Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-09-2017 02Ran by Owner (administrator) on ACER-PC (23-09-2017 16:30:27)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner & Guest)
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files\SRWare Iron\chrome.exe" -- "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCService.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\Monitor.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
() C:\Program Files\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(KeepSolid Inc.) C:\Program Files\VPN Unlimited\vpn-unlimited-daemon.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ALi) C:\Windows\WebCam\S6000\S6000Mnt.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(LastPass) C:\Program Files\LastPass\lastapp.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(KeepSolid Inc.) C:\Program Files\VPN Unlimited\vpn-unlimited.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
() C:\Program Files\MightyText\MightyText.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
() C:\Program Files\VPN Unlimited\QtWebEngineProcess.exe
(The OpenVPN Project) C:\Program Files\VPN Unlimited\openvpn.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
() C:\Program Files\Siber Systems\GoodSync\gs-server.exe
() C:\Program Files\Box\Box Sync\BoxSyncMonitor.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKLM\...\Run: [S6000Mnt] => Rundll32.exe S6000Rmv.dll ,WinMainRmv /StartStillMnt
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [16553472 2017-08-06] (Realtek Semiconductor)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM\...\Run: [LastApp] => C:\Program Files\LastPass\lastapp.exe [30021712 2016-01-05] (LastPass)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [1812264 2010-11-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Dropbox] => C:\Program Files\Dropbox\Client\Dropbox.exe [3481912 2017-09-20] (Dropbox, Inc.)
HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5079024 2017-08-07] (Box, Inc.)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [714120 2011-01-05] (Acer Incorporated)
HKLM\...\Policies\Explorer: [MemCheckBoxInRunDlg] 1
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\...\Run: [Advanced SystemCare Ultimate] => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [3023136 2017-06-19] (IObit)
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\...\Run: [VPN Unlimited] => C:\Program Files\VPN Unlimited\vpn-unlimited-launcher.exe [398168 2017-05-16] (KeepSolid Inc.)
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\...\Run: [GUDelayStartup] => C:\Program Files\Glary Utilities 5\StartupManager.exe [44024 2017-09-15] (Glarysoft Ltd)
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-07-26]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-11-03]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MightyText.lnk [2016-07-21]
ShortcutTarget: MightyText.lnk -> C:\Program Files\MightyText\MightyText.exe ()
BootExecute: autocheck autochk * SmartDefragBootTime.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.204.0.1
Tcpip\..\Interfaces\{47BC881C-BF9B-4DC1-BAFD-B4EF2317C2DB}: [DhcpNameServer] 10.204.0.1
Tcpip\..\Interfaces\{8BA8B11D-3CDE-4E4D-AB6D-2FE701155FB2}: [DhcpNameServer] 192.168.29.1
Tcpip\..\Interfaces\{F433C961-DA20-4C9D-A7EB-CBC403AE569F}: [DhcpNameServer] 192.168.29.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=avantsearch6
HKU\S-1-5-21-2533281548-2792480986-1104297636-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2533281548-2792480986-1104297636-1000 -> DefaultScope {4047CC5C-7BF8-4509-B638-9B80ED1B934D} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-2533281548-2792480986-1104297636-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2533281548-2792480986-1104297636-1000 -> {4047CC5C-7BF8-4509-B638-9B80ED1B934D} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer.dll [2017-03-28] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-09-07] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files\Evernote\Evernote\EvernoteIE.dll [2017-09-07] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files\LastPass\LPToolbar.dll [2016-07-26] (LastPass)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-07] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll [2016-07-26] (LastPass)
Toolbar: HKU\S-1-5-21-2533281548-2792480986-1104297636-1000 -> No Name - {724D43A0-0D85-11D4-9908-00400523E39A} - No File
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)
Handler: skype4com - No CLSID Value -
FireFox:
========
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-08-22] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-09-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-09-07] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files\LastPass\nplastpass.dll [2016-07-26] (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService10; C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCService.exe [1013024 2017-04-05] (IObit)
R2 ASCAntivirusSrv; C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [1931552 2017-01-06] (IObit)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [36680 2017-08-07] (Box, Inc.)
S2 dbupdate; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-12-03] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-12-03] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [43336 2017-09-20] (Dropbox, Inc.)
