[SOLVED] [Win7Pro x64] Win.Update has issues installing updates properly

Platinum Lucario

Active member
Joined
Apr 1, 2017
Posts
39
Not too long ago, I had some SFC and Windows Update corruptions due to bad RAM, which have now been fixed in an earlier thread that I made.

So now that my Windows Update and SFC issues are out of the way. I did a test run to install updates today on the same machine, only to notice that the updates successfully installed, and even says that it successfully installed in the history log. But the updates don't show up in the installed updates area, and the updates will just keep re-appearing.

These updates, are mainly Office-related updates, which I don't even have any Microsoft Office programs installed on the OS. So from what I can see, it thinks there is Office entries, but when it installs, it can't find the folders.

Normally this should result in an error, but it doesn't, and instead just results in a "Update Installed Successfully" and even shows "Successful" in the Update History, but it's not in the installed updates though.

So I ran a Process Monitor, then I viewed the results. Many of the processes come back saying "NAME NOT FOUND" in the result category. I remember long ago when I tried to uninstall Microsoft Office 2003 manually (without requiring the disc), which would've been part of the problem. The only leftovers of Microsoft Office 2003 I didn't remove, were the registry entries, which would also be contributing to the issue that I'm having with the updates.

If anyone wants to take a look into the first PML file, you're more than welcome to. It's right here!

The next issue I have regarding problems installing updates, is actually to do with Microsoft Security Essentials itself. For one thing, if attempted to install, it will fail with error code 8004FF80. The one thing I noticed in the Process Manager with this one, is that there shows some results saying "BUFFER OVERFLOW" with the process UpdateInstall.exe. Also, attempting to uninstall MSE will also result in the same error code. So I'd say there is possibly some corrupt entries with MSE as well. I'd say that it also got damaged by bad RAM in the past as well. If anyone wants to take a look at the PML for this error, here it is!

I also ran a dism /online /cleanup-image /scanhealth. And everything seems fine except for Avast-related files. Here's the output of Checksur.txt:
Code:
=================================
Checking System Update Readiness.
Binary Version 6.1.7601.23471
2017-04-07 00:01

Checking Windows Servicing Packages

Checking Package Manifests and Catalogs

Checking Package Watchlist

Checking Component Watchlist

Checking Packages

Checking Component Store
(f)	CSI C Mark Deployment Missing	0x00000000	c!avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_0b20a8ff883c3a4a	x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c	
(f)	CSI C Mark Deployment Missing	0x00000000	c!avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_c373722873c01144	amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396	
(f)	CSI C Mark Deployment Missing	0x00000000	c!avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_49391d6d8244622b	x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_none_a338d8ea2df29efb	
(f)	CSI C Mark Deployment Missing	0x00000000	c!policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_ef17e13d91c55d96	amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_499a1b14d5902dfc	
(f)	CSI C Mark Deployment Missing	0x00000000	c!policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_36c51814a641869c	x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_914751ebea0c5702	
(f)	CSI C Mark Deployment Missing	0x00000000	c!avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_020285fe6d6e0580	amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_56aba0211ca246c2	
(f)	CSI C Mark Deployment Missing	0x00000000	c!policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_364e78aca69bba41	x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_none_962753dde6e08635	
(f)	CSI C Mark Deployment Missing	0x00000000	c!avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_49afbcd581ea2e86	x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8	

Summary:
Seconds executed: 676
 Found 8 errors
  CSI C Mark Deployment Missing Total count: 8

So looks like, there's still more corruptions that need to be fixed, which probably lurk outside of Windows Update and SFC. Mostly to do with programs that don't exist and MSE.
 
Let's address one issue at a time. We'll focus on the office updates first. Can you provide me the KB numbers of the office updates that are installing/failing?
 
Alrighty, here's the list of Office 2003-related Updates:

KB982311 - Security Update for Microsoft Office 2003
KB950625 - Security Update for Microsoft Office Word Viewer 2003
KB920813 - Security Update for Office 2003
KB936048 - Security Update for Office 2003
KB954478 - Security Update for Office 2003
KB2543854 - Update for Microsoft Office 2003
KB919029 - Update for Office 2003
SP3 - Word Viewer 2003 Service Pack 3

Here's the list of updates for Office 2010-related updates:

KB2687456 - Service Pack 2 for Microsoft PowerPoint Viewer, 32-Bit Edition
KB2553310 - Update for Microsoft Office 2010, 32-Bit Edition
KB2553347 - Update for Microsoft Office 2010, 32-Bit Edition
KB2553065 - Update for Office File Validation 2010, 32-Bit Edition

Here's the Office 2007-related updates:

KB2596615 - Security Update for Microsoft Office 2007 suites
KB2596672 - Security Update for Microsoft Office 2007 suites
KB2596785 - Security Update for Microsoft Office 2007 suites
KB2687311 - Security Update for Microsoft Office 2007 suites
KB2687499 - Security Update for Microsoft Office 2007 suites
KB2760416 - Security Update for Microsoft Office 2007 suites
KB2596843 - Security Update for Microsoft Office PowerPoint 2007
KB2596848 - Update for Microsoft Office 2007 suites

Here's the MSE-related updates (for later reference):

KB3205972 - Update for Microsoft Security Essentials - 4.10.209.0
KB2310138 - Definition Update for Microsoft Security Essentials (Definition 1.239.1325.0)
 
Please do the following.

FRST Scan

1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the 64-bit Version so please ensure you download that one.
2. Right click to run as administrator. When the tool opens click Yes to disclaimer.
3. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running (if not already).
4. Press Scan button.
5. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
6. Please copy and paste log back here.
7. Another log (Addition.txt - also located in the same directory as FRST64.exe) will be generated Please also paste that along with the FRST.txt into your reply.
 
Here's the output of FRST.txt:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Administrator (administrator) on WENDY-HP (13-04-2017 01:34:47)
Running from C:\Users\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CryptoMill Technologies Ltd.) C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Hewlett-Packard Development Company) C:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7194840 2013-07-27] (Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [CryptoMill Refresh] => C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-09-04] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2013-08-07] (CyberLink Corp.)
HKLM-x32\...\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2013-09-18] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2017-01-03] (AVAST Software)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1193728 2017-02-15] (PDF Complete Inc)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-2394251349-1681379467-2739588611-500\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2394251349-1681379467-2739588611-500\...\MountPoints2: F - F:\setup.exe
Lsa: [Notification Packages] DPPassFilter scecli
ShellIconOverlayIdentifiers: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-10-03] (CryptoMill Technologies Ltd.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-01-03] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-10-03] (CryptoMill Technologies Ltd.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - .lnk [2014-08-26]
ShortcutTarget: Monitor Ink Alerts - .lnk -> C:\Program Files\HP\HP Officejet 6700\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6700 (Network).lnk [2017-04-12]
ShortcutTarget: Monitor Ink Alerts - HP Officejet 6700 (Network).lnk -> C:\Program Files\HP\HP Officejet 6700\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2015-04-03]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (No File)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.20.1 192.168.20.1
Tcpip\..\Interfaces\{33B06B76-343C-4FA0-9419-EC13DE271976}: [DhcpNameServer] 192.168.20.1 192.168.20.1
Tcpip\..\Interfaces\{C86CB0A8-F9E0-484B-AC7A-E7F63CEBA222}: [DhcpNameServer] 192.168.42.129

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/53
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/53
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/53
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/53
HKU\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/53
HKU\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/53
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-03-31] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-03-31] (Oracle Corporation)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2013-09-18] (Hewlett-Packard)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2015-04-02] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-01-03] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2015-04-02] (Oracle Corporation)
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\45eii6i1.default [2017-04-13]
FF Extension: (FlashGot) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\45eii6i1.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2016-12-25]
FF Extension: (Adblock Plus) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\45eii6i1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-25]
FF Extension: (Net Usage Item) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\45eii6i1.default\Extensions\{DA1B0AB5-7DD3-4066-BC2A-64AABBDD0A8B}.xpi [2016-03-24]
FF Extension: (Disable Prefetch) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\45eii6i1.default\features\{b5b973f3-555e-4b8b-b1bc-a0caf693f7e0}\disable-prefetch@mozilla.org.xpi [2017-04-05]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-29] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2017-01-03]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2017-01-03]
FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome
FF Extension: (HP Client Security Manager) - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2014-09-04] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-12] ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-03-31] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-12] ()
FF Plugin-x32: @glance.net/GlanceClient -> C:\Program Files (x86)\Glance29\npglance.dll [2014-09-16] (Glance Networks, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-04-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-12] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-12] (Google Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2014-02-10] (DigitalPersona, Inc.)

Chrome: 
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default [2017-03-19]
CHR Extension: (Google Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-02]
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-03]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-23]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-23]
CHR Extension: (Google Search) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-23]
CHR Extension: (Avast SafePrice) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-12-31]
CHR Extension: (Google Docs Offline) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-10]
CHR Extension: (HP Client Security Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2015-04-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-03]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-03]
CHR Extension: (Chrome Media Router) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-31]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx [2014-02-10]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2017-01-03] (AVAST Software)
S3 becldr3Service; C:\Program Files\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [263168 2013-07-03] () [File not signed]
R2 CreoService; C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [1390552 2013-10-03] (CryptoMill Technologies Ltd.)
R2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2014-03-31] () [File not signed]
R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2014-02-10] (DigitalPersona, Inc.)
S3 FLCDLOCK; C:\windows\SysWOW64\flcdlock.exe [567608 2014-04-10] (Hewlett-Packard Company)
R2 HpDamServiceHost; C:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [18232 2014-04-10] (Hewlett-Packard Development Company)
S3 hpqwmiex; C:\Users\Administrator\AppData\Roaming\Hewlett-Packard\hpqwmiex.exe [1224192 2014-09-04] (Hewlett-Packard Company) [File not signed]
R2 igfxCUIService1.0.0.0; C:\windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe [270336 2001-02-23] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [86528 2011-06-17] () [File not signed]
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1719552 2017-02-15] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-19] (Realtek Semiconductor)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-19] (Microsoft Corporation)
S2 HP Support Assistant Service; "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswHwid; C:\windows\system32\drivers\aswHwid.sys [37656 2017-01-03] (AVAST Software)
R1 aswKbd; C:\windows\system32\drivers\aswKbd.sys [37144 2017-01-03] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [108816 2017-01-03] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [103064 2017-01-03] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2017-01-03] (AVAST Software)
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [969184 2017-01-03] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [513632 2017-01-03] (AVAST Software)
R2 aswStm; C:\windows\system32\drivers\aswStm.sys [163416 2017-01-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2017-01-03] (AVAST Software)
R1 CLVirtualDrive; C:\windows\System32\DRIVERS\CLVirtualDrive.sys [90608 2011-12-27] (CyberLink)
S3 DAMDrv; C:\windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-10-07] (Hewlett-Packard Company)
R3 glancedrv; C:\windows\System32\DRIVERS\glancedrv.sys [36384 2009-05-13] (Glance Networks, Inc)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28008 2013-09-21] (Intel Corporation)
R3 IceKore; C:\windows\System32\DRIVERS\IceKore.sys [401368 2013-09-30] (CryptoMill Technologies Inc.)
R3 MEIx64; C:\windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R0 PinFile; C:\windows\System32\DRIVERS\PinFile.sys [49856 2013-08-23] (WinMagic Inc.)
R0 SDDisk2K; C:\windows\System32\DRIVERS\SDDisk2K.sys [228544 2013-08-23] (WinMagic Inc.)
R0 SDDToki; C:\windows\System32\DRIVERS\SDDToki.sys [131264 2013-08-23] (WinMagic Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-13 01:34 - 2017-04-13 01:35 - 00022044 _____ C:\Users\Administrator\Desktop\FRST.txt
2017-04-13 01:33 - 2017-04-06 00:11 - 02424832 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2017-04-12 18:15 - 2017-04-12 18:15 - 00000000 ____D C:\windows\TempAFABF901-3B14-9090-F250-7B0F6A684394-Signatures
2017-04-12 12:06 - 2017-04-12 12:07 - 00000000 ____D C:\windows\Temp618ADD5A-67FD-70B8-8607-DFD5C082BAA6-Signatures
2017-04-12 11:39 - 2017-03-26 05:39 - 20284416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2017-04-12 11:39 - 2017-03-26 05:06 - 13654016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2017-04-12 11:39 - 2017-03-26 03:52 - 25746944 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-04-12 11:39 - 2017-03-26 02:28 - 15259136 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-04-12 11:39 - 2016-03-24 08:40 - 03181568 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-04-12 11:39 - 2016-03-24 08:40 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-04-12 11:38 - 2017-03-28 04:13 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2017-04-12 11:38 - 2017-03-28 03:28 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2017-04-12 11:38 - 2017-03-26 05:07 - 04604416 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2017-04-12 11:38 - 2017-03-26 04:55 - 02767360 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2017-04-12 11:38 - 2017-03-26 04:52 - 02289152 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2017-04-12 11:38 - 2017-03-26 04:51 - 01313280 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2017-04-12 11:38 - 2017-03-26 04:48 - 00499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2017-04-12 11:38 - 2017-03-26 04:47 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2017-04-12 11:38 - 2017-03-26 04:47 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2017-04-12 11:38 - 2017-03-26 04:47 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-12 11:38 - 2017-03-26 04:46 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2017-04-12 11:38 - 2017-03-26 04:45 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2017-04-12 11:38 - 2017-03-26 04:45 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2017-04-12 11:38 - 2017-03-26 04:44 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2017-04-12 11:38 - 2017-03-26 04:44 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2017-04-12 11:38 - 2017-03-26 04:35 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2017-04-12 11:38 - 2017-03-26 04:35 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2017-04-12 11:38 - 2017-03-26 04:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2017-04-12 11:38 - 2017-03-26 04:14 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2017-04-12 11:38 - 2017-03-26 04:14 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2017-04-12 11:38 - 2017-03-26 04:13 - 00576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-04-12 11:38 - 2017-03-26 04:13 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2017-04-12 11:38 - 2017-03-26 04:10 - 02898432 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2017-04-12 11:38 - 2017-03-26 04:04 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2017-04-12 11:38 - 2017-03-26 04:02 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2017-04-12 11:38 - 2017-03-26 03:57 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2017-04-12 11:38 - 2017-03-26 03:56 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-04-12 11:38 - 2017-03-26 03:56 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2017-04-12 11:38 - 2017-03-26 03:56 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2017-04-12 11:38 - 2017-03-26 03:56 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2017-04-12 11:38 - 2017-03-26 03:45 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2017-04-12 11:38 - 2017-03-26 03:41 - 06045696 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-04-12 11:38 - 2017-03-26 03:41 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2017-04-12 11:38 - 2017-03-26 03:30 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2017-04-12 11:38 - 2017-03-26 03:29 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2017-04-12 11:38 - 2017-03-26 03:24 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2017-04-12 11:38 - 2017-03-26 03:23 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2017-04-12 11:38 - 2017-03-26 03:20 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2017-04-12 11:38 - 2017-03-26 03:19 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2017-04-12 11:38 - 2017-03-26 03:17 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2017-04-12 11:38 - 2017-03-26 03:06 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2017-04-12 11:38 - 2017-03-26 03:04 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2017-04-12 11:38 - 2017-03-26 03:00 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2017-04-12 11:38 - 2017-03-26 02:59 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-04-12 11:38 - 2017-03-26 02:57 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2017-04-12 11:38 - 2017-03-26 02:57 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2017-04-12 11:38 - 2017-03-26 02:27 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2017-04-12 11:38 - 2017-03-26 02:24 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-04-12 11:38 - 2017-03-26 02:10 - 01546240 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-04-12 11:38 - 2017-03-26 02:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-04-12 11:38 - 2017-03-25 08:50 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2017-04-12 11:38 - 2017-03-25 08:42 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2017-04-12 11:38 - 2017-03-23 01:32 - 03165184 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-04-12 11:38 - 2017-03-23 01:32 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-04-12 11:38 - 2017-03-23 01:32 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-04-12 11:38 - 2017-03-23 01:30 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2017-04-12 11:38 - 2017-03-23 01:24 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2017-04-12 11:38 - 2017-03-23 01:17 - 02651136 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-04-12 11:38 - 2017-03-23 01:15 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-04-12 11:38 - 2017-03-23 01:15 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-04-12 11:38 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-04-12 11:38 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-04-12 11:38 - 2017-03-23 01:15 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-04-12 11:38 - 2017-03-23 01:15 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2017-04-12 11:38 - 2017-03-23 01:05 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2017-04-12 11:38 - 2017-03-23 01:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2017-04-12 11:38 - 2017-03-23 01:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2017-04-12 11:38 - 2017-03-23 01:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2017-04-12 11:38 - 2017-03-15 01:34 - 00986344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2017-04-12 11:38 - 2017-03-15 01:34 - 00265448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2017-04-12 11:38 - 2017-03-15 01:30 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2017-04-12 11:38 - 2017-03-11 02:35 - 00382696 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2017-04-12 11:38 - 2017-03-11 02:31 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2017-04-12 11:38 - 2017-03-11 02:31 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2017-04-12 11:38 - 2017-03-11 02:31 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2017-04-12 11:38 - 2017-03-11 02:31 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2017-04-12 11:38 - 2017-03-11 02:27 - 00308456 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2017-04-12 11:38 - 2017-03-11 02:20 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2017-04-12 11:38 - 2017-03-11 02:19 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2017-04-12 11:38 - 2017-03-11 02:19 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2017-04-12 11:38 - 2017-03-11 02:00 - 03219968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2017-04-12 11:38 - 2017-03-11 01:53 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2017-04-12 11:38 - 2017-03-09 06:20 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2017-04-12 11:38 - 2017-03-09 06:10 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2017-04-12 11:38 - 2017-03-08 14:37 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2017-04-12 11:38 - 2017-03-08 14:36 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2017-04-12 11:38 - 2017-03-08 14:36 - 00706792 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2017-04-12 11:38 - 2017-03-08 14:36 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-04-12 11:38 - 2017-03-08 14:36 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-04-12 11:38 - 2017-03-08 14:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 02064384 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:26 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2017-04-12 11:38 - 2017-03-08 14:26 - 03945192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2017-04-12 11:38 - 2017-03-08 14:24 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 01416192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-04-12 11:38 - 2017-03-08 14:22 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 14:03 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2017-04-12 11:38 - 2017-03-08 14:03 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-04-12 11:38 - 2017-03-08 14:03 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2017-04-12 11:38 - 2017-03-08 14:03 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2017-04-12 11:38 - 2017-03-08 14:00 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2017-04-12 11:38 - 2017-03-08 13:59 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2017-04-12 11:38 - 2017-03-08 13:57 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-04-12 11:38 - 2017-03-08 13:56 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-04-12 11:38 - 2017-03-08 13:56 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-04-12 11:38 - 2017-03-08 13:56 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-04-12 11:38 - 2017-03-08 13:55 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2017-04-12 11:38 - 2017-03-08 13:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-04-12 11:38 - 2017-03-08 13:54 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2017-04-12 11:38 - 2017-03-08 13:54 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2017-04-12 11:38 - 2017-03-08 13:54 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2017-04-12 11:38 - 2017-03-08 13:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2017-04-12 11:38 - 2017-03-08 13:53 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-04-12 11:38 - 2017-03-08 13:53 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 13:53 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 13:53 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 13:53 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 11:38 - 2017-03-08 02:30 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2017-04-12 11:38 - 2017-03-08 02:17 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2017-04-12 11:38 - 2017-03-08 00:05 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-04-12 11:38 - 2017-03-04 11:27 - 01574912 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2017-04-12 11:38 - 2017-03-04 11:27 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\mfmjpegdec.dll
2017-04-12 11:38 - 2017-03-04 11:14 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2017-04-12 11:38 - 2017-03-04 11:14 - 00077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmjpegdec.dll
2017-04-12 11:31 - 2017-04-12 11:31 - 06230616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2017-04-11 08:39 - 2017-04-11 08:40 - 00000000 ____D C:\windows\Temp3370038C-930E-F522-1A70-26080F612F5F-Signatures
2017-04-10 12:08 - 2017-04-10 12:08 - 00000000 ____D C:\windows\TempD1390EBF-7443-45BA-850A-7CCC12952C3D-Signatures
2017-04-10 11:36 - 2017-04-10 11:36 - 00000000 ____D C:\windows\Temp3B911429-9E3B-BDB7-9109-764ACD5E2498-Signatures
2017-04-10 03:00 - 2017-04-10 03:00 - 00000000 ____D C:\windows\TempBD384E73-2D2E-A9DD-FDE7-F026210219F2-Signatures
2017-04-09 03:00 - 2017-04-09 03:00 - 00000000 ____D C:\windows\Temp2E24471E-B0DE-A0F0-DE65-E83DAF88BD27-Signatures
2017-04-08 03:00 - 2017-04-08 03:00 - 00000000 ____D C:\windows\Temp670061E9-6BBF-F102-03AC-4D852266FCAA-Signatures
2017-04-07 03:00 - 2017-04-07 03:00 - 00000000 ____D C:\windows\Temp236C579B-51BF-B78D-06DD-7D12A84037F1-Signatures
2017-04-06 23:41 - 2017-04-06 23:41 - 00000000 ____D C:\windows\Temp5CAB321E-EC5F-FF4A-6705-14219C268C39-Signatures
2017-04-06 22:38 - 2017-04-06 22:38 - 00000000 ____D C:\windows\Temp78961447-F2A7-1D4F-55FE-477B70E2AC0B-Signatures
2017-04-06 13:43 - 2017-04-06 13:43 - 00000000 ____D C:\windows\TempA40CC0DD-8218-EBCC-F4F1-4895A08D9728-Signatures
2017-04-06 13:41 - 2017-04-06 13:41 - 00000000 ____D C:\windows\TempCA6598E0-3B3E-6571-5D5E-73567464CF55-Signatures
2017-04-06 13:24 - 2017-04-06 13:24 - 00000000 ____D C:\windows\Temp6BCC5CE9-7569-4327-4588-A583ABBC8B86-Signatures
2017-04-06 13:18 - 2016-05-13 01:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2017-04-06 13:13 - 2016-08-17 06:40 - 00343552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2017-04-06 13:13 - 2016-08-17 06:40 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2017-04-06 13:13 - 2016-08-17 06:40 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2017-04-06 13:13 - 2016-08-17 06:40 - 00056320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2017-04-06 13:13 - 2016-08-17 06:40 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2017-04-06 12:31 - 2017-04-06 12:31 - 00000000 ____D C:\windows\Temp7550C89C-5BB5-50ED-9699-0797E4DBA57E-Signatures
2017-04-06 12:23 - 2015-08-06 03:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-04-06 12:23 - 2015-08-06 03:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-04-06 12:22 - 2017-02-15 02:33 - 00757248 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2017-04-06 12:22 - 2017-02-15 02:19 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2017-04-06 12:22 - 2017-02-12 02:33 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2017-04-06 12:22 - 2017-02-12 02:16 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2017-04-06 12:22 - 2017-02-12 01:58 - 00462848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2017-04-06 12:22 - 2017-02-12 01:58 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2017-04-06 12:22 - 2017-02-12 01:58 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2017-04-06 12:22 - 2017-02-11 02:32 - 00803328 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2017-04-06 12:22 - 2017-02-11 02:17 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2017-04-06 12:22 - 2017-02-11 00:33 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2017-04-06 12:22 - 2017-02-10 02:32 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\samsrv.dll
2017-04-06 12:22 - 2017-02-10 02:32 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\samlib.dll
2017-04-06 12:22 - 2017-02-10 02:32 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\WcsPlugInService.dll
2017-04-06 12:22 - 2017-02-10 02:31 - 00625664 _____ (Microsoft Corporation) C:\windows\system32\mscms.dll
2017-04-06 12:22 - 2017-02-10 02:31 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\icm32.dll
2017-04-06 12:22 - 2017-02-10 02:14 - 00481792 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscms.dll
2017-04-06 12:22 - 2017-02-10 02:14 - 00215040 _____ (Microsoft Corporation) C:\windows\SysWOW64\icm32.dll
2017-04-06 12:22 - 2017-02-10 02:14 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\samlib.dll
2017-04-06 12:22 - 2017-02-10 01:51 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcsPlugInService.dll
2017-04-06 12:22 - 2017-02-10 00:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2017-04-06 12:22 - 2017-02-10 00:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2017-04-06 12:22 - 2017-02-07 02:14 - 00733696 _____ (Microsoft Corporation) C:\windows\HelpPane.exe
2017-04-06 12:22 - 2017-01-19 01:36 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:36 - 00011608 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-06 12:22 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-06 12:22 - 2017-01-14 04:00 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2017-04-06 12:22 - 2017-01-14 04:00 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2017-04-06 12:22 - 2017-01-14 03:45 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2017-04-06 12:22 - 2017-01-14 03:45 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2017-04-06 12:22 - 2017-01-12 04:01 - 01887744 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2017-04-06 12:22 - 2017-01-12 04:01 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2017-04-06 12:22 - 2017-01-12 03:43 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2017-04-06 12:22 - 2017-01-12 03:43 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2017-04-06 12:22 - 2016-11-22 04:12 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2017-04-06 12:22 - 2016-11-21 02:19 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2017-04-06 12:22 - 2016-11-21 00:07 - 00467392 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2017-04-06 12:22 - 2016-11-18 02:41 - 00370920 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2017-04-06 12:22 - 2016-11-11 02:32 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2017-04-06 12:22 - 2016-11-11 02:19 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2017-04-06 12:22 - 2016-11-10 02:41 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2017-04-06 12:22 - 2016-11-10 02:33 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2017-04-06 12:22 - 2016-11-10 02:33 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2017-04-06 12:22 - 2016-11-10 02:33 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2017-04-06 12:22 - 2016-11-10 02:33 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2017-04-06 12:22 - 2016-11-10 02:33 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2017-04-06 12:22 - 2016-11-10 02:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2017-04-06 12:22 - 2016-11-10 02:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2017-04-06 12:22 - 2016-11-10 02:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2017-04-06 12:22 - 2016-11-10 02:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2017-04-06 12:22 - 2016-11-10 02:02 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2017-04-06 12:22 - 2016-11-10 01:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2017-04-06 12:22 - 2016-10-12 01:32 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\nlsbres.dll
2017-04-06 12:22 - 2016-10-12 01:31 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\IMJP10.IME
2017-04-06 12:22 - 2016-10-12 01:31 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2017-04-06 12:22 - 2016-10-12 01:31 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2017-04-06 12:22 - 2016-10-12 01:31 - 00457216 _____ (Microsoft Corporation) C:\windows\system32\imkr80.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00246784 _____ (Microsoft Corporation) C:\windows\system32\input.dll
2017-04-06 12:22 - 2016-10-12 01:31 - 00176128 _____ (Microsoft Corporation) C:\windows\system32\tintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\quick.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\qintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\phon.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\cintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\chajei.ime
2017-04-06 12:22 - 2016-10-12 01:31 - 00132608 _____ (Microsoft Corporation) C:\windows\system32\pintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 01027584 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10.IME
2017-04-06 12:22 - 2016-10-12 01:18 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2017-04-06 12:22 - 2016-10-12 01:18 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2017-04-06 12:22 - 2016-10-12 01:18 - 00430080 _____ (Microsoft Corporation) C:\windows\SysWOW64\imkr80.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00202240 _____ (Microsoft Corporation) C:\windows\SysWOW64\input.dll
2017-04-06 12:22 - 2016-10-12 01:18 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\tintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\quick.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\phon.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\cintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\chajei.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00090112 _____ (Microsoft Corporation) C:\windows\SysWOW64\pintlgnt.ime
2017-04-06 12:22 - 2016-10-12 01:18 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlsbres.dll
2017-04-06 12:22 - 2016-10-12 00:55 - 00346112 _____ (Microsoft Corporation) C:\windows\system32\bcdedit.exe
2017-04-06 12:22 - 2016-10-11 23:33 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2017-04-06 12:22 - 2016-10-11 23:18 - 00419648 _____ C:\windows\SysWOW64\locale.nls
2017-04-06 12:22 - 2016-10-11 23:17 - 00419648 _____ C:\windows\system32\locale.nls
2017-04-06 12:22 - 2016-10-11 23:06 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2017-04-06 12:22 - 2016-10-08 23:06 - 00633296 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2017-04-06 12:22 - 2016-10-08 01:32 - 03649536 _____ (Microsoft Corporation) C:\windows\system32\MSVidCtl.dll
2017-04-06 12:22 - 2016-10-08 01:32 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2017-04-06 12:22 - 2016-10-08 01:12 - 02291712 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVidCtl.dll
2017-04-06 12:22 - 2016-10-08 01:12 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2017-04-06 12:22 - 2016-10-06 00:54 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys
2017-04-06 12:22 - 2016-10-05 01:31 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2017-04-06 12:22 - 2016-10-05 01:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2017-04-06 12:22 - 2016-10-05 01:31 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2017-04-06 12:22 - 2016-10-05 01:31 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2017-04-06 12:22 - 2016-10-05 01:13 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2017-04-06 12:22 - 2016-10-05 01:13 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2017-04-06 12:22 - 2016-10-05 01:13 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2017-04-06 12:22 - 2016-10-05 01:13 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2017-04-06 12:22 - 2016-09-16 00:56 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2017-04-06 12:22 - 2016-09-13 07:08 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\adsmsext.dll
2017-04-06 12:22 - 2016-09-13 06:49 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\adsmsext.dll
2017-04-06 12:22 - 2016-09-09 06:34 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2017-04-06 12:22 - 2016-09-09 06:34 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2017-04-06 12:22 - 2016-09-09 06:34 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2017-04-06 12:22 - 2016-09-09 06:34 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2017-04-06 12:22 - 2016-09-09 00:55 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2017-04-06 12:22 - 2016-09-09 00:55 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dfsc.sys
2017-04-06 12:22 - 2016-08-23 02:19 - 01386496 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2017-04-06 12:22 - 2016-08-13 03:02 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2017-04-06 12:22 - 2016-08-13 03:02 - 12574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2017-04-06 12:22 - 2016-08-13 03:02 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2017-04-06 12:22 - 2016-08-13 03:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2017-04-06 12:22 - 2016-08-13 03:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2017-04-06 12:22 - 2016-08-13 02:47 - 12574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2017-04-06 12:22 - 2016-08-13 02:47 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2017-04-06 12:22 - 2016-08-13 02:31 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2017-04-06 12:22 - 2016-08-13 02:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2017-04-06 12:22 - 2016-08-13 02:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2017-04-06 12:22 - 2016-08-13 02:26 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 02023424 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 00347136 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 00310784 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 00054272 _____ (Microsoft Corporation) C:\windows\system32\WsmRes.dll
2017-04-06 12:22 - 2016-08-07 01:31 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\wsmplpxy.dll
2017-04-06 12:22 - 2016-08-07 01:15 - 01178112 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2017-04-06 12:22 - 2016-08-07 01:15 - 00249344 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2017-04-06 12:22 - 2016-08-07 01:15 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2017-04-06 12:22 - 2016-08-07 01:15 - 00146944 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2017-04-06 12:22 - 2016-08-07 01:15 - 00054272 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmRes.dll
2017-04-06 12:22 - 2016-08-07 01:01 - 00266752 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2017-04-06 12:22 - 2016-08-07 01:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\wsmprovhost.exe
2017-04-06 12:22 - 2016-08-07 00:53 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2017-04-06 12:22 - 2016-08-07 00:53 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmprovhost.exe
2017-04-06 12:22 - 2016-08-07 00:53 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmplpxy.dll
2017-04-06 12:22 - 2016-06-15 03:21 - 00094440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2017-04-06 12:22 - 2016-06-15 03:16 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00680448 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00632320 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00440320 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00295936 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2017-04-06 12:22 - 2016-06-15 03:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2017-04-06 12:22 - 2016-06-15 03:11 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2017-04-06 12:22 - 2016-06-15 01:21 - 03209216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00195072 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2017-04-06 12:22 - 2016-06-15 01:21 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2017-04-06 12:22 - 2016-06-15 01:15 - 00125952 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2017-04-06 12:22 - 2016-06-15 01:15 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2017-04-06 12:22 - 2016-06-15 01:15 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2017-04-06 12:22 - 2016-06-15 01:05 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2017-04-06 12:22 - 2016-06-15 01:05 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2017-04-06 12:22 - 2016-06-15 01:00 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2017-04-06 12:22 - 2016-06-15 01:00 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2017-04-06 12:22 - 2016-05-12 23:05 - 00297984 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2017-04-06 12:22 - 2016-05-12 23:04 - 00249352 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2017-04-06 12:20 - 2015-12-17 04:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-04-06 12:20 - 2015-12-17 04:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-04-06 12:20 - 2015-12-17 04:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-04-06 12:20 - 2015-12-17 04:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-04-06 12:20 - 2015-12-17 04:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-04-06 12:20 - 2015-12-17 04:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-04-06 03:56 - 2015-07-30 23:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-04-06 03:56 - 2015-07-30 23:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-04-06 03:46 - 2017-04-06 03:46 - 00000000 ____D C:\windows\Temp9EE8B60E-D2B8-10EA-F919-37362ACB7891-Signatures
2017-04-06 00:14 - 2017-04-13 01:34 - 00000000 ____D C:\FRST
2017-04-05 06:11 - 2017-04-05 06:11 - 00000000 ____D C:\windows\system32\appraiser
2017-04-05 03:24 - 2017-04-05 03:24 - 00000000 ____D C:\windows\Temp92592259-AF95-5EE4-5497-AE5D19A28D7D-Signatures
2017-04-05 02:10 - 2015-01-09 13:14 - 00950272 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2017-04-05 02:10 - 2015-01-09 13:14 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2017-04-05 02:10 - 2015-01-09 13:14 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2017-04-05 02:10 - 2015-01-09 12:48 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdi.dll
2017-04-05 02:09 - 2016-03-17 04:50 - 00156672 _____ (Microsoft Corporation) C:\windows\system32\mtxoci.dll
2017-04-05 02:09 - 2016-03-17 04:28 - 00176128 _____ (Microsoft Corporation) C:\windows\SysWOW64\msorcl32.dll
2017-04-05 02:09 - 2016-03-17 04:28 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\mtxoci.dll
2017-04-05 02:09 - 2016-02-03 04:57 - 00511488 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
2017-04-05 02:09 - 2015-11-14 09:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapistub.dll
2017-04-05 02:09 - 2015-11-14 09:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapi32.dll
2017-04-05 02:09 - 2015-11-14 09:08 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\fixmapi.exe
2017-04-05 02:09 - 2015-11-14 08:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapistub.dll
2017-04-05 02:09 - 2015-11-14 08:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapi32.dll
2017-04-05 02:09 - 2015-11-14 08:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\fixmapi.exe
2017-04-05 02:09 - 2015-08-06 03:56 - 01110016 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2017-04-05 02:09 - 2015-07-17 05:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-04-05 02:09 - 2015-07-17 05:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-04-05 02:09 - 2015-07-17 05:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-04-05 02:09 - 2015-07-17 05:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-04-05 02:09 - 2015-07-17 05:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-04-05 02:09 - 2015-07-17 05:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-04-05 02:09 - 2015-07-16 04:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2017-04-05 02:09 - 2015-07-11 23:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-04-05 02:09 - 2015-06-04 06:17 - 00546656 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2017-04-05 02:09 - 2015-06-02 10:07 - 00254976 _____ (Microsoft Corporation) C:\windows\system32\cewmdm.dll
2017-04-05 02:09 - 2015-06-02 09:47 - 00210432 _____ (Microsoft Corporation) C:\windows\SysWOW64\cewmdm.dll
2017-04-05 02:09 - 2015-04-13 13:28 - 00328704 _____ (Microsoft Corporation) C:\windows\system32\services.exe
2017-04-05 02:08 - 2016-06-26 10:27 - 00970240 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2017-04-05 02:08 - 2016-06-26 10:27 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
2017-04-05 02:08 - 2016-06-26 10:27 - 00166400 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
2017-04-05 02:08 - 2016-06-26 10:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\inetppui.dll
2017-04-05 02:08 - 2016-06-26 05:53 - 00297472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
2017-04-05 02:08 - 2016-06-26 05:53 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
2017-04-05 02:08 - 2016-06-26 05:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
2017-04-05 02:08 - 2016-06-26 05:41 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
2017-04-05 02:08 - 2016-02-06 04:56 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\tbs.dll
2017-04-05 02:08 - 2016-02-06 04:54 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\fveapibase.dll
2017-04-05 02:08 - 2016-02-06 03:33 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbs.dll
2017-04-05 02:08 - 2016-01-21 10:51 - 00073664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\disk.sys
2017-04-05 02:08 - 2015-07-15 13:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2017-04-05 02:08 - 2015-07-10 03:58 - 01632256 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2017-04-05 02:08 - 2015-07-10 03:58 - 00082944 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
2017-04-05 02:08 - 2015-07-10 03:42 - 01372160 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2017-04-05 02:08 - 2015-07-10 03:42 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
2017-04-05 02:08 - 2015-06-04 06:21 - 00451080 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll
2017-04-05 02:08 - 2015-05-26 04:19 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\sechost.dll
2017-04-05 02:08 - 2015-05-26 04:18 - 00404992 _____ (Microsoft Corporation) C:\windows\system32\tracerpt.exe
2017-04-05 02:08 - 2015-05-26 04:18 - 00104448 _____ (Microsoft Corporation) C:\windows\system32\logman.exe
2017-04-05 02:08 - 2015-05-26 04:18 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\typeperf.exe
2017-04-05 02:08 - 2015-05-26 04:18 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\relog.exe
2017-04-05 02:08 - 2015-05-26 04:18 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\diskperf.exe
2017-04-05 02:08 - 2015-05-26 04:01 - 00092160 _____ (Microsoft Corporation) C:\windows\SysWOW64\sechost.dll
2017-04-05 02:08 - 2015-05-26 04:00 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\tracerpt.exe
2017-04-05 02:08 - 2015-05-26 04:00 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\logman.exe
2017-04-05 02:08 - 2015-05-26 04:00 - 00040448 _____ (Microsoft Corporation) C:\windows\SysWOW64\typeperf.exe
2017-04-05 02:08 - 2015-05-26 04:00 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\relog.exe
2017-04-05 02:08 - 2015-05-26 04:00 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\diskperf.exe
2017-04-05 02:08 - 2015-02-03 13:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2017-04-05 02:08 - 2015-02-03 13:12 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ubpm.dll
2017-04-05 02:08 - 2015-01-29 13:19 - 02543104 _____ (Microsoft Corporation) C:\windows\system32\wpdshext.dll
2017-04-05 02:08 - 2015-01-29 13:02 - 02311168 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpdshext.dll
2017-04-05 02:08 - 2014-12-19 13:06 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2017-04-05 02:08 - 2014-12-06 14:17 - 00303616 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2017-04-05 02:08 - 2014-12-06 13:50 - 00156672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2017-04-05 02:08 - 2014-12-06 13:50 - 00052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2017-04-05 02:08 - 2014-10-14 12:13 - 00683520 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2017-04-05 02:07 - 2016-07-08 01:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2017-04-05 02:07 - 2016-07-08 01:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2017-04-05 02:07 - 2016-07-08 01:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2017-04-05 02:07 - 2016-07-08 01:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2017-04-05 02:07 - 2016-05-12 03:02 - 00483840 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2017-04-05 02:07 - 2016-05-12 01:19 - 00363520 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2017-04-05 02:07 - 2016-04-14 23:49 - 00603648 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2017-04-05 02:07 - 2016-04-14 23:21 - 00647680 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2017-04-05 02:07 - 2016-02-05 11:19 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2017-04-05 02:07 - 2016-02-05 04:41 - 00296448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2017-04-05 02:07 - 2016-02-04 04:07 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2017-04-05 02:07 - 2016-01-12 05:11 - 01684416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2017-04-05 02:07 - 2015-12-09 07:54 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2017-04-05 02:07 - 2015-12-09 07:54 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 01568768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVENCOD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 01325056 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOE.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00902144 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00815616 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOE.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00740352 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmpmde.dll
2017-04-05 02:07 - 2015-12-09 07:54 - 00739328 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVXENCD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00541184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSDECD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00358400 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSENCD.DLL
2017-04-05 02:07 - 2015-12-09 07:54 - 00154112 _____ (Microsoft Corporation) C:\windows\SysWOW64\VIDRESZR.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00970240 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2adec.dll
2017-04-05 02:07 - 2015-12-09 07:53 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMPEG2ENC.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00609280 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFWMAAEC.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00509952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2017-04-05 02:07 - 2015-12-09 07:53 - 00415744 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP4SDECD.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MPG4DECD.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP43DECD.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\RESAMPLEDMO.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\qasf.dll
2017-04-05 02:07 - 2015-12-09 07:53 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksproxy.ax
2017-04-05 02:07 - 2015-12-09 07:53 - 00153600 _____ (Microsoft Corporation) C:\windows\SysWOW64\COLORCNV.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00079872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP3DMOD.DLL
2017-04-05 02:07 - 2015-12-09 07:53 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\devenum.dll
2017-04-05 02:07 - 2015-12-09 07:53 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfvdsp.dll
2017-04-05 02:07 - 2015-12-09 07:53 - 00004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksuser.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 01955328 _____ (Microsoft Corporation) C:\windows\system32\WMVENCOD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01575424 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOE.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01307136 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2adec.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 01232896 _____ (Microsoft Corporation) C:\windows\system32\WMADMOD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\MSMPEG2ENC.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01153024 _____ (Microsoft Corporation) C:\windows\system32\WMADMOE.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 01026048 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 01010688 _____ (Microsoft Corporation) C:\windows\system32\mcmde.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00666112 _____ (Microsoft Corporation) C:\windows\system32\WMVSDECD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00653824 _____ (Microsoft Corporation) C:\windows\system32\MP4SDECD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00642048 _____ (Microsoft Corporation) C:\windows\system32\WMVXENCD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00624640 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\MFWMAAEC.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00447488 _____ (Microsoft Corporation) C:\windows\system32\WMVSENCD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00378880 _____ (Microsoft Corporation) C:\windows\system32\SysFxUI.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00292352 _____ (Microsoft Corporation) C:\windows\system32\VIDRESZR.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00254464 _____ (Microsoft Corporation) C:\windows\system32\qasf.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00225792 _____ (Microsoft Corporation) C:\windows\system32\RESAMPLEDMO.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00224768 _____ (Microsoft Corporation) C:\windows\system32\MPG4DECD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00223744 _____ (Microsoft Corporation) C:\windows\system32\MP43DECD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\COLORCNV.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\MP3DMOD.DLL
2017-04-05 02:07 - 2015-12-09 05:07 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\devenum.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\mfvdsp.dll
2017-04-05 02:07 - 2015-12-09 05:07 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\ksuser.dll
2017-04-05 02:07 - 2015-12-09 05:06 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\ksproxy.ax
2017-04-05 02:07 - 2015-12-09 04:54 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2017-04-05 02:07 - 2015-12-09 04:12 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2017-04-05 02:07 - 2015-12-09 04:11 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmkaud.sys
2017-04-05 02:07 - 2015-11-12 04:53 - 01735680 _____ (Microsoft Corporation) C:\windows\system32\comsvcs.dll
2017-04-05 02:07 - 2015-11-12 04:53 - 00525312 _____ (Microsoft Corporation) C:\windows\system32\catsrvut.dll
2017-04-05 02:07 - 2015-11-12 04:39 - 01242624 _____ (Microsoft Corporation) C:\windows\SysWOW64\comsvcs.dll
2017-04-05 02:07 - 2015-11-12 04:39 - 00487936 _____ (Microsoft Corporation) C:\windows\SysWOW64\catsrvut.dll
2017-04-05 02:07 - 2015-11-06 05:05 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\wshrm.dll
2017-04-05 02:07 - 2015-11-06 05:02 - 00014848 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshrm.dll
2017-04-05 02:07 - 2015-11-05 19:53 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rmcast.sys
2017-04-05 02:07 - 2015-10-30 03:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2017-04-05 02:07 - 2015-10-30 03:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2017-04-05 02:07 - 2015-10-30 03:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2017-04-05 02:07 - 2015-10-30 03:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2017-04-05 02:07 - 2015-10-30 03:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2017-04-05 02:07 - 2015-10-30 03:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2017-04-05 02:07 - 2015-10-30 03:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2017-04-05 02:07 - 2015-10-14 02:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2017-04-05 02:07 - 2015-10-14 02:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2017-04-05 02:07 - 2015-07-31 04:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2017-04-05 02:07 - 2015-07-31 03:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2017-04-05 02:07 - 2015-07-23 10:02 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2017-04-05 02:07 - 2015-07-23 03:53 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2017-04-05 02:07 - 2015-07-10 03:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2017-04-05 02:07 - 2015-07-10 03:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2017-04-05 02:07 - 2015-07-10 03:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2017-04-05 02:07 - 2015-04-25 04:17 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2017-04-05 02:07 - 2015-04-25 03:56 - 00530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.dll
2017-04-05 02:07 - 2014-12-12 03:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-04-05 02:07 - 2014-11-11 13:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2017-04-05 02:07 - 2014-11-11 12:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2017-04-05 02:06 - 2017-02-23 09:42 - 00084712 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2017-04-05 02:06 - 2017-02-23 09:37 - 01285632 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2017-04-05 02:06 - 2017-02-19 00:05 - 01609216 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2017-04-05 02:06 - 2017-02-19 00:05 - 00646656 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2017-04-05 02:06 - 2017-01-01 01:36 - 00556544 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2017-04-05 02:06 - 2017-01-01 01:36 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2017-04-05 02:06 - 2017-01-01 01:36 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2017-04-05 02:06 - 2017-01-01 01:36 - 00233984 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2017-04-05 02:06 - 2017-01-01 01:36 - 00133632 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2017-04-05 02:06 - 2016-08-30 01:31 - 14183424 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2017-04-05 02:06 - 2016-08-30 01:31 - 01867776 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2017-04-05 02:06 - 2016-08-30 01:12 - 12880384 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2017-04-05 02:06 - 2016-08-30 01:12 - 01499648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2017-04-05 02:06 - 2016-08-30 01:04 - 03229696 _____ (Microsoft Corporation) C:\windows\explorer.exe
2017-04-05 02:06 - 2016-08-30 00:55 - 02972672 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2017-04-05 02:06 - 2016-05-13 03:15 - 00105472 _____ (Microsoft Corporation) C:\windows\system32\winipsec.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00794624 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00793088 _____ (Microsoft Corporation) C:\windows\system32\gpprefcl.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00502272 _____ (Microsoft Corporation) C:\windows\system32\IPSECSVC.DLL
2017-04-05 02:06 - 2016-05-13 03:14 - 00373760 _____ (Microsoft Corporation) C:\windows\system32\polstore.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00096256 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\FwRemoteSvr.dll
2017-04-05 02:06 - 2016-05-13 03:14 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\gpscript.dll
2017-04-05 02:06 - 2016-05-13 01:18 - 00591872 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpprefcl.dll
2017-04-05 02:06 - 2016-05-13 01:18 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\polstore.dll
2017-04-05 02:06 - 2016-05-13 01:18 - 00079360 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll
2017-04-05 02:06 - 2016-05-13 01:18 - 00070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\winipsec.dll
2017-04-05 02:06 - 2016-05-13 01:18 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\FwRemoteSvr.dll
2017-04-05 02:06 - 2016-05-13 01:06 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\gpscript.exe
2017-04-05 02:06 - 2016-05-13 00:57 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpscript.dll
2017-04-05 02:06 - 2016-05-13 00:57 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpscript.exe
2017-04-05 02:06 - 2016-05-12 03:02 - 00444928 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2017-04-05 02:06 - 2016-05-12 03:02 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2017-04-05 02:06 - 2016-05-12 03:02 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\ws2_32.dll
2017-04-05 02:06 - 2016-05-12 01:19 - 00351744 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2017-04-05 02:06 - 2016-05-12 01:19 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2017-04-05 02:06 - 2016-05-12 01:19 - 00206336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ws2_32.dll
2017-04-05 02:06 - 2016-05-12 01:11 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\netbtugc.exe
2017-04-05 02:06 - 2016-05-12 01:01 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\netbtugc.exe
2017-04-05 02:06 - 2016-05-12 00:58 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbt.sys
2017-04-05 02:06 - 2016-03-24 08:40 - 01239720 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2017-04-05 02:06 - 2016-03-10 05:00 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2017-04-05 02:06 - 2016-03-10 04:40 - 00316416 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll
2017-04-05 02:06 - 2016-02-09 19:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2017-04-05 02:06 - 2016-01-22 16:18 - 00961024 _____ (Microsoft Corporation) C:\windows\system32\CPFilters.dll
2017-04-05 02:06 - 2016-01-22 16:18 - 00723968 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2017-04-05 02:06 - 2016-01-22 16:04 - 00642048 _____ (Microsoft Corporation) C:\windows\SysWOW64\CPFilters.dll
2017-04-05 02:06 - 2016-01-22 16:04 - 00535040 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2017-04-05 02:06 - 2015-10-13 14:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2017-04-05 02:06 - 2015-08-28 04:18 - 02004480 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2017-04-05 02:06 - 2015-08-28 04:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2017-04-05 02:06 - 2015-08-28 03:58 - 01391104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2017-04-05 02:06 - 2015-08-28 03:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2017-04-05 02:06 - 2015-04-11 13:19 - 00069888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\stream.sys
2017-04-05 02:06 - 2015-02-25 13:18 - 00754688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2017-04-05 02:06 - 2014-10-30 12:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2017-04-05 02:06 - 2014-10-30 11:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2017-04-05 02:06 - 2014-10-25 11:57 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2017-04-05 02:06 - 2014-10-25 11:32 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2017-04-05 02:05 - 2016-03-10 04:54 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2017-04-05 02:05 - 2016-03-10 04:34 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2017-04-05 02:05 - 2015-11-04 05:04 - 00241664 _____ (Microsoft Corporation) C:\windows\system32\els.dll
2017-04-05 02:05 - 2015-11-04 04:55 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\els.dll
2017-04-05 02:05 - 2015-03-04 14:41 - 00079360 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2017-04-05 02:05 - 2015-03-04 14:10 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll
2017-04-05 02:05 - 2014-12-08 13:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2017-04-05 02:05 - 2014-12-08 12:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2017-04-05 02:04 - 2016-04-09 14:20 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2017-04-05 02:04 - 2016-04-09 13:52 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2017-04-05 02:04 - 2015-02-04 13:16 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2017-04-05 02:04 - 2015-02-04 12:54 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2017-04-05 02:00 - 2016-07-23 00:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2017-04-05 02:00 - 2016-07-23 00:51 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2017-04-01 23:20 - 2017-04-06 11:37 - 00000000 ____D C:\SFCFix
2017-04-01 23:11 - 2017-04-06 11:37 - 00000000 ____D C:\Users\Administrator\AppData\Local\niemiro
2017-04-01 21:13 - 2017-04-01 21:13 - 00000000 ____D C:\ProgramData\RegInOut
2017-04-01 20:45 - 2017-04-01 20:45 - 02582248 _____ (SORCIM Tech ) C:\Users\Administrator\Downloads\rio_setup.exe
2017-04-01 15:39 - 2015-07-06 21:13 - 3320903680 ____R C:\Users\Administrator\Documents\en_windows_7_professional_with_sp1_x64_dvd_u_676939.iso
2017-04-01 14:43 - 2017-04-01 14:45 - 00000000 ___HD C:\$WINDOWS.~BT
2017-03-31 10:10 - 2017-03-31 10:10 - 00000000 ____D C:\windows\Temp96937ACA-DFBD-0669-26C0-D99342638EE0-Signatures
2017-03-29 07:44 - 2017-03-30 06:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-27 11:27 - 2017-03-27 11:27 - 00000000 ____D C:\windows\TempD10B846F-EA77-DD13-AF56-DAEBB8529706-Signatures
2017-03-26 10:08 - 2017-03-26 10:08 - 00000000 ____D C:\windows\Temp7236834A-EE53-EC64-77D0-00A26256513E-Signatures
2017-03-24 10:54 - 2017-03-24 10:54 - 00000000 ____D C:\windows\TempC42F3A9C-B7DE-04BA-2975-FAD5D6311D2D-Signatures
2017-03-24 02:02 - 2017-03-24 02:02 - 00000000 ____D C:\windows\Temp20B198FC-3251-B691-8BE6-91D760280829-Signatures
2017-03-23 12:45 - 2017-02-15 11:25 - 00027368 _____ (PDF Complete, Inc.) C:\windows\system32\pdfc_port.dll
2017-03-22 11:24 - 2017-03-22 11:24 - 00000000 ____D C:\windows\Temp29530DA8-3103-1266-1F6B-760B2ED044BE-Signatures
2017-03-21 09:39 - 2017-03-21 09:39 - 00000000 ____D C:\windows\TempF351217F-346F-9D39-2C26-7F9F0B620BA8-Signatures
2017-03-20 00:48 - 2017-03-20 00:48 - 00028352 _____ (Microsoft Corporation) C:\windows\SysWOW64\aspnet_counters.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr110_clr0400.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100_clr0400.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp110_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00030400 _____ (Microsoft Corporation) C:\windows\system32\aspnet_counters.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\windows\system32\msvcr110_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\windows\system32\msvcr100_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\windows\system32\msvcp110_clr0400.dll
2017-03-19 09:43 - 2017-03-19 09:43 - 00000000 ____D C:\windows\Temp49778F1D-86DB-F82B-B953-3A3B9189B692-Signatures
2017-03-18 18:55 - 2017-03-18 18:55 - 00000000 ____D C:\windows\Temp63A88B46-E672-FBF6-B8B5-58F753978E50-Signatures
2017-03-18 13:24 - 2017-03-18 13:24 - 00000000 ____D C:\windows\Temp301B87E9-34BA-A658-BC31-7FE3D026B970-Signatures
2017-03-17 11:56 - 2017-03-17 11:56 - 00000000 ____D C:\windows\Temp76361DC7-4125-6179-E3F0-AD04D949189F-Signatures
2017-03-16 18:11 - 2017-03-16 18:11 - 00000000 ____D C:\windows\Temp6D63EBFE-FC6C-0399-C9E3-EB2AB2E6C95E-Signatures
2017-03-16 14:26 - 2017-03-16 14:26 - 00082088 _____ C:\Users\Administrator\Downloads\Individual Report for Edward Thomas King.pdf
2017-03-16 11:22 - 2017-03-16 11:22 - 00000000 ____D C:\windows\Temp59D7CCC4-DF93-2518-6286-49A6913B375C-Signatures
2017-03-16 09:00 - 2017-03-16 09:00 - 00000000 ____D C:\windows\Temp3A775C48-D29C-EB65-1233-E02A633E410E-Signatures
2017-03-15 17:44 - 2017-03-15 17:44 - 00000000 ____D C:\windows\TempA3EC63D3-AF23-D009-B817-0AD6F61838DC-Signatures
2017-03-15 12:14 - 2017-03-15 12:14 - 00000000 ____D C:\windows\TempDD971417-03B1-3FC5-9081-A6A2B7B6762C-Signatures
2017-03-14 10:54 - 2017-03-14 10:54 - 00000000 ____D C:\windows\Temp24EAA083-197F-5B5E-3990-B7E5886FD729-Signatures

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-13 01:30 - 2014-03-31 18:29 - 00000000 _____ C:\windows\system32\Drivers\lvuvc.hs
2017-04-12 21:39 - 2009-07-14 13:20 - 00000000 ____D C:\windows\rescache
2017-04-12 20:43 - 2009-07-14 14:45 - 00027568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-12 20:43 - 2009-07-14 14:45 - 00027568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-12 20:41 - 2009-07-14 15:13 - 00781790 _____ C:\windows\system32\PerfStringBackup.INI
2017-04-12 20:41 - 2009-07-14 13:20 - 00000000 ____D C:\windows\inf
2017-04-12 20:36 - 2016-11-19 07:48 - 00000000 ____D C:\Users\Administrator\AppData\LocalLow\Mozilla
2017-04-12 20:35 - 2014-08-21 21:42 - 00000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
2017-04-12 20:35 - 2014-03-19 06:22 - 00000000 ____D C:\ProgramData\PDFC
2017-04-12 20:34 - 2009-07-14 15:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-04-12 18:15 - 2014-03-19 06:22 - 00002113 _____ C:\windows\epplauncher.mif
2017-04-12 17:19 - 2014-03-19 06:21 - 00000225 _____ C:\windows\CryptoMill_CreoService.001
2017-04-12 17:15 - 2014-03-19 06:21 - 00000225 _____ C:\windows\CryptoMill_CreoService.002
2017-04-12 17:15 - 2009-07-14 14:45 - 00464872 _____ C:\windows\system32\FNTCACHE.DAT
2017-04-12 12:08 - 2014-03-31 21:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-12 12:07 - 2014-03-31 21:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 12:07 - 2014-03-31 21:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 12:06 - 2014-03-31 21:04 - 00000000 ____D C:\windows\system32\MRT
2017-04-12 12:05 - 2014-03-31 21:04 - 148601744 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-04-12 12:03 - 2011-02-12 06:29 - 00765656 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-04-12 11:32 - 2015-04-02 22:36 - 00003330 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-12 11:32 - 2015-04-02 22:36 - 00003202 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-12 11:31 - 2014-03-31 22:21 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-04-12 11:31 - 2014-03-31 22:21 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-12 11:31 - 2014-03-31 22:21 - 00004312 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-04-12 11:31 - 2014-03-31 22:21 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-04-12 11:31 - 2014-03-31 22:21 - 00000000 ____D C:\windows\system32\Macromed
2017-04-12 11:16 - 2014-03-31 20:19 - 00003958 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{864B416F-62E6-4C18-9D13-CE9989F2DEC7}
2017-04-12 11:13 - 2014-03-19 06:21 - 00000225 _____ C:\windows\CryptoMill_CreoService.003
2017-04-11 07:46 - 2014-03-19 06:21 - 00000225 _____ C:\windows\CryptoMill_CreoService.004
2017-04-10 11:58 - 2014-03-19 06:21 - 00000225 _____ C:\windows\CryptoMill_CreoService.005
2017-04-10 11:21 - 2015-04-02 23:10 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype
2017-04-09 20:52 - 2014-04-09 08:11 - 00003234 _____ C:\windows\System32\Tasks\HPCeeScheduleForAdministrator
2017-04-09 20:52 - 2014-04-09 08:11 - 00000364 _____ C:\windows\Tasks\HPCeeScheduleForAdministrator.job
2017-04-08 08:06 - 2010-11-21 13:27 - 00532136 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2017-04-06 21:12 - 2014-07-17 08:50 - 01887978 _____ C:\windows\ntbtlog.txt
2017-04-06 13:00 - 2014-03-19 06:05 - 00000000 ____D C:\Intel
2017-04-06 13:00 - 2009-07-14 15:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2017-04-06 13:00 - 2009-07-14 14:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-04-06 12:53 - 2009-07-14 15:32 - 00000000 ____D C:\Program Files\DVD Maker
2017-04-06 12:53 - 2009-07-14 13:20 - 00000000 ____D C:\windows\SysWOW64\Dism
2017-04-06 12:53 - 2009-07-14 13:20 - 00000000 ____D C:\windows\system32\Dism
2017-04-06 12:53 - 2009-07-14 13:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-04-06 03:42 - 2009-07-14 13:20 - 00000000 ____D C:\windows\AppCompat
2017-04-05 06:12 - 2009-07-14 13:20 - 00000000 ____D C:\windows\tracing
2017-04-05 06:12 - 2009-07-14 13:20 - 00000000 ____D C:\windows\system32\AdvancedInstallers
2017-04-05 06:11 - 2014-05-06 13:34 - 00000000 ___SD C:\windows\system32\CompatTel
2017-04-04 18:04 - 2015-04-02 22:37 - 00002203 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-04 18:04 - 2015-04-02 22:37 - 00002191 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-03 20:44 - 2009-07-14 12:34 - 44040192 _____ C:\windows\system32\config\components.bad
2017-04-01 16:33 - 2014-08-21 21:49 - 00000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2017-04-01 16:26 - 2009-07-14 13:20 - 00000000 ____D C:\windows\system32\NDF
2017-04-01 14:45 - 2015-07-06 10:46 - 00001908 _____ C:\windows\diagwrn.xml
2017-04-01 14:45 - 2015-07-06 10:46 - 00001908 _____ C:\windows\diagerr.xml
2017-04-01 14:45 - 2011-02-12 06:13 - 00000000 ____D C:\windows\Panther
2017-04-01 13:10 - 2015-04-02 22:38 - 00004180 _____ C:\windows\System32\Tasks\avast! Emergency Update
2017-03-30 11:15 - 2014-03-31 20:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-24 10:55 - 2014-09-05 18:20 - 00000000 ____D C:\windows\system32\catroot2.bak
2017-03-23 12:45 - 2016-09-19 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Complete
2017-03-23 12:45 - 2014-03-19 06:22 - 00000000 ____D C:\Program Files (x86)\PDF Complete
2017-03-19 12:38 - 2009-07-14 15:08 - 00032612 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-03-17 12:23 - 2014-04-25 10:46 - 00000000 ____D C:\Users\Administrator\Documents\Family Tree Maker
2017-03-16 07:39 - 2016-06-15 08:57 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2017-03-16 07:39 - 2015-04-02 23:09 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-03-16 07:39 - 2015-04-02 23:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-03-16 07:39 - 2014-03-19 06:19 - 00000000 ____D C:\ProgramData\Skype
2017-03-16 07:37 - 2014-03-19 06:13 - 00000000 ____D C:\ProgramData\Package Cache

==================== Files in the root of some directories =======

2014-04-03 07:14 - 2014-04-03 07:14 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-09-04 19:09 - 2014-09-04 19:14 - 14935512 _____ () C:\ProgramData\hpcsmmsilogs.log

Some files in TEMP:
====================
2013-06-05 03:30 - 2013-06-05 03:30 - 0050432 ____R () C:\Users\Administrator\AppData\Local\Temp\Extract.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-13 01:31

==================== End of FRST.txt ============================

And here's the output of Addition.txt:
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Administrator (13-04-2017 01:36:30)
Running from C:\Users\Administrator\Desktop
Windows 7 Professional Service Pack 1 (X64) (2014-03-31 08:24:14)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2394251349-1681379467-2739588611-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-2394251349-1681379467-2739588611-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2394251349-1681379467-2739588611-1003 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 24.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software)
BCL easyConverter SDK 3 (Word Version) 64 (HKLM\...\{350CC85B-CA59-4F85-909D-8E4CDBF532FA}) (Version: 3.0.64 - BCL Technologies)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.3207 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.)
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Family Tree Maker 2014 (HKLM-x32\...\Family Tree Maker 2014) (Version: 22.0.207 - Ancestry.com, Inc.)
Family Tree Maker 2014 (Version: 22.0.207 - Ancestry.com, Inc.) Hidden
Glance 2.9 (HKLM-x32\...\Glance_is1) (Version:  - Glance Networks, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 8.3.3.1786 - Hewlett-Packard Company)
HP Device Access Manager (HKLM\...\{122104A2-D83A-47CC-A25D-DD1EC1AD2741}) (Version: 8.3.3.0 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{5FCDA690-8D3F-4855-BEC5-B69977D23529}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Drive Encryption (HKLM\...\HPDriveEncryption) (Version: 8.6.5.142 - Hewlett-Packard Company)
HP File Sanitizer (HKLM-x32\...\{547607B0-3294-4ECA-8F5E-921404676CBB}) (Version: 8.4.13.1 - Hewlett-Packard Company)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 6700 Basic Device Software (HKLM\...\{A1CFA587-90D4-4DE6-B200-68CC0F92252F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Help (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Officejet 6700 Product Improvement Study (HKLM\...\{988D55BB-08DE-43C9-8D16-3751361E2A79}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{68E1C9E9-1606-49AF-9978-573148CED9E4}) (Version: 3.5.3.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{7561C06A-7797-4462-A7C3-86F45AE901CF}) (Version: 8.7.4 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP Theft Recovery (HKLM-x32\...\InstallShield_{B1E569B6-A5EB-4C97-9F93-9ED2AA99AF0E}) (Version: 8.3.0.7 - Hewlett-Packard Company)
HP Trust Circles (HKLM-x32\...\HP Trust Circles) (Version: 8.3.6.16976 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.009 - HTC Corporation)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.1.1000 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.19 - Intel Corporation)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.670 - Oracle)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2000 Disc 2 (HKLM-x32\...\{00040409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM-x32\...\{90110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\...\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft Office XP Standard (HKLM-x32\...\{90120409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2394251349-1681379467-2739588611-500\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 52.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 52.0.2 (x86 en-US)) (Version: 52.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.2.6291 - Mozilla)
Mozilla Thunderbird 45.8.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 45.8.0 (x86 en-US)) (Version: 45.8.0 - Mozilla)
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.2.11 - PDF Complete, Inc)
PeaZip 5.5.3 (HKLM-x32\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version:  - Giorgio Tani)
qBittorrent 3.1.12 (HKLM-x32\...\qBittorrent) (Version: 3.1.12 - The qBittorrent project)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.74.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
Skypeâ„¢ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Skypeâ„¢ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Skypeâ„¢ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
System Requirements Lab for Intel (HKLM-x32\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2394251349-1681379467-2739588611-500_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {13560FFD-2DAE-4EBE-9CC9-E5790F1F141A} - System32\Tasks\HPCeeScheduleForAdministrator => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {1DD4AE9B-5843-4276-AEF6-4EFB3E9AE8C5} - System32\Tasks\HP AR Program Upload - f1847313489d4b8a87f714dc3fc495372ebadfb2925d4d5691e28fafe13bed71 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {231F3D6A-B621-4DFD-A008-ECAD621F31F6} - System32\Tasks\HP AR Program Upload - f8774cd431ef47a09b6b982212b74b5c7103f493addf499fb9106156415aa122 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {695A07BA-4FDD-41A1-AD69-2A4E82F255AC} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2017-01-03] (AVAST Software)
Task: {6BA3277F-C4CA-43FB-941F-724B84236484} - System32\Tasks\HP AR Program Upload - 21a87f9fd6954346aa607a95cf7a2de9f4ac50ee3972446baf9d9f15b5166ce2 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {A07FBF07-FC86-4A25-A281-2A64885D8BB3} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-28] (AVAST Software)
Task: {A6478355-C6C2-439C-BD65-5B962B3F20C0} - System32\Tasks\HP Officejet 6700.exe_{B5400CA5-7352-4281-A244-09365E21522D} => C:\Program Files\HP\HP Officejet 6700\Bin\HP Officejet 6700.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {AB2CCC15-026C-4315-9ECC-0892A8E4F64C} - System32\Tasks\HPCustParticipation HP Officejet 6700 => C:\Program Files\HP\HP Officejet 6700\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {AD7CD062-0B01-487A-AE1C-5209278774E8} - System32\Tasks\SafeZone scheduled Autoupdate 1464672746 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {B5D36694-DEBB-496C-AA60-FC3EA9BFF52B} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe [2012-03-21] ()
Task: {CF144046-700B-4FDB-879D-C4E6CE9E152E} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-12] (Adobe Systems Incorporated)
Task: {D8C67129-CAC7-4CD3-A604-1FA4BD5D24D8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {DFFD7464-FA61-41E2-B39B-2F79342FE01F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {FEE74F2A-E943-47DF-A6CF-367D6C453ED5} - System32\Tasks\HP AR Program Upload - f054fff98575417a90263c172a7230653a901a48e5b940908e581e9a77074e3a => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForAdministrator.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Public\Desktop\Box offer for HP.lnk -> C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe () -> hxxp://js.redirect.hp.com/jumpstation?bd=all&c=none&locale=en_*&pf=cmdt&s=Box_50GB&tp=dticon

==================== Loaded Modules (Whitelisted) ==============

2013-09-18 04:32 - 2013-09-18 04:32 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll
2014-03-31 13:28 - 2014-03-31 13:28 - 00007168 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
2011-06-17 12:46 - 2011-06-17 12:46 - 00086528 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2014-01-25 02:22 - 2015-08-09 04:50 - 00404376 _____ () C:\windows\system32\igfxTray.exe
2017-01-03 07:14 - 2017-01-03 07:14 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-01-03 07:14 - 2017-01-03 07:14 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-04-12 20:36 - 2017-04-12 20:36 - 06022832 _____ () C:\Program Files\AVAST Software\Avast\defs\17041200\algo.dll
2014-03-19 06:19 - 2013-08-05 17:49 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-08-06 08:48 - 2013-08-06 08:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2017-01-03 07:14 - 2017-01-03 07:14 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-03 16:48 - 2014-04-03 16:48 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 12:34 - 2009-06-11 07:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2394251349-1681379467-2739588611-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.20.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{6670C688-703E-40DD-8C6A-1C8E6E2F0C94}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{42C40CA0-BDAE-48BC-B0F4-F18D37483239}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{7D6E39FE-D8FE-4E95-A4E7-57DC60289048}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{42FE0FF3-6164-431B-A1F6-D268C636ECF3}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{BDD9082A-B188-44F6-BC99-AB92A2D65ADA}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{05D1499C-480B-4E3E-8DE2-C9FFC287A48E}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{8C5EE46B-5FA6-40ED-99EF-2EC9C1E5F73A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{7BACA031-AD71-4FE8-81A1-E1BB495EA8EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C84790D5-6A70-467F-8056-C9F122668470}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{EEA8DAAB-E30A-4D33-8819-E1D0E5EB5315}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{249E21BC-942E-427F-B57B-F7332A2D0997}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9330C1FA-C11F-4345-B128-253D34E93E1A}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe
FirewallRules: [{2E9B16B1-B21D-4AD7-8328-D523E259AC77}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe
FirewallRules: [{4C64687E-A073-4BD1-8C85-ECA732C3E530}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe
FirewallRules: [{FAE7339F-5EB5-4C2B-AD62-9C0B3C58E247}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe
FirewallRules: [{B23361E4-2F93-4A32-9C7D-977F0E1D1CCB}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
FirewallRules: [{C99583D9-44B6-4FD2-8AAC-8AFF87D57683}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{AC41C6E0-1EDB-44DA-831F-78C360358144}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{12CA4C37-DFB2-4EC3-A2A3-E281201F3ABF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2D3DF19D-B9A8-47B7-B89C-F074E23558E6}] => (Allow) C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [TCP Query User{89125E55-B6F8-404A-8F8E-844FE4EBD1C4}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{E6FE2068-9BEC-4C31-8854-E1A23F236428}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{DD300CA2-B780-487E-8952-1AE482ADCF8B}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{A7DF8368-34FC-4E1E-99FA-FC4A8A233529}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{9859651F-3181-4C62-A948-FCD245BB3FF2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FEAF06D1-E8B7-4984-BC64-AF33B1D1D972}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FEBE1C06-3467-455E-9DE8-8863703C6ACD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

06-04-2017 22:25:32 Windows Update
06-04-2017 22:27:35 Windows Update
06-04-2017 22:36:52 Windows Update
06-04-2017 22:37:24 Windows Update
06-04-2017 22:46:00 Windows Update
06-04-2017 22:54:43 Windows Update
06-04-2017 23:00:40 Windows Update
06-04-2017 23:40:45 Windows Update
07-04-2017 03:00:25 Windows Update
08-04-2017 03:00:25 Windows Update
09-04-2017 03:00:14 Windows Update
10-04-2017 03:00:15 Windows Update
10-04-2017 11:36:35 Windows Update
10-04-2017 12:08:30 Windows Update
11-04-2017 08:39:38 Windows Update
12-04-2017 12:00:54 Windows Update
12-04-2017 18:14:44 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/12/2017 06:15:52 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF80
Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80.

Error: (04/12/2017 06:15:46 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
Description: Product: Microsoft Security Client -- Error 1921. Service 'Microsoft Antimalware Service' (MsMpSvc) could not be stopped.  Verify that you have sufficient privileges to stop system services.

Error: (04/12/2017 12:07:34 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF80
Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80.

Error: (04/12/2017 12:07:31 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
Description: Product: Microsoft Security Client -- Error 1921. Service 'Microsoft Antimalware Service' (MsMpSvc) could not be stopped.  Verify that you have sufficient privileges to stop system services.

Error: (04/11/2017 08:40:43 AM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF80
Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80.

Error: (04/11/2017 08:40:39 AM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
Description: Product: Microsoft Security Client -- Error 1921. Service 'Microsoft Antimalware Service' (MsMpSvc) could not be stopped.  Verify that you have sufficient privileges to stop system services.

Error: (04/10/2017 12:09:54 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF80
Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80.

Error: (04/10/2017 12:09:33 PM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
Description: Product: Microsoft Security Client -- Error 1921. Service 'Microsoft Antimalware Service' (MsMpSvc) could not be stopped.  Verify that you have sufficient privileges to stop system services.

Error: (04/10/2017 11:37:34 AM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF80
Description:Cannot complete the Security Essentials Upgrade. An error has prevented the Security Essentials Upgrade Wizard from continuing. The previous version of Security Essentials was restored. Error code:0x8004FF80.

Error: (04/10/2017 11:37:25 AM) (Source: MsiInstaller) (EventID: 11921) (User: NT AUTHORITY)
Description: Product: Microsoft Security Client -- Error 1921. Service 'Microsoft Antimalware Service' (MsMpSvc) could not be stopped.  Verify that you have sufficient privileges to stop system services.


System errors:
=============
Error: (04/12/2017 11:14:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (04/12/2017 08:37:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Support Assistant Service service failed to start due to the following error: 
The system cannot find the file specified.

Error: (04/12/2017 06:15:54 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Security Essentials - 4.10.209.0 (KB3205972).

Error: (04/12/2017 05:22:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Support Assistant Service service failed to start due to the following error: 
The system cannot find the file specified.

Error: (04/12/2017 12:07:36 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Security Essentials - 4.10.209.0 (KB3205972).

Error: (04/12/2017 11:16:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Support Assistant Service service failed to start due to the following error: 
The system cannot find the file specified.

Error: (04/12/2017 11:14:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Device Access Manager Usage Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (04/12/2017 11:14:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the HP Device Access Manager Usage Service service to connect.

Error: (04/11/2017 08:40:45 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Security Essentials - 4.10.209.0 (KB3205972).

Error: (04/11/2017 08:00:50 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

    New Signature Version: 

    Previous Signature Version: 1.239.1134.0

    Update Source: Microsoft Update Server

    Update Stage: Search

    Source Path: http://www.microsoft.com

    Signature Type: AntiVirus

    Update Type: Full

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: 

    Previous Engine Version: 1.1.13601.0

    Error code: 0x80244022

    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.


CodeIntegrity:
===================================
  Date: 2017-04-03 23:08:37.587
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 23:08:37.587
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:50:23.672
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:50:23.672
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:49:13.601
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:49:13.600
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:48:24.951
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:48:24.951
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:48:07.397
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2017-04-03 22:48:07.397
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\PROCMON23.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Percentage of memory in use: 24%
Total physical RAM: 8120.2 MB
Available physical RAM: 6129.75 MB
Total Virtual: 16238.57 MB
Available Virtual: 13567.2 MB

==================== Drives ================================

Drive c: (Windows ) (Fixed) (Total:454.04 GB) (Free:221.72 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:10.61 GB) (Free:1.17 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
Drive f: (GSP1RMCPRXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF
Drive i: (SAMSUNG) (Fixed) (Total:931.51 GB) (Free:866.28 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7D1D7CEF)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=454 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=10.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=100 MB) - (Type=0C)

========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: E8E49842)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
Thank you. To confirm, have you tried to uninstall each of the programs listed below from add/remove programs?

Microsoft Office 2000 Disc 2
Microsoft Office Word Viewer 2003
Microsoft Office XP Professional
Microsoft Office XP Professional with FrontPage
Microsoft Office XP Standard
Microsoft PowerPoint Viewer
Microsoft Security Essentials
 
I have. And the thing is, the Microsoft Office 2000, and Microsoft Office XP ones require a disc to uninstall, so I removed them manually years ago, but there still may be some files remaining, but I'm pretty sure I removed them, it may just be the registry. And I'm pretty sure I've uninstalled Word Viewer 2003 and PowerPoint Viewer, but I'm not sure if it was done correctly, I'll take a look again and see. Yep, they don't appear in Add/Remove.

And as for Microsoft Security Essentials, just like I said earlier, uninstalling it just results in Error 8004FF80 on the uninstaller.
 
Alrighty, I ran the tools, it didn't say anything of whenever it uninstalled successfully and didn't show any errors. They closed immediately as it had finished cleaning the registry. Except the last one, which showed that the Fix It had processed successfully.

So I'm not exactly sure if there it was or wasn't successful.
 
OK, good. I never recommend registry cleaners but I'm going to make an exception in this instance. Please download and install the following.
CCleaner - Standard

When installing, ensure you uncheck any of the optional stuff that may be offered at the bottom of the screen (example below).
Capture.JPG

Run Ccleaner and select the Registry button and then click "Scan for Issues". Once all the identified issues come up, click the Fix selected Issues... button.

You will get a question as to whether you want to back up the registry. Please answer Yes. Save this file to your desktop.

You may get another prompt asking what you want to do. Click Fix All Selected Issues. When it's done, close the program and reboot your machine.

Let me know when complete. Thanks.
 
Alrighty, I installed CCleaner, and it didn't offer any optional stuff during the installation process. I ran CCleaner and have backed up the registry and selected Fix All Selected Issues and then rebooted the OS.
 
Okay, I reloaded Windows Updates, and only KB3205972 - Update for Microsoft Security Essentials - 4.10.209.0 appears.
 
OK, good. So the last issue is MSE. You need to get rid of it correct? You should be able to follow the manual removal steps from the following link.
https://support.microsoft.com/en-us...l-it-by-using-the-add-or-remove-programs-item

If you are uncomfortable doing this or would prefer that I assist with this then I will need your Software hive. If that's the case, please follow the steps below.


Step#1 - Retrieve Software Hive
Note: The Software hive has confidential and sensitive information in it so please send me a PM with a link to the hive so it's not in the public form.

  • Open RegBack by clicking on your Start button and clicking on Registry Backup and Restore. Answer Yes on the User Account Control dialog if prompted.
  • Click the New Backup button.
  • Click the link that says "Click here to view details of the hives in the backup".
  • Uncheck the "Current User (recommended)" checkbox at the top of the form. Keep "System (recommended)" checked.
  • At the bottom of the form, uncheck all options except "C:\Windows\System32\config\SOFTWARE" and click OK.
  • Click the Start button to begin the backup.
  • When it says Finished successfully, click the Close button.
  • This will bring you back to the main screen of the program. You will see two entries in this list. Right-click on the one from today and select Explore Backup...
  • This will bring you into the folder where the backup was made. You should see a Users folder and a Windows folder along with a couple other files. Double-click on the Windows folder to open it. Then open the System32 folder and then config folder. You should see one file which is named SOFTWARE.
  • Copy this file to your Desktop and overwrite any one that is currently there.
  • Now right click on this file on your desktop and select Send to > Compressed (zipped) folder.
  • Then please upload the zip file(s) to your favourite file sharing website (it will be too big to upload here). Examples of services to upload to are Dropbox or One Drive or SendSpace and then just PM me your link.
  • You can close any open windows you have as well as the RegBack program now.
 
MSE really is hard to remove. I have deleted as many entries as I could, many of them are protected by the software itself. Even attempting to terminate the service, or even using the run command won't do anything to stop MsMpSvc or any other service. even while running as Administrator. Even MsMpEng.exe can't be terminated in Task Manager.

Attempting to delete some registry keys results in an error like these one:
Code:
Cannot delete Microsoft Antimalware_1D09423BE52AF3D: Error while deleting key.
Code:
Cannot delete MsMpSvc: Error while deleting key.

Attempting to stop the service results in this:
Code:
The operation could not be completed.
Access is denied.
 
When I booted into Safe Mode, I wasn't able to end MsMpSvc from services, but I was able to end the MsMpEng.exe process from Task Manager. Then I deleted as many files (including MsMpEng.exe and any related files) and registry entries as I could, rebooted, deleted more registry entries and the remaining Microsoft Security Client and Microsoft Antimalware files, rebooted again and then tried to remove more of them.

But then, there was some registry entries that I was unable to delete, some in which point to MsMpEng.exe. Resulted in the same error, as seen with this one:
Code:
Cannot delete Microsoft Antimalware_1D09423BE52AF3D: Error while deleting key.
Despite their source files being removed, something seems to be using the registry entries, or at least preventing them from being deleted.
 
For the registering entries that you are unable to delete, can you right-click on them and choose copy key and paste them into your next reply?
 
Sorry for my late response. Anyways, this is a pretty long list, here's the following keys that I'm unable to delete:

HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D267061D83B0A3
HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D2AE7DEAA73FA9
HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D2AE854441E67F
HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D2AE87B8924E2C
HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D2AE87EF09DF53
HKEY_CURRENT_USER\Software\Microsoft\Microsoft Antimalware_1D2AEDB730F4072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware Setup

String Name: 2D153B43-11B4-461f-AA43-832B2C8B8872 | Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Microsoft Antimalware

String Name: 2D153B43-11B4-461f-AA43-832B2C8B8872 | Location: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup

HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D09423BE52AF3D
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D09541E89AF135
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D09CF32F158343
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D09DB54D1F3070
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A01D6AC1C3EC
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A143DECECAC4
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A173C9EDDDC7
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A1D76467BCC8
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A8E65E08529B
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0A99B506D08EE
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0AA3F2D7C8986
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0AB21CF4819D8
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0AE567E025539
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0AE78B857B792
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B3AD67213C4C
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B53951E53B43
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B77C63A2D76F
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B80D7B867769
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B89ED3992B4
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0B927ED9DFC14
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0BDF91CD9B4C2
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0BE962014C3A0
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0BF8A44E5746F
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C03554227360
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C1F31FC10771
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C364BB7C9C56
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C5A6C5729F00
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C76175EC6F9E
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C8014C617952
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C8C6FF7AFEE9
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0C99412EEAD43
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0CA5AB2506EFA
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0CB70416E55B9
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0CD01F09C149B
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0CD93DE02C7D5
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0CF38F57F505A
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D03BECAF1FCA
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D19FC0ADFD79
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D1BE9D11CD6A
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D25443783DBB
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D26FD08566C7
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D2FE84ED8193
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D36057F9E6D8
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D8A9AD227345
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0D94384A0B576
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DD3FF526A11B
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DD79C8731E6E
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DDFF1DC99485
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DEC223BE1823
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DF9445C814AF
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0DFB322EA6BE0
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0E055B9293874
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0E37B8D439E6F
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0E43FC6DFE743
HKEY_USERS\.DEFAULT\Software\Microsoft\Microsoft Antimalware_1D0E528C247F64E
...

It's incredibly long in this section, so I'm going to export the Microsoft key, then copy and paste all the Microsoft Antimalware keys into a new txt file and put it into a .zip:

View attachment microsoft-antimalware.zip

Alright, next is the rest of the keys:
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D267061D83B0A3
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D2AE7DEAA73FA9
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D2AE854441E67F
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D2AE87B8924E2C
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D2AE87EF09DF53
HKEY_USERS\S-1-5-21-2394251349-1681379467-2739588611-500\Software\Microsoft\Microsoft Antimalware_1D2AEDB730F4072
 
Again, sorry for the oversight. Please do the following.

FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download fixlist.txt and save it to the Desktop.
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please zip up this file and attach to your next reply.
 
Back
Top