Inc.)
    Task: {5940AE3D-5FFD-49F0-B50D-62865D50256D} - System32\Tasks\{1891A17D-74EB-445B-8C49-2D49478914BD} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kushal Suryamohan\Downloads\ncbi-blast-2.2.26+-win64.exe" -d "C:\Users\Kushal Suryamohan\Downloads"
    Task: {5FE649F7-6EF1-4DA1-B746-477F5D8E959D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-19] (Google Inc.)
    Task: {602B938D-8BEE-4085-B645-5FC88C7F5A9D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {6394F884-10F6-4A06-8442-1F880A3BBBB4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
    Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
    Task: {6B90FCB0-A439-46F0-A739-0A4BE37A8D70} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {6D92C4DF-A7A9-4367-85F4-CFFD87E222F1} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
    Task: {6E915AA5-254A-48B6-B5B3-E003BF74E2A5} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_Plugin.exe [2018-07-10] (Adobe Systems Incorporated)
    Task: {6F9212B9-63FA-4AC0-967B-F2547A6AF6B7} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
    Task: {732231EA-D4A4-4CBF-9348-BDA361DCCCCF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-07-20] (AVAST Software)
    Task: {7431B122-31AC-432F-AB98-A25A71CA580B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
    Task: {7A1F768D-99E9-41FA-8F2A-DE6E52A79B46} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-416558941-4114933524-1477959264-1001UA => C:\Users\Kushal Suryamohan\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: {7A4C3C1F-7966-4703-ABA3-52D84F03E6F4} - System32\Tasks\{48BF31A5-8F80-4E94-98B0-7216C2EB5AAF} => C:\Program Files (x86)\WolfPack\Need for Speed 5 Porsche Unleashed\Porsche.exe
    Task: {7DC1FDE4-ACFC-4A26-89DD-0D45DDBC844D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {815B4692-4585-4002-9E97-45DB5EC8488D} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {8802FF36-1CF5-4A2A-91F3-A7A0D0049186} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {8ED539B0-55B5-4CFC-8706-B788746931AF} - System32\Tasks\DivXUpdate => C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [2017-08-02] (DivX, LLC)
    Task: {8F405E69-1744-49CD-A370-A80ADAC9BAF3} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
    Task: {9285D295-625E-4ABD-A326-1B09E7364886} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {9E4A3CFE-94A2-4914-BEA8-97F7145444A3} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-07-20] (AVAST Software)
    Task: {A3D428F0-731A-402C-A213-2766E9E1553B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {A9A4DC83-24ED-4548-AE10-BDC2794EE8C4} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {AA82AF92-81FC-473E-8D07-C8BC75F9EE50} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {ABEED9E7-C258-4F69-8FFE-85FF7F6F319A} - System32\Tasks\{125791CB-018E-49BB-AB11-2B6DACDE17EF} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kushal Suryamohan\Downloads\NFS5-3.5.20040310\SETUP.EXE" -d "C:\Users\Kushal Suryamohan\Downloads\NFS5-3.5.20040310"
    Task: {B37021D8-8BD9-4081-A71E-2328CA6E5485} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [2018-07-20] (AVAST Software)
    Task: {B45A35B7-46E7-406B-8027-84B69FB6F2A2} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {B817E7AC-F423-4C48-A78E-1F9FA7AD8A14} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
    Task: {C058667E-03DA-4504-8E26-07659E2C21E4} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {C75E78D8-DB05-4C6A-9193-8C8D62B971E9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
    Task: {C96DE700-94A8-41A8-8E8E-F75B5C588898} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {C9A53571-561C-431F-91B5-666A251AAD53} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
    Task: {D23993B3-AC80-4940-91C2-F27C8244B5B6} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
    Task: {D62736C5-C98A-45D6-97F0-8F664D2F4C73} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {E5FC0710-84C7-45E6-93C4-A3CA50F28493} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-416558941-4114933524-1477959264-1001Core => C:\Users\Kushal Suryamohan\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: {EFF75B8F-764F-4246-AF38-2CC0F6A08519} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {F31793DA-4127-49E8-B7CF-477CBAADB904} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-416558941-4114933524-1477959264-1001Core.job => C:\Users\Kushal Suryamohan\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-416558941-4114933524-1477959264-1001UA.job => C:\Users\Kushal Suryamohan\AppData\Local\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ==================== Loaded Modules (Whitelisted) ==============