R2 EaseUS Agent; C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [40080 2017-08-30] (CHENGDU YIWO Tech Development Co., Ltd)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [734592 2011-01-05] (Acer Incorporated)
R2 FoxitReaderService; C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659456 2017-08-25] (Foxit Software Inc.)
R2 GsServer; C:\Program Files\Siber Systems\GoodSync\gs-server.exe [5032672 2017-08-23] ()
S2 IObitUnSvr; C:\Program Files\IObit\IObit Uninstaller\IUService.exe [360736 2017-03-28] (IObit)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3398608 2017-05-09] (Malwarebytes)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
S3 SystemExplorerHelpService; C:\Program Files\System Explorer\service\SystemExplorerService.exe [567008 2014-12-20] (Mister Group)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [10803440 2017-08-29] (TeamViewer GmbH)
R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-28] (Acer Group)
R2 VPNUnlimitedService; C:\Program Files\VPN Unlimited\vpn-unlimited-daemon.exe [62296 2017-05-16] (KeepSolid Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [59936 2017-07-01] ()
R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [116008 2010-11-12] (ELAN Microelectronics Corp.)
R0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [56824 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [46584 2016-12-06] ()
R1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [20984 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [195576 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [17472 2015-08-11] (Glarysoft Ltd)
R2 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [196640 2016-10-27] (BitDefender LLC)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-08-31] (REALiX(tm))
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2015-08-31] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [162240 2017-09-14] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [85400 2017-09-23] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [40352 2017-09-23] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [221600 2017-09-23] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [65824 2017-09-23] (Malwarebytes)
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [167576 2015-08-31] (Windows (R) Win 7 DDK provider)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18800 2016-03-22] (IObit)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 Trufos; C:\Windows\System32\DRIVERS\TRUFOS.sys [458656 2016-11-02] (BitDefender S.R.L.)
S3 dbx; system32\DRIVERS\dbx.sys [X]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-23 16:30 - 2017-09-23 16:32 - 000016633 _____ C:\Users\Owner\Desktop\FRST.txt
2017-09-23 16:27 - 2017-09-23 16:26 - 001796096 _____ (Farbar) C:\Users\Owner\Desktop\FRST.exe
2017-09-23 11:36 - 2017-09-23 11:36 - 000000000 ___HD C:\OneDriveTemp
2017-09-21 15:14 - 2017-09-21 15:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-09-21 10:57 - 2017-09-21 11:00 - 160334608 _____ (Microsoft Corporation) C:\Users\Owner\Desktop\msert.exe
2017-09-20 11:48 - 2017-09-20 11:48 - 000043336 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-09-20 11:48 - 2017-09-20 11:48 - 000035432 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-09-20 11:48 - 2017-09-20 11:48 - 000035408 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-09-20 11:48 - 2017-09-20 11:48 - 000035408 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-09-20 10:59 - 2017-08-19 10:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-09-20 10:59 - 2017-08-19 10:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-09-20 10:59 - 2017-08-19 09:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-09-20 10:59 - 2017-08-19 09:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-09-20 10:59 - 2017-08-14 12:39 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-09-20 10:59 - 2017-08-14 12:39 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-09-20 10:59 - 2017-08-14 12:35 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-09-20 10:59 - 2017-08-14 12:35 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-09-20 10:59 - 2017-08-13 16:35 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-09-20 10:59 - 2017-08-13 16:30 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-09-20 10:59 - 2017-08-13 16:26 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-09-20 10:59 - 2017-08-13 16:26 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-09-20 10:59 - 2017-08-13 16:26 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-09-20 10:59 - 2017-08-13 16:26 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-09-20 10:59 - 2017-08-13 16:26 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-09-20 10:59 - 2017-08-13 16:26 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-09-20 10:58 - 2017-08-19 10:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-09-20 10:58 - 2017-08-14 12:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-09-18 22:36 - 2017-09-18 22:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Greenshot
2017-09-18 22:36 - 2017-09-18 22:36 - 000000000 ____D C:\Program Files\Greenshot
2017-09-18 22:24 - 2017-09-18 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2017-09-16 18:35 - 2017-09-23 16:30 - 000000000 ____D C:\FRST
2017-09-14 20:00 - 2017-08-15 19:25 - 000347336 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-09-14 20:00 - 2017-08-15 09:01 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-09-14 20:00 - 2017-08-15 09:01 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-09-14 20:00 - 2017-08-15 09:01 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-09-14 20:00 - 2017-08-15 08:58 - 013673984 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-09-14 20:00 - 2017-08-13 11:54 - 020269056 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-09-14 20:00 - 2017-08-13 11:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-09-14 20:00 - 2017-08-13 11:45 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-09-14 20:00 - 2017-08-13 11:30 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-09-14 20:00 - 2017-08-13 11:29 - 000499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-09-14 20:00 - 2017-08-13 11:29 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-09-14 20:00 - 2017-08-13 11:28 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-09-14 20:00 - 2017-08-13 11:24 - 002291200 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-09-14 20:00 - 2017-08-13 11:22 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-09-14 20:00 - 2017-08-13 11:21 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-09-14 20:00 - 2017-08-13 11:19 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-09-14 20:00 - 2017-08-13 11:17 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-09-14 20:00 - 2017-08-13 11:17 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-09-14 20:00 - 2017-08-13 11:17 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-09-14 20:00 - 2017-08-13 11:01 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-09-14 20:00 - 2017-08-13 11:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-14 20:00 - 2017-08-13 11:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-09-14 20:00 - 2017-08-13 10:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-09-14 20:00 - 2017-08-13 10:48 - 004547072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-09-14 20:00 - 2017-08-13 10:46 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-09-14 20:00 - 2017-08-13 10:44 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-09-14 20:00 - 2017-08-13 10:44 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-09-14 20:00 - 2017-08-13 10:43 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-09-14 20:00 - 2017-08-13 10:17 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-09-14 20:00 - 2017-08-13 10:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-09-14 20:00 - 2017-08-13 10:13 - 001314816 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-09-14 19:59 - 2017-08-19 10:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-09-14 19:59 - 2017-08-16 10:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-09-14 19:59 - 2017-08-16 09:50 - 002403328 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-09-14 19:59 - 2017-08-15 10:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-09-14 19:59 - 2017-08-15 10:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-09-14 19:59 - 2017-08-14 12:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-09-14 19:59 - 2017-08-14 12:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2017-09-14 19:59 - 2017-08-14 12:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2017-09-14 19:59 - 2017-08-14 12:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2017-09-14 19:59 - 2017-08-13 16:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-09-14 19:59 - 2017-08-13 11:29 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-09-14 19:59 - 2017-08-13 11:18 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-09-14 19:59 - 2017-08-13 11:10 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-14 19:59 - 2017-08-13 10:53 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-09-14 19:59 - 2017-08-13 10:43 - 002058752 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-09-14 19:59 - 2017-08-11 01:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-09-14 19:59 - 2017-08-11 01:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-09-14 19:59 - 2017-08-11 01:21 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000781824 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000019968 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 01:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-09-14 19:59 - 2017-08-11 01:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-09-14 19:59 - 2017-08-11 01:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-09-14 19:59 - 2017-08-11 01:00 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-09-14 19:59 - 2017-08-11 01:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-09-14 19:59 - 2017-08-11 01:00 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-09-14 19:59 - 2017-08-11 01:00 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-09-14 19:59 - 2017-08-11 00:58 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-09-14 19:59 - 2017-08-11 00:58 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-09-14 19:59 - 2017-08-11 00:56 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-09-14 