    2012-08-29 11:12 - 2012-08-29 11:12 - 009717760 _____ () C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
    2018-04-11 19:34 - 2018-04-11 19:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
    2017-02-23 08:29 - 2017-02-23 08:29 - 008909512 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2018-04-11 19:34 - 2018-04-11 19:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
    2018-04-11 19:34 - 2018-04-11 19:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
    2018-07-14 06:22 - 2018-07-06 02:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2018-07-03 16:02 - 2018-07-03 16:03 - 001922224 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
    2018-07-10 09:13 - 2018-07-10 09:13 - 027143680 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    2018-07-20 06:05 - 2018-07-20 06:06 - 068153856 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
    2017-11-03 10:27 - 2017-11-03 10:28 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
    2018-04-26 05:43 - 2018-04-26 05:46 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 004139008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
    2018-03-30 05:59 - 2018-03-30 06:01 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 014919168 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 003982848 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\MediaEngine.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 002938880 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
    2018-05-30 06:26 - 2018-05-30 06:26 - 000872448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
    2018-07-20 06:05 - 2018-07-20 06:06 - 001396224 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
    2018-02-02 06:54 - 2018-02-02 06:55 - 004601048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
    2018-07-20 08:13 - 2018-07-20 08:13 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2018-07-20 08:10 - 2018-07-20 08:10 - 000483544 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
    2018-07-20 08:10 - 2018-07-20 08:10 - 000282840 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll

  7. #7
    Join Date
    Jul 2018
    Posts
    7
    Farber 4 of 4

    Addition:



    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [273]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 22:34 - 2018-07-20 08:14 - 000000827 _____ C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-416558941-4114933524-1477959264-1003\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
    HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper ->
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{05E95599-A3FD-439A-8D85-1BE379621C28}] => (Allow) LPort=51001
    FirewallRules: [{F1A5BBEC-1B65-4226-9A6C-6C9F2D1020A4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{32B26F90-9613-426E-B8EE-A4CFCB29F656}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{900C68BF-BC5A-43D6-8C00-06E0A3E147A9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
    FirewallRules: [{416EB221-E2CA-414F-8EDF-66034018DD61}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{A1957BB4-313F-4895-8D89-4CE11D33AAB6}] => (Allow) svchost.exe
    FirewallRules: [{27C71E7E-DE77-45C5-9073-3C17821FC708}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{66D2C177-EFE0-476C-B45A-390017068FE4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{C892209C-4838-408C-9B0B-81C21A408829}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{16483ED2-2F19-42F8-9A58-9C3DADD74365}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{E05A0239-55B8-41F2-B1F8-6A33E3671F60}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{C3CF0603-A5F7-4678-AC45-5A1791FA621D}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
    FirewallRules: [{590813D1-973A-4AB4-8E4F-B2928074E8BA}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
    FirewallRules: [TCP Query User{8A314CFC-BA97-4A25-B9B0-FBF76FD3A9AC}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
    FirewallRules: [UDP Query User{20CE46BA-CE0D-4AA6-825F-01ECB21895DD}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
    FirewallRules: [TCP Query User{D409BCB8-029C-46F8-A190-808F7409F926}C:\program files (x86)\xming\xming.exe] => (Allow) C:\program files (x86)\xming\xming.exe
    FirewallRules: [UDP Query User{3EF6B804-F633-4498-AD40-26A6A40635FE}C:\program files (x86)\xming\xming.exe] => (Allow) C:\program files (x86)\xming\xming.exe
    FirewallRules: [{F5182830-21B2-4221-B165-7A8F1FFB95C7}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
    FirewallRules: [{2D540887-F0FE-48E3-9675-0C9039BB8642}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
    FirewallRules: [{5142A274-1DFC-4155-B2CC-F98FA6E9D017}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
    FirewallRules: [{48B1E8CB-A89A-403A-9923-A362545EBF71}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
    FirewallRules: [{27B1DF1B-E389-4A63-A80C-7DA391B4468D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
    FirewallRules: [{1F8A85E0-748F-4EFE-B9AF-6F2FA34B6ADA}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
    FirewallRules: [{1FD2A459-9A0A-4A8C-A30C-F0C6E37D274D}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
    FirewallRules: [{E6BF8573-3540-42B9-AEC4-99E1DB1B00EE}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
    FirewallRules: [{B10D2B8A-016A-478B-9973-40503203D310}] => (Allow) C:\Users\Kushal Suryamohan\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{28A3B3C4-304F-4E78-A275-992A4ED37862}] => (Allow) C:\Users\Kushal Suryamohan\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{ACD4D217-998E-42BE-AAF7-E581A4A868FA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{B0F6ED75-A700-4BF1-A95E-FAE8F8EC5B5C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
    FirewallRules: [{7605BCA0-D4A4-484E-954B-04653721AD27}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
    FirewallRules: [{00D82B84-252B-4B85-AB1B-5F6C31ED8C7C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe

    ==================== Restore Points =========================

    25-06-2018 15:08:55 Scheduled Checkpoint
    11-07-2018 15:56:48 Windows Update

    ==================== Faulty Device Manager Devices =============

    Name: Unknown USB Device (Device Descriptor Request Failed)
    Description: Unknown USB Device (Device Descriptor Request Failed)
    Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
    Manufacturer: (Standard USB Host Controller)
    Service:
    Problem: : Windows has stopped this device because it has reported problems. (Code 43)
    Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (07/20/2018 08:27:18 AM) (Source: VSS) (EventID: 8193) (User: )
    Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
    .


    Operation:
    Executing Asynchronous Operation

    Context:
    Current State: DoSnapshotSet

    Error: (07/20/2018 08:25:53 AM) (Source: VSS) (EventID: 8193) (User: )
    Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
    .


    Operation:
    Executing Asynchronous Operation

    Context:
    Current State: DoSnapshotSet

    Error: (07/20/2018 06:26:48 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: sttray64.exe, version: 1.0.6217.0, time stamp: 0x4a490274
    Faulting module name: sttray64.exe, version: 1.0.6217.0, time stamp: 0x4a490274
    Exception code: 0xc000041d
    Fault offset: 0x000000000000cae5
    Faulting process id: 0x1dd0
    Faulting application start time: 0x01d420141a0ec544
    Faulting application path: C:\Program Files\IDT\WDM\sttray64.exe
    Faulting module path: C:\Program Files\IDT\WDM\sttray64.exe
    Report Id: e3541320-21a2-4b4b-b0db-0b23e2a03f38
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (07/20/2018 06:26:29 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: sttray64.exe, version: 1.0.6217.0, time stamp: 0x4a490274
    Faulting module name: sttray64.exe, version: 1.0.6217.0, time stamp: 0x4a490274
    Exception code: 0xc0000005
    Fault offset: 0x000000000000cae5
    Faulting process id: 0x1dd0
    Faulting application start time: 0x01d420141a0ec544
    Faulting application path: C:\Program Files\IDT\WDM\sttray64.exe
    Faulting module path: C:\Program Files\IDT\WDM\sttray64.exe
    Report Id: e4129f12-6edc-41bc-a47a-bc671fdce584
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (07/20/2018 06:21:37 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.17134.1, time stamp: 0x5ace103a
    Faulting module name: Windows.UI.Xaml.dll, version: 10.0.17134.81, time stamp: 0x4f4899f8
    Exception code: 0xc00001ad
    Fault offset: 0x00000000003768cf
    Faulting process id: 0x23dc
    Faulting application start time: 0x01d4201330e76fb2
    Faulting application path: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
    Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll
    Report Id: 6be3c04a-fcb7-4c55-9f08-d00edd0129d1
    Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy
    Faulting package-relative application ID: App