19:59 - 2017-08-11 00:56 - 000311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-09-14 19:59 - 2017-08-11 00:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-09-14 19:59 - 2017-08-11 00:55 - 000188928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-09-14 19:59 - 2017-08-11 00:55 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-09-14 19:59 - 2017-08-11 00:55 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-09-14 19:59 - 2017-08-11 00:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 00:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 00:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-14 19:59 - 2017-08-11 00:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-14 19:59 - 2017-07-29 09:50 - 000074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-09-14 19:59 - 2017-07-21 09:26 - 000518144 _____ C:\Windows\system32\msjetoledb40.dll
2017-09-14 19:59 - 2017-07-21 09:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll
2017-09-14 19:59 - 2017-07-21 09:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll
2017-09-14 19:59 - 2017-07-21 09:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-09-14 19:59 - 2017-07-14 10:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-09-14 19:59 - 2017-07-14 10:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-09-14 19:59 - 2017-07-14 10:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-09-14 19:59 - 2017-07-14 09:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-09-14 19:59 - 2017-07-14 09:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-09-14 19:59 - 2017-07-14 09:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-09-14 19:59 - 2017-07-14 09:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-09-14 19:59 - 2017-07-08 10:19 - 000250600 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-09-14 19:59 - 2017-07-07 10:15 - 000296680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-09-14 19:59 - 2017-07-07 10:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-09-14 19:59 - 2017-07-07 10:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll
2017-09-14 19:59 - 2017-07-01 08:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll
2017-09-13 12:21 - 2017-09-13 12:21 - 000000000 ____D C:\ProgramData\SystemAcCrux
2017-09-12 12:23 - 2017-09-12 12:27 - 239126136 _____ C:\Users\Owner\Desktop\Windows6.1-KB947821-v34-x86.msu
2017-09-11 09:17 - 2017-09-11 09:16 - 000197679 _____ C:\Users\Owner\Desktop\ListChkdskResult.exe
2017-09-09 20:52 - 2017-09-09 20:52 - 002884096 _____ (niemiro) C:\Users\Owner\Desktop\SFCFix.exe
2017-09-08 02:15 - 2017-09-21 09:15 - 000269104 _____ C:\Windows\system32\FNTCACHE.DAT
2017-09-08 01:37 - 2017-09-08 01:37 - 000058016 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2017-09-08 00:23 - 2017-09-08 00:23 - 000000000 ____D C:\Program Files\Common Files\Skype
2017-09-08 00:18 - 2017-09-08 00:18 - 000000933 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-09-08 00:18 - 2017-09-08 00:18 - 000000921 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-09-08 00:08 - 2017-09-08 00:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMPlayer
2017-09-08 00:01 - 2017-09-08 00:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoodSync
2017-09-07 23:59 - 2017-09-07 23:59 - 000000000 ____D C:\Program Files\Common Files\Java
2017-09-07 23:35 - 2017-09-07 23:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2017-09-07 22:42 - 2017-09-07 22:42 - 000000590 _____ C:\Users\Owner\Desktop\foo (TM-AC1900-A9C0) (M).lnk
2017-09-07 22:27 - 2017-09-19 22:22 - 000000000 ____D C:\SFCFix
2017-09-07 22:21 - 2017-09-19 22:22 - 000000000 ____D C:\Users\Owner\AppData\Local\niemiro
2017-09-07 18:00 - 2017-09-07 18:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync
2017-09-07 17:11 - 2016-03-22 11:02 - 000018800 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-23 16:30 - 2011-01-11 19:37 - 000000000 ____D C:\Windows\system32\Macromed
2017-09-23 16:29 - 2015-08-09 19:58 - 000000000 ___RD C:\Users\Owner\Dropbox
2017-09-23 16:07 - 2016-12-03 19:41 - 000000894 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-09-23 15:41 - 2015-08-08 23:28 - 000000000 ____D C:\Users\Owner\AppData\Local\Adobe
2017-09-23 15:40 - 2015-08-10 22:26 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-09-23 15:40 - 2015-08-10 22:26 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-09-23 15:39 - 2016-12-09 10:47 - 000000982 _____ C:\Users\Public\Desktop\SRWare Iron.lnk
2017-09-23 15:39 - 2016-02-29 20:28 - 000001044 _____ C:\Users\Public\Desktop\Iron Config and Backup.lnk
2017-09-23 15:39 - 2015-08-17 14:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron
2017-09-23 15:39 - 2015-08-17 14:40 - 000000000 ____D C:\Program Files\SRWare Iron
2017-09-23 15:22 - 2009-07-13 23:34 - 000016480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-23 15:22 - 2009-07-13 23:34 - 000016480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-23 15:11 - 2017-06-17 20:00 - 000085400 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-09-23 15:11 - 2017-06-17 00:30 - 000065824 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-09-23 15:11 - 2017-06-17 00:29 - 000040352 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-09-23 15:11 - 2017-06-17 00:26 - 000221600 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-09-23 15:11 - 2016-01-27 21:58 - 000000000 ___RD C:\Users\Owner\OneDrive
2017-09-23 15:10 - 2016-12-03 19:41 - 000000890 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-09-23 15:10 - 2009-07-13 23:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-23 11:37 - 2015-08-12 15:27 - 000000000 ____D C:\ProgramData\ProductData
2017-09-23 11:33 - 2015-08-09 22:36 - 000000000 ____D C:\Windows\pss
2017-09-21 18:22 - 2015-08-08 23:57 - 000000000 ____D C:\ProgramData\boost_interprocess
2017-09-21 17:56 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\rescache
2017-09-21 15:14 - 2016-12-03 19:41 - 000000000 ____D C:\Program Files\Dropbox
2017-09-21 09:25 - 2011-01-11 18:29 - 000782656 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-21 09:25 - 2009-07-13 21:37 - 000000000 ____D C:\Windows\inf
2017-09-18 23:08 - 2015-08-11 09:10 - 000000000 ____D C:\Users\Owner\Desktop\shortcuts
2017-09-18 23:08 - 2015-08-11 08:59 - 000000000 ____D C:\Program Files\CCleaner
2017-09-18 22:38 - 2015-08-11 12:03 - 000000000 ____D C:\Program Files\Glary Utilities 5
2017-09-18 22:02 - 2015-08-11 12:03 - 000001058 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2017-09-15 11:54 - 2015-08-11 12:21 - 000000000 ____D C:\Users\Owner\AppData\Roaming\GoodSync
2017-09-14 20:12 - 2015-08-08 23:42 - 000000000 ____D C:\Windows\system32\MRT
2017-09-14 20:02 - 2015-08-08 23:42 - 135337392 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-09-14 19:40 - 2015-08-09 22:40 - 000002163 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-09-14 19:29 - 2017-06-17 00:31 - 000162240 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-09-13 12:21 - 2017-05-24 10:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup 10.6
2017-09-09 21:05 - 2017-07-16 22:12 - 001309928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-09-09 21:05 - 2017-07-16 22:12 - 001213672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-09-09 21:05 - 2017-07-16 22:12 - 000187624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-09-09 21:05 - 2016-12-13 21:48 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2017-09-09 21:05 - 2016-09-22 08:56 - 000437248 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-09-09 12:13 - 2017-07-16 22:12 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2017-09-09 12:13 - 2017-06-14 00:04 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-09-09 12:13 - 2017-06-14 00:04 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-09-09 12:13 - 2017-06-14 00:04 - 000073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-09-09 12:13 - 2017-06-14 00:04 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-09-09 12:13 - 2017-06-14 00:04 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-09-09 12:13 - 2017-06-14 00:04 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-09-09 12:13 - 2017-06-14 00:04 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-09-09 12:13 - 2017-05-11 23:57 - 000338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-09-09 12:13 - 2017-04-12 08:00 - 002746880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-09-09 12:13 - 2017-04-12 08:00 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-09-09 12:13 - 2017-04-12 08:00 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2017-09-09 12:13 - 2017-03-30 08:21 - 000066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-09-09 12:13 - 2017-03-30 08:21 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-09-09 12:13 - 2017-03-30 08:21 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-09-09 12:13 - 2017-03-30 08:21 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-09-09 12:13 - 2016-11-09 11:20 - 002291712 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2017-09-09 12:13 - 2016-11-09 11:20 - 000202240 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2017-09-09 12:13 - 2016-11-09 11:20 - 000187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-09-09 12:13 - 2016-11-02 17:08 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2017-09-09 12:13 - 2016-10-11 17:48 - 000208896 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-09-09 12:13 - 2016-10-11 17:48 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2017-09-09 12:13 - 2016-09-22 08:56 - 001178112 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2017-09-09 12:13 - 2016-09-22 08:56 - 000249344 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2017-09-09 12:13 - 2016-09-22 08:56 - 000214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2017-09-09 12:13 - 2016-09-22 08:56 - 000199168 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2017-09-09 12:13 - 2016-09-22 08:56 - 000146944 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2017-09-09 12:13 - 2016-09-22 08:55 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2017-09-09 12:13 - 2016-09-22 08:55 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2017-09-09 12:13 - 2016-09-22 08:55 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2017-09-09 12:13 - 2015-08-10 21:44 - 000014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2017-09-09 12:13 - 2009-07-13 17:06 - 000201034 _____ C:\Windows\system32\winrm.vbs
2017-09-09 12:13 - 2009-07-13 17:06 - 000004675 _____ C:\Windows\system32\wsmanconfig_schema.xml
2017-09-09 12:13 - 2009-07-13 17:06 - 000002426 _____ C:\Windows\system32\WsmTxt.xsl
2017-09-09 12:13 - 2009-07-13 17:06 - 000001559 _____ C:\Windows\system32\WsmPty.xsl
2017-09-09 12:13 - 2009-06-10 16:40 - 000000035 _____ C:\Windows\system32\winrm.cmd
2017-09-09 12:12 - 2017-07-16 22:12 - 001227264 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-09-09 12:12 - 2017-07-16 22:12 - 000390144 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2017-09-09 12:12 - 2017-07-16 22:12 - 000303616 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-09-09 12:12 - 2017-07-16 22:12 - 000240872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-09-09 12:12 - 2017-07-16 22:12 - 000157184 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2017-09-09 12:12 - 2017-07-16 22:12 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2017-09-09 12:12 - 2017-07-16 22:12 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2017-09-09 12:12 - 2017-07-05 00:31 - 000730856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-09-09 12:12 - 2017-07-05 00:31 - 000218856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-09-09 12:12 - 2017-07-05 00:31 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-09-09 12:12 - 2017-06-14 00:04 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-09-09 12:12 - 2017-06-14 00:04 - 000078568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-09-09 12:12 - 2017-06-14 00:04 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-09-09 12:12 - 2017-04-20 08:27 - 001508352 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-09-09 12:12 - 2017-04-20 08:27 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-09-09 12:12 - 2017-04-12 08:00 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-09-09 12:12 - 2017-04-12 08:00 - 000067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-09-09 12:12 - 2017-03-14 23:24 - 000741888 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-09-09 12:12 - 2017-03-14 23:24 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-09-09 12:12 - 2016-12-13 21:48 - 000105192 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2017-09-09 12:12 - 2016-12-13 21:48 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2017-09-09 12:12 - 2016-11-22 15:17 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2017-09-09 12:12 - 2016-11-09 11:20 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2017-09-09 12:12 - 2016-09-22 08:56 - 012574208 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2017-09-09 12:12 - 2016-09-22 08:56 - 011410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-09-09 12:12 - 2016-09-22 08:56 - 000988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2017-09-09 12:12 - 2016-09-22 08:56 - 000744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2017-09-09 12:12 - 2016-09-22 08:56 - 000617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2017-09-09 12:12 - 2016-09-22 08:55 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2017-09-09 12:12 - 2016-09-22 08:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2017-09-09 12:12 - 2016-09-22 08:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2017-09-09 12:12 - 2009-07-13 16:28 - 000145519 _____ C:\Windows\system32\perfmon.msc
2017-09-09 12:11 - 2016-09-22 08:56 - 000442368 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-09-09 12:11 - 2016-09-22 08:55 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-09-08 00:26 - 2017-03-03 16:08 - 000000000 ____D C:\Users\Owner\AppData\Roaming\Skype
2017-09-08 00:24 - 2017-03-06 16:11 - 000000000 ___RD C:\Program Files\Skype
2017-09-08 00:23 - 2017-03-04 20:33 - 000000000 ____D C:\ProgramData\Skype
2017-09-08 00:18 - 2015-08-09 15:54 - 000000000 ____D C:\Program Files\TeamViewer
2017-09-08 00:11 - 2015-08-11 21:45 - 000000000 ____D C:\Users\Owner\.smplayer
2017-09-08 00:08 - 2015-08-11 21:44 - 000000000 ____D C:\Program Files\SMPlayer
2017-09-07 23:58 - 2015-08-10 22:19 - 000000000 ____D C:\ProgramData\Oracle
2017-09-07 23:48 - 2015-08-10 22:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-09-07 23:47 - 2015-08-10 22:20 - 000095808 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2017-09-07 23:45 - 2015-08-10 22:19 - 000000000 ____D C:\Program Files\Java
2017-09-07 23:37 - 2016-06-29 10:41 - 000000000 ____D C:\ProgramData\Foxit Software
2017-09-07 22:11 - 2017-01-10 18:50 - 010026094 ____H C:\Users\Owner\AppData\Local\IconCache.db.backup
2017-09-07 17:58 - 2016-06-15 22:53 - 000000000 ____D C:\Users\Owner\AppData\Local\MightyText
2017-09-07 17:09 - 2016-04-21 04:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
==================== Files in the root of some directories =======
2016-02-11 21:51 - 2016-07-26 07:51 - 017348120 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2015-08-10 00:41 - 2017-03-01 23:44 - 000007600 _____ () C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
2016-06-29 10:18 - 2016-06-29 10:18 - 000000077 _____ () C:\Users\Owner\AppData\Local\smplayerhdpi.ini
2015-08-31 22:48 - 2015-08-31 22:48 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-09-20 12:24
==================== End of FRST.txt ============================