    Error: (07/20/2018 06:21:04 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: minidump-analyzer.exe, version: 61.0.1.6759, time stamp: 0x5b3c2519
    Faulting module name: mozglue.dll, version: 61.0.1.6759, time stamp: 0x5b3c2501
    Exception code: 0x80000003
    Fault offset: 0x000000000001a9c9
    Faulting process id: 0xd4
    Faulting application start time: 0x01d420135d2e06d3
    Faulting application path: C:\Program Files (x86)\Mozilla Firefox\minidump-analyzer.exe
    Faulting module path: C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
    Report Id: 060c74c8-3f44-4fa3-a4ff-85a81834cb64
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (07/20/2018 06:19:23 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: dwm.exe, version: 10.0.17134.1, time stamp: 0xf5178e97
    Faulting module name: dwmcore.dll, version: 10.0.17134.137, time stamp: 0x2ba8c5ae
    Exception code: 0xc00001ad
    Fault offset: 0x00000000001ce072
    Faulting process id: 0x163c
    Faulting application start time: 0x01d41ef2eb4b1a15
    Faulting application path: C:\WINDOWS\System32\dwm.exe
    Faulting module path: C:\WINDOWS\System32\dwmcore.dll
    Report Id: 8530d55b-5fa9-4bbd-9bb1-63bc70478deb
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (07/20/2018 06:04:27 AM) (Source: SideBySide) (EventID: 35) (User: )
    Description: Activation context generation failed for "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8.
    Component identity found in manifest does not match the identity of the component requested.
    Reference is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
    Definition is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
    Please use sxstrace.exe for detailed diagnosis.


    System errors:
    =============
    Error: (07/20/2018 08:18:48 AM) (Source: DCOM) (EventID: 10016) (User: MENS-LAPTOP2)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user MENS-LAPTOP2\NCT Mens SID (S-1-5-21-416558941-4114933524-1477959264-1003) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 08:13:11 AM) (Source: DCOM) (EventID: 10016) (User: MENS-LAPTOP2)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user MENS-LAPTOP2\NCT Mens SID (S-1-5-21-416558941-4114933524-1477959264-1003) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 08:09:56 AM) (Source: DCOM) (EventID: 10016) (User: MENS-LAPTOP2)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {9E175B6D-F52A-11D8-B9A5-505054503030}
    and APPID
    {9E175B9C-F52A-11D8-B9A5-505054503030}
    to the user MENS-LAPTOP2\NCT Mens SID (S-1-5-21-416558941-4114933524-1477959264-1003) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 08:09:56 AM) (Source: DCOM) (EventID: 10016) (User: MENS-LAPTOP2)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {9E175B6D-F52A-11D8-B9A5-505054503030}
    and APPID
    {9E175B9C-F52A-11D8-B9A5-505054503030}
    to the user MENS-LAPTOP2\NCT Mens SID (S-1-5-21-416558941-4114933524-1477959264-1003) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 08:09:56 AM) (Source: DCOM) (EventID: 10016) (User: MENS-LAPTOP2)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {9E175B6D-F52A-11D8-B9A5-505054503030}
    and APPID
    {9E175B9C-F52A-11D8-B9A5-505054503030}
    to the user MENS-LAPTOP2\NCT Mens SID (S-1-5-21-416558941-4114933524-1477959264-1003) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 06:27:21 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
    Windows.SecurityCenter.WscBrokerManager
    and APPID
    Unavailable
    to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (07/20/2018 06:25:09 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The NetTcpActivator service depends on the WAS service which failed to start because of the following error:
    The system cannot find the file specified.

    Error: (07/20/2018 06:24:55 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The W3SVC service depends on the WAS service which failed to start because of the following error:
    The system cannot find the file specified.


    Windows Defender:
    ===================================
    Date: 2018-07-20 08:12:25.526
    Description:
    Controlled Folder Access blocked C:\Program Files\AVAST Software\Avast\setup\instup.exe from making changes to memory.
    Detection time: 2018-07-20T12:12:25.526Z
    Path: \Device\Harddisk0\DR0
    Process Name: C:\Program Files\AVAST Software\Avast\setup\instup.exe
    Signature Version: 1.273.76.0
    Engine Version: 1.1.15100.1
    Product Version: 4.18.1806.18062

    Date: 2018-07-20 08:12:25.237
    Description:
    Controlled Folder Access blocked C:\Program Files\AVAST Software\Avast\wsc_proxy.exe from making changes to memory.
    Detection time: 2018-07-20T12:12:25.236Z
    Path: \Device\Harddisk0\DR0
    Process Name: C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
    Signature Version: 1.273.76.0
    Engine Version: 1.1.15100.1
    Product Version: 4.18.1806.18062

    Date: 2018-07-20 08:12:23.915
    Description:
    Controlled Folder Access blocked C:\Program Files\AVAST Software\Avast\setup\instup.exe from making changes to memory.
    Detection time: 2018-07-20T12:12:23.914Z
    Path: \Device\Harddisk0\DR0
    Process Name: C:\Program Files\AVAST Software\Avast\setup\instup.exe
    Signature Version: 1.273.76.0
    Engine Version: 1.1.15100.1
    Product Version: 4.18.1806.18062

    Date: 2018-07-20 08:12:23.794
    Description:
    Controlled Folder Access blocked C:\Program Files\AVAST Software\Avast\setup\instup.exe from making changes to memory.
    Detection time: 2018-07-20T12:12:23.793Z
    Path: \Device\Harddisk0\DR0
    Process Name: C:\Program Files\AVAST Software\Avast\setup\instup.exe
    Signature Version: 1.273.76.0
    Engine Version: 1.1.15100.1
    Product Version: 4.18.1806.18062

    Date: 2018-07-20 08:12:14.908
    Description:
    Controlled Folder Access blocked C:\Program Files\AVAST Software\Avast\AvastSvc.exe from making changes to memory.
    Detection time: 2018-07-20T12:12:14.907Z
    Path: \Device\Harddisk0\DR0
    Process Name: C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    Signature Version: 1.273.76.0
    Engine Version: 1.1.15100.1
    Product Version: 4.18.1806.18062

    Date: 2018-06-17 19:17:46.972
    Description:
    Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: On Access
    Error Code: 0x80004005
    Error description: Unspecified error
    Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.

    Date: 2018-06-10 14:24:19.496
    Description:
    Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: On Access
    Error Code: 0x80004005
    Error description: Unspecified error
    Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.

    Date: 2018-06-08 15:49:10.172
    Description:
    Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
    Feature: On Access
    Error Code: 0x80004005
    Error description: Unspecified error
    Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.

    CodeIntegrity:
    ===================================

    Date: 2018-07-17 10:57:59.270
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:59.194
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:59.100
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:58.858
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:58.823
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:58.777
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:53.333
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-07-17 10:57:51.864
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz
    Percentage of memory in use: 63%
    Total physical RAM: 3956.52 MB
    Available physical RAM: 1442.42 MB
    Total Virtual: 7924.52 MB
    Available Virtual: 4701.13 MB

    ==================== Drives ================================

    Drive c: (Machine) (Fixed) (Total:451.07 GB) (Free:381.44 GB) NTFS

    \\?\Volume{c1d4b8ae-0653-11df-94db-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:14.65 GB) (Free:9.82 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: CF5AC2F0)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=451.1 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

  8. #8
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    I don't see anything malicious there.
    If those issues started with new display driver I'd suggest reinstalling previous one.

  9. #9
    Join Date
    Jul 2018
    Posts
    7
    Thanks

    But the thing is I didnt install the new driver...the system went to an automatic default driver of some sort. I will watch it and if anything else happens let you know

    Dave

  10. #10
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •