Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Cecile on ma 16/05/2016 at 16:09:31,70. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Cecile\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2016-05-13-203343.log 4326 bytes ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Empty Folders Check ====================== C:\PROGRA~3\Comms deleted successfully C:\Users\Cecile\AppData\Local\ActiveSync deleted successfully C:\Users\Cecile\AppData\Local\NetworkTiles deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B3769379-0E4F-48C0-9BDF-A470CA88B674} deleted successfully HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B4ECC3BD-7885-4436-8AE1-1CFA47240E67} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B4ECC3BD-7885-4436-8AE1-1CFA47240E67} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeKrnl deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeNetFilter deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default user.js not found ---- Lines delta removed from prefs.js ---- user_pref("browser.search.selectedEngine", "delta-homes"); ---- Lines quick_start removed from prefs.js ---- user_pref("extensions.quick_start.enable_search1", false); user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); ---- Lines searchengine removed from prefs.js ---- user_pref("browser.search.searchengine.alias", ""); user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); user_pref("browser.search.searchengine.iconURL", "http://www.nicesearches.com/favicon.ico?t=1"); user_pref("browser.search.searchengine.name", "nice "); user_pref("browser.search.searchengine.ptid", "wpm07163"); user_pref("browser.search.searchengine.ref", ""); user_pref("browser.search.searchengine.ts", "1462764438"); user_pref("browser.search.searchengine.type", ""); user_pref("browser.search.searchengine.uid", "wdcxwd5000lpvx-75v0tt0_wx71a14l9878a14l9878"); user_pref("browser.search.searchengine.url", "http://www.nicesearches.com/search.php?type=ds&ts=1462764438&from=87640509&uid=wdcxwd5000lpvx-75v0tt0_wx ---- Lines searches removed from prefs.js ---- user_pref("browser.newtab.url", "http://www.nicesearches.com?type=hp&ts=1462764438&from=87640509&uid=wdcxwd5000lpvx-75v0tt0_wx71a14l9878a14l9878&z=d9b ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 0); ---- FireFox user.js and prefs.js backups ---- prefs_20161305_1335_.backup prefs_20161605_1637_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe] ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Uniblue\SpeedUpMyPC not found C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default\extensions\arthurj8283@gmail.com not found C:\Program Files (x86)\AVG Web TuneUp deleted C:\Program Files (x86)\Common Files\DVDVideoSoft deleted C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater deleted C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default\extensions\1427743657_xpi deleted C:\Users\Cecile\AppData\Local\AVG Web TuneUp deleted C:\PROGRA~2\PriceGong deleted C:\Program Files\AVG Web TuneUp deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\COMMON~1\AVG Secure Search deleted C:\PROGRA~3\APN deleted C:\PROGRA~3\AVG Web TuneUp deleted C:\PROGRA~3\AVG Security Toolbar deleted C:\PROGRA~3\eWinManProe deleted C:\PROGRA~3\IHProtectUpDate deleted C:\PROGRA~3\AVG Secure Search deleted C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted C:\PROGRA~3\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} deleted C:\PROGRA~3\Package Cache deleted C:\Users\Cecile\AppData\Local\SearchProtect deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\WINDOWS\Tasks\SpeedUpMyPC Maintenance.job deleted C:\WINDOWS\Tasks\SpeedUpMyPC Startup.job deleted C:\windows\SysNative\Tasks\SpeedUpMyPC Maintenance deleted C:\windows\SysNative\Tasks\SpeedUpMyPC Startup deleted C:\Users\Cecile\AppData\LocalLow\Unity deleted C:\Users\Cecile\AppData\LocalLow\DataMngr deleted C:\Users\Cecile\AppData\LocalLow\Allin1Convert_8hEI deleted C:\WINDOWS\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb deleted C:\END deleted C:\WINDOWS\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb deleted "C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default\websearches.sqlite" deleted "C:\Users\Cecile\AppData\Roaming\driver\driver.html" deleted "C:\Users\Cecile\AppData\Roaming\driver" deleted "C:\Users\Cecile\AppData\Roaming\eCyber" deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2016-05-14 16:16:17 2617877C5761B8A696FD0368861EE6E4 4515256 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\Cecile\AppData\Local\Temp ==== ====== Java Cache ===== 2016-05-16 14:06:21 4F85459CEC4F78A3987FFFD5B6A816C5 605 ----a-w- C:\Users\Cecile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\52c00ce5-2ac71673 2016-05-16 14:06:21 82651FC960753876875580E3B996D83E 429 ----a-w- C:\Users\Cecile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\52c00ce5-78e96a5ccf5c5b6a29dcdffe1d16c989d010904d54059e7b28aad8dacf6a56c9-6.0.lap 2016-05-16 14:06:21 33E6A7F07217C4DAFA9AA4E7714A0CCA 8513 ----a-w- C:\Users\Cecile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\298d42d-4df5b8e1 2016-05-16 14:06:31 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Cecile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\c8dc66e-680e7cc1 ====== C:\WINDOWS\SysWOW64 ===== 2016-05-14 16:16:56 15F732C297CE4B169D85214A96A16559 792064 ----a-w- C:\WINDOWS\SysWOW64\kerberos.dll 2016-05-14 16:16:53 22120EE8EC8AC405618FEA768071E267 19344384 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2016-05-14 16:16:49 3A5C07D5517087143701DBEB749F0EF1 18676224 ----a-w- C:\WINDOWS\SysWOW64\edgehtml.dll 2016-05-14 16:16:46 0561104CC8619EC5A53848F642434235 13018112 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-05-14 16:16:37 9CD20753821A4F28AA797B5C9A24050F 9918976 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2016-05-14 16:16:33 5D9BB3289D25FDEA1B2DD491C9771778 21123320 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2016-05-14 16:16:32 98DA2DE9A1AC739DF3750F7DABECC9CF 6295552 ----a-w- C:\WINDOWS\SysWOW64\mos.dll 2016-05-14 16:16:32 468AA89AF32BEE9D6B0ABBDF7C88CF20 5240960 ----a-w- C:\WINDOWS\SysWOW64\windows.storage.dll 2016-05-14 16:16:31 5A77C7C30E117F60ACCEF43E2EA6841D 12125696 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2016-05-14 16:16:29 A404EA688829EF2657431CB34D0C72DF 5660160 ----a-w- C:\WINDOWS\SysWOW64\Chakra.dll 2016-05-14 16:16:29 85ED26DB17B3270944C344E0E5B7C34A 1542816 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2016-05-14 16:16:28 9F6F693FD7738B8DA4B420E46E973F35 2919832 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2016-05-14 16:16:25 3AEDE16F62921F443DDE37440C84B6F1 5205504 ----a-w- C:\WINDOWS\SysWOW64\BingMaps.dll 2016-05-14 16:16:16 FA6CCFE5305E3D276F06A104EAA83029 4759040 ----a-w- C:\WINDOWS\SysWOW64\d2d1.dll 2016-05-14 16:16:15 52FEDEA32F2BBFCD3AAA83FD39852C1A 2061824 ----a-w- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-05-14 16:16:14 80785EA474D952CC0CB2CF936E36DDE0 3666432 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2016-05-14 16:16:14 692E62EA6039478321AE5D24A68E1FE2 4074160 ----a-w- C:\WINDOWS\SysWOW64\explorer.exe 2016-05-14 16:16:11 717DDEC1ABA5678EDC9F2AF1044BAA69 2000896 ----a-w- C:\WINDOWS\SysWOW64\twinui.appcore.dll 2016-05-14 16:16:03 FB01CB67364FF3AA677F0CFD8C958E50 5324288 ----a-w- C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-05-14 16:16:02 2942FB92C23B77D3BD9D38117AF3663B 1557768 ----a-w- C:\WINDOWS\SysWOW64\KernelBase.dll 2016-05-14 16:15:59 1F90253211F8E102D814F4DE4D550B85 1626624 ----a-w- C:\WINDOWS\SysWOW64\dwmcore.dll 2016-05-14 16:15:59 0188F4F7264EE585DE518FD02DDD9F79 711680 ----a-w- C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-05-14 16:15:58 35E635469515D564CE418DDCC7B7BC96 1500160 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2016-05-14 16:15:58 2CE163D00A7DA251D77F7B39E267382B 925064 ----a-w- C:\WINDOWS\SysWOW64\mfplat.dll 2016-05-14 16:15:57 32A696B0A48CCCCE5FC8E8E572FD4E90 434688 ----a-w- C:\WINDOWS\SysWOW64\LogonController.dll 2016-05-14 16:15:56 E48F0A089D9BAE356BF14FE3A16B1147 489984 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.dll 2016-05-14 16:15:56 B6506139C8A4CE3BDD3B4EFDF63A87B5 348672 ----a-w- C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-05-14 16:15:56 03B7C4D05DB7FF060E49FA900FCE627E 451928 ----a-w- C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2016-05-14 16:15:55 25E42F5C3FDE0E96BF3C16814DC7A688 1372304 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll 2016-05-14 16:15:54 30E3DC9ED2C6641709AC961CB7CE72BB 647680 ----a-w- C:\WINDOWS\SysWOW64\jscript.dll 2016-05-14 16:15:53 3A1BD59AF5A0D20438D1E44FCF5EA4E8 349696 ----a-w- C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-05-14 16:15:52 362C9AA8696C74CD38F1416FF866C25C 522176 ----a-w- C:\WINDOWS\SysWOW64\dxgi.dll 2016-05-14 16:15:51 4ECC2FAF9F29066636E06253C0D7FA06 503296 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2016-05-14 16:15:51 1D04327817511268754ED6F177DAD3E8 754176 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-05-14 16:15:50 DFB54165665C7E369A59B273C91B90B0 800768 ----a-w- C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-05-14 16:15:49 D408D20295BA135DC1B9B181FADF78DD 255168 ----a-w- C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-05-14 16:15:49 318E2A6EC26C9703A5B273B015672660 388608 ----a-w- C:\WINDOWS\SysWOW64\schannel.dll 2016-05-14 16:15:48 4B71644224F39A390B6DCC482B3D582A 639488 ----a-w- C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-05-14 16:15:48 4AE45F3077E79A3E3B22996F80DA9E7A 354304 ----a-w- C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-05-14 16:15:47 89C74675E6DE7888153B1F6644772774 1536088 ----a-w- C:\WINDOWS\SysWOW64\crypt32.dll 2016-05-14 16:15:47 122F8F0FAF690B88FBDE2DB097740AB6 569744 ----a-w- C:\WINDOWS\SysWOW64\SHCore.dll 2016-05-14 16:15:45 1587235261E629DFFAA0C39A72CAD1A6 667648 ----a-w- C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-05-14 16:15:45 10564E7A7EE807FF580E34A94ACF5590 1522152 ----a-w- C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-05-14 16:15:43 A825405D442EB9A2526468E16296DD58 513368 ----a-w- C:\WINDOWS\SysWOW64\d3d10level9.dll 2016-05-14 16:15:43 9E6DBA611E99BE75589D6A358F54364F 137728 ----a-w- C:\WINDOWS\SysWOW64\shacct.dll 2016-05-14 16:15:42 E7BD4D15CDC5A1E162256CFADCA92344 1337240 ----a-w- C:\WINDOWS\SysWOW64\user32.dll 2016-05-14 16:15:41 525FC35182F9660E2A7DCC75607535DC 707608 ----a-w- C:\WINDOWS\SysWOW64\rpcrt4.dll 2016-05-14 16:15:41 1B26C71109A2EA27DD6684719BF493EC 188256 ----a-w- C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-05-14 16:15:39 CD36155EE56E94B4E8830FA90822511F 503296 ----a-w- C:\WINDOWS\SysWOW64\SettingSync.dll 2016-05-14 16:15:38 A1A9DDD5C6A335C0B97423A2F75C9299 453472 ----a-w- C:\WINDOWS\SysWOW64\directmanipulation.dll 2016-05-14 16:15:38 9F8A026A9643F89B4E451539A7AAC0C9 50176 ----a-w- C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-05-14 16:15:38 30F680D95B0CCABE46C775672C912C0A 306832 ----a-w- C:\WINDOWS\SysWOW64\wlanapi.dll 2016-05-14 16:15:37 5AEDC6D333BC8D8B1DE5928FCE2150DB 400896 ----a-w- C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-05-14 16:15:37 460CDD92C5283DCB9E35AF2B8DB7F200 461824 ----a-w- C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-05-14 16:15:37 1159023FAA938BF54C7C033D2BC643BE 59904 ----a-w- C:\WINDOWS\SysWOW64\MosStorage.dll 2016-05-14 16:15:36 FAD56D0A789345614220D9B770DF400A 465760 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-05-14 16:15:35 B91176A909798C7EAC28AB4FE786CA53 705536 ----a-w- C:\WINDOWS\SysWOW64\wuapi.dll 2016-05-14 16:15:34 25B0BAA64D6D62873FAA7719DB64015C 183904 ----a-w- C:\WINDOWS\SysWOW64\rsaenh.dll 2016-05-14 16:15:30 AB48B90C4DB88D2F31D1A6F460F76D29 241664 ----a-w- C:\WINDOWS\SysWOW64\cryptngc.dll 2016-05-14 16:15:30 9CAC58EBAFB3E32711920568810CDCD7 307200 ----a-w- C:\WINDOWS\SysWOW64\ieproxy.dll 2016-05-14 16:15:29 E9E7FA1FC796ADC16A1169736EFC7AF3 84480 ----a-w- C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2016-05-14 16:15:28 DA97C8A8C517210E4ACA90E45C836E80 80896 ----a-w- C:\WINDOWS\SysWOW64\BluetoothApis.dll 2016-05-14 16:15:28 96101F3B90BDE894A862CDF1B808A03F 84832 ----a-w- C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-05-14 16:15:28 8E8FBA400CD678AB46D46BB24921A051 342528 ----a-w- C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-05-14 16:15:28 0D19695F93813C63B4656E42536892FA 47104 ----a-w- C:\WINDOWS\SysWOW64\hmkd.dll 2016-05-14 16:15:27 AA7CBB3B7A7BFC41E9EC4EF645797DFA 502104 ----a-w- C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-05-14 16:15:27 98DA8D97E83C73E7AD7A142A801E1898 2193408 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2016-05-14 16:15:26 359765C7C700F7CED909A69C5DBBD943 140800 ----a-w- C:\WINDOWS\SysWOW64\BrowserSettingSync.dll 2016-05-14 16:15:25 89C06DA6E3B3C06F69E2CAFB3431CAF5 31232 ----a-w- C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe 2016-05-14 16:15:25 3166A46AA132AACD035C7163108F2DA1 103936 ----a-w- C:\WINDOWS\SysWOW64\updatepolicy.dll 2016-05-14 16:15:24 F5814ED9E8B83F872FBDCB139B001C8A 23552 ----a-w- C:\WINDOWS\SysWOW64\wups.dll 2016-05-14 16:15:19 CD94405BB0A90B179E94BE23F4D2B79D 39424 ----a-w- C:\WINDOWS\SysWOW64\wfdprov.dll 2016-05-14 16:15:19 486919689633D1C0DADA718DF1A3E7FB 219648 ----a-w- C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-05-14 16:15:18 3D3BBD2DA5660B0B6C9F6A8B9401648C 337920 ----a-w- C:\WINDOWS\SysWOW64\wlanmsm.dll 2016-05-14 16:15:17 51DF6FC12B5EF8CA87414D79C98CBC7A 395264 ----a-w- C:\WINDOWS\SysWOW64\wlansec.dll 2016-05-14 16:15:16 8450005F7BA8662A64E3FB7B0C3EE836 51712 ----a-w- C:\WINDOWS\SysWOW64\wshbth.dll 2016-05-14 16:15:16 6BC0E961EA78AFD90348C8E05896A7DC 784896 ----a-w- C:\WINDOWS\SysWOW64\NMAA.dll 2016-05-14 16:15:14 40591C3BEBAEA638423B10863315D93F 87040 ----a-w- C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-05-14 16:15:10 9B034D049D1C6EC9BED55D2F27D86ED9 2186 ----a-w- C:\WINDOWS\SysWOW64\AppxProvisioning.xml 2016-05-14 08:42:03 79422D76818752C6D935A97C8FFC4EEA 44147 ----a-w- C:\WINDOWS\SysWOW64\license.rtf 2016-05-14 08:34:02 EC21FC40C74206DAB19F1A8F9132EFAB 890368 ----a-w- C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-05-14 08:34:02 C8F351BE29CEA63BC5EE5A175576B7F3 1105920 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-05-14 08:34:02 C86784A6F08E733BE19D62C82182FA7D 266752 ----a-w- C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2016-05-14 08:34:02 C117F577BB0CC6545EA181FBB3FACE99 980352 ----a-w- C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-05-14 08:34:02 B65549A1CDB2C827AD022A3F35994FCF 2180136 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2016-05-14 08:34:02 AF209F751EB761084CEFE2CF10E1CE8D 895080 ----a-w- C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-05-14 08:34:02 A7583A49B0F4A91E5B2E154C3582DF82 420928 ----a-w- C:\WINDOWS\SysWOW64\msvproc.dll 2016-05-14 08:34:02 A34EDEA5F401143A0190642EABA28518 709688 ----a-w- C:\WINDOWS\SysWOW64\mfsvr.dll 2016-05-14 08:34:02 A19A2DDCC69FF16B5FB68AD4F02B564A 480256 ----a-w- C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-05-14 08:34:02 964DE3052B6A869EFBC86930DD51E8BD 379392 ----a-w- C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-05-14 08:34:02 92B98A16E41005D74CF7B2EF28AB1FCF 26112 ----a-w- C:\WINDOWS\SysWOW64\wsdchngr.dll 2016-05-14 08:34:02 888D41F5EFD6995491326C0DEEA2124A 713824 ----a-w- C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2016-05-14 08:34:02 49CF99392314B7CAD65DE8A05ABFE30D 882720 ----a-w- C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-05-14 08:34:02 463DA1563BB9C1849527967BA80C1810 287712 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll 2016-05-14 08:34:02 05B15BD9C92BE52F35A2295B22C5D892 168448 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-05-14 08:34:01 B073C14F8B76DF8652415488C22F10A1 670928 ----a-w- C:\WINDOWS\SysWOW64\mfds.dll 2016-05-14 08:34:01 8D9CB9BB31AC17112D75456E928C3839 103936 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2016-05-14 08:34:01 287FAD133D3E5F47DB367B86DC523631 2798080 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-05-14 08:34:00 550ECFF3C3808065169BFEA6C2B7837C 400896 ----a-w- C:\WINDOWS\SysWOW64\winspool.drv 2016-05-14 08:33:59 B315EB17077EF082A79922D4EA47DBF4 163328 ----a-w- C:\WINDOWS\SysWOW64\fwbase.dll 2016-05-14 08:33:59 9DEB4C56FAAB147839BF68B6C28A38FC 164864 ----a-w- C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-05-14 08:33:59 9A9CDAB4049BDB383C5CA8746F44E4CB 269824 ----a-w- C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2016-05-14 08:33:59 7734BD0E9C8ED7DC48F559A67D0A79F4 20480 ----a-w- C:\WINDOWS\SysWOW64\wfapigp.dll 2016-05-14 08:33:59 160CC95D34D62B6A72F9E4E3EE52EBCC 369664 ----a-w- C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-05-14 08:33:48 AD1B282BDE4A19D7CE2D405409DBB8D0 1497088 ----a-w- C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-05-14 08:33:47 780795062541AF34415CCCE4072FBBB8 12586496 ----a-w- C:\WINDOWS\SysWOW64\wmp.dll 2016-05-14 08:33:40 F40196C743D54C56C7C2CCDD6FDE262E 572272 ----a-w- C:\WINDOWS\SysWOW64\taskschd.dll 2016-05-14 08:33:40 F297B1F54D3FF42732C89C738AEC041F 141824 ----a-w- C:\WINDOWS\SysWOW64\easwrt.dll 2016-05-14 08:33:40 E9B121C13C171C28E8AF4871B52AABA0 450560 ----a-w- C:\WINDOWS\SysWOW64\SyncController.dll 2016-05-14 08:33:40 CA57FE09C1255009C9AC1462B7D7264D 957608 ----a-w- C:\WINDOWS\SysWOW64\ole32.dll 2016-05-14 08:33:40 C31BB8559C52E389B82A4B533C2FB39A 764928 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-05-14 08:33:40 B9378EA1892974391D15D54E57056130 151040 ----a-w- C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-05-14 08:33:40 B4643C990D071EE99D9713336052F97B 193024 ----a-w- C:\WINDOWS\SysWOW64\credprovhost.dll 2016-05-14 08:33:40 B1D8636E375413D57B50BDE20CA5E710 358400 ----a-w- C:\WINDOWS\SysWOW64\AccountsRt.dll 2016-05-14 08:33:40 9DB69A637142A6C72DF22706CF2F6F7B 31744 ----a-w- C:\WINDOWS\SysWOW64\TimeBrokerClient.dll 2016-05-14 08:33:40 97E96ABEBCB6CF556406781C47C5282A 78848 ----a-w- C:\WINDOWS\SysWOW64\asycfilt.dll 2016-05-14 08:33:40 96BFB1E4B3F38D999E418D286BE45BFB 118272 ----a-w- C:\WINDOWS\SysWOW64\mtxoci.dll 2016-05-14 08:33:40 8CE4D365EF60DA0A098757371DD43752 88576 ----a-w- C:\WINDOWS\SysWOW64\olepro32.dll 2016-05-14 08:33:40 7D276C5DF303462091092C3311027D30 129024 ----a-w- C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2016-05-14 08:33:40 64229C17CFE9262689EAE3E852D3975F 296488 ----a-w- C:\WINDOWS\SysWOW64\policymanager.dll 2016-05-14 08:33:40 5A98CF000F5202776E4A58438AB2E070 4412928 ----a-w- C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-05-14 08:33:40 594D1C58958A1F980336964B643784F3 3671040 ----a-w- C:\WINDOWS\SysWOW64\msi.dll 2016-05-14 08:33:40 2BECAD7E55AB723F361254477270ED2F 1707520 ----a-w- C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-05-14 08:33:40 197948552BE23DACBEF10ECC8168FD11 29696 ----a-w- C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-05-14 08:33:40 100E983F59F3BF3A3F8BFA327CF9B438 157184 ----a-w- C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2016-05-14 08:33:40 0BF6FDE72035DDC32FAF24344853B80B 777728 ----a-w- C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2016-05-14 08:33:35 EB5DBA11B7C79B28A759AF12F03A17BB 769536 ----a-w- C:\WINDOWS\SysWOW64\ContactApis.dll 2016-05-14 08:33:35 E34395496B11CF5C8C5B6D2E438BFA43 18944 ----a-w- C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-05-14 08:33:35 AD1EC1102124182624F1224768FFAE96 564224 ----a-w- C:\WINDOWS\SysWOW64\WSDApi.dll 2016-05-14 08:33:35 93B7ED5F44D9C3FB0A74C059E1B9E68B 89088 ----a-w- C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-05-14 08:33:35 806D3A66BBC91F7F2B4FCC337C13EFAE 239104 ----a-w- C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2016-05-14 08:33:35 75B5C1588D3703F44004D3EB2BD358AD 129024 ----a-w- C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-05-14 08:33:35 6C2B2CA75F486449921ED10A39DB9799 69744 ----a-w- C:\WINDOWS\SysWOW64\netapi32.dll 2016-05-14 08:33:35 620737C11CD32E03299E0B60BC896230 552960 ----a-w- C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-05-14 08:33:35 5A212173FC0622865F409B16ED77C9DF 98304 ----a-w- C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-05-14 08:33:35 56315A6A6598E701BB0A5F506DA6143E 200704 ----a-w- C:\WINDOWS\SysWOW64\cemapi.dll 2016-05-14 08:33:35 4B9DE8EAA2E16C34E018749F325BAEFF 949248 ----a-w- C:\WINDOWS\SysWOW64\Unistore.dll 2016-05-14 08:33:35 43AE8C9F7D031AB3DBEADA4C17D8C682 150528 ----a-w- C:\WINDOWS\SysWOW64\VCardParser.dll 2016-05-14 08:33:35 3B1F2F6F89F3F4ED75C5FADDB2E7CFE1 56320 ----a-w- C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-05-14 08:33:35 39E7BAB659A6AB4419A908E578BE7029 56320 ----a-w- C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-05-14 08:33:35 395F9E50709FAE503C339047207E46CF 540160 ----a-w- C:\WINDOWS\SysWOW64\ChatApis.dll 2016-05-14 08:33:35 392434472351B2DA0499AEC962E988CE 37888 ----a-w- C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-05-14 08:33:35 3547D79A60007624BFEBAFCAE158E992 169984 ----a-w- C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-05-14 08:33:35 31657EDEEA6039E71C708BDA61AB62D5 37888 ----a-w- C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-05-14 08:33:35 2C84609F09FD003FA955567D395EEA8A 575488 ----a-w- C:\WINDOWS\SysWOW64\EmailApis.dll 2016-05-14 08:33:35 259517866C369BCC5990292BCB57E709 223744 ----a-w- C:\WINDOWS\SysWOW64\ExSMime.dll 2016-05-14 08:33:35 242708810A22D373904539EDF39FFAD1 196608 ----a-w- C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-05-14 08:33:35 1AEBF2230422716D8CE1BEBCBAE961D3 48128 ----a-w- C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-05-14 08:33:34 E46FCEC3EAC209AFCDB2825386E51423 415232 ----a-w- C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-05-14 08:33:34 BC5D8155DBA7DC0E4F92430701C19901 161280 ----a-w- C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-05-14 08:33:34 897906025BD3616BF9C30A3979A73DEE 712704 ----a-w- C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-05-14 08:33:34 7D51637A2E604113F1A4E96FF3F2727C 51128 ----a-w- C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-05-14 08:33:34 70128BC69D515F2D38577D2438861424 133632 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-05-14 08:33:34 6D062C6E2C47B3DCDE8F4C3FDB634DEE 83456 ----a-w- C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-05-14 08:33:34 408AF8141C4A44BC120F4204F8F79A75 1944576 ----a-w- C:\WINDOWS\SysWOW64\InputService.dll 2016-05-14 08:33:34 395AC69CCD9E2D590775AA6ADD2AE1D2 649728 ----a-w- C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-05-14 08:33:34 2823A28AB08EE9DCE85436C700799D66 80384 ----a-w- C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2016-05-14 08:33:34 265DB46FE368D8F701A74976D3823ADC 986976 ----a-w- C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-05-14 08:33:31 EAF904785CA7849C66F6DC2EF0A0E0E7 22528 ----a-w- C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2016-05-14 08:33:31 E793B893135F3B6942B6230D45E27610 61440 ----a-w- C:\WINDOWS\SysWOW64\samlib.dll 2016-05-14 08:33:31 D57F7D9FB771CA0B434E975F76413430 1072128 ----a-w- C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-05-14 08:33:31 D28C3C4AAB51D00FD6EFA07F6DCC1CBA 1862008 ----a-w- C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-05-14 08:33:31 CA2EA5401563387162E61444AE15AF59 53248 ----a-w- C:\WINDOWS\SysWOW64\profext.dll 2016-05-14 08:33:31 C9B1E5A2FE0C7BF75B8B751311331EB4 2604032 ----a-w- C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-05-14 08:33:31 C122D52ED9662F09EC2650B010544468 73872 ----a-w- C:\WINDOWS\SysWOW64\srvcli.dll 2016-05-14 08:33:31 BF769A5BEA8E50F12264746D30D57C6F 52736 ----a-w- C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2016-05-14 08:33:31 B65D241B81A010B6A78CCEEA900CCFC0 56320 ----a-w- C:\WINDOWS\SysWOW64\wkscli.dll 2016-05-14 08:33:31 AC42505CBCEE5825BB2695C34E43B1D0 184832 ----a-w- C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-05-14 08:33:31 7C7CC816CEEB07022EBCC6B779B16E1D 521728 ----a-w- C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2016-05-14 08:33:31 7C557ABB26C2B2D930AA005FF6A8C025 592384 ----a-w- C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-05-14 08:33:31 6DFDAD2B0EA3385069276DF547F4CAC8 2186864 ----a-w- C:\WINDOWS\SysWOW64\d3d11.dll 2016-05-14 08:33:31 6DA0B412C0DD9DDB5382527488A5AD2E 237056 ----a-w- C:\WINDOWS\SysWOW64\thumbcache.dll 2016-05-14 08:33:31 6A7ACABAE92C837F5C1330188EAE36AE 535080 ----a-w- C:\WINDOWS\SysWOW64\dnsapi.dll 2016-05-14 08:33:31 5E52C817BCF919CF11CD523A2EC4A456 638464 ----a-w- C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-05-14 08:33:31 402A33FCE08200518FB0012A6BF2E966 2722816 ----a-w- C:\WINDOWS\SysWOW64\esent.dll 2016-05-14 08:33:31 3EB91A44E6BCD05CA257E113FCA1DA0C 43520 ----a-w- C:\WINDOWS\SysWOW64\browcli.dll 2016-05-14 08:33:31 3ABE2040F4F9BDDD008EC5D4713D5ABE 294752 ----a-w- C:\WINDOWS\SysWOW64\msv1_0.dll 2016-05-14 08:33:31 3249EA75874EE3DD3FCBA141656DF210 713728 ----a-w- C:\WINDOWS\SysWOW64\netlogon.dll 2016-05-14 08:33:31 2E947792E9B1C738E33FD5794B1650F9 30208 ----a-w- C:\WINDOWS\SysWOW64\tbauth.dll 2016-05-14 08:33:31 15E75D27F0C67A7A21D5A514601F0E5A 135168 ----a-w- C:\WINDOWS\SysWOW64\AppxSip.dll 2016-05-14 08:33:31 053E2D136DB8A4743E4C40D5D979834B 200704 ----a-w- C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-05-14 08:33:30 FD639F1372389D7C5990663D6A100CFE 541304 ----a-w- C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-05-14 08:33:30 FC90756CB632C0E4AC0D6A60AF2DF9AD 585216 ----a-w- C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-05-14 08:33:30 EBD26D676238C0B3938AFF925043576F 394752 ----a-w- C:\WINDOWS\SysWOW64\werui.dll 2016-05-14 08:33:30 E07F85C08C025B08F25150E60CB69B44 37376 ----a-w- C:\WINDOWS\SysWOW64\atmlib.dll 2016-05-14 08:33:30 D5BF10F0C309C82820813A7190CE1F5F 65536 ----a-w- C:\WINDOWS\SysWOW64\wininetlui.dll 2016-05-14 08:33:30 D1600085065675F98F41A01DCD03AA6E 854528 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2016-05-14 08:33:30 CC68ABFB0AA40F62E7BD740101A0C92B 1117184 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-05-14 08:33:30 CC2F923F02D8EB36D0C442CE709B6CD9 1139712 ----a-w- C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-05-14 08:33:30 CA3C908B5C24293F1F1FB89301D63F16 1588224 ----a-w- C:\WINDOWS\SysWOW64\msxml3.dll 2016-05-14 08:33:30 C9D7861D1C984E1997A3778A97DD1AF9 162816 ----a-w- C:\WINDOWS\SysWOW64\MTF.dll 2016-05-14 08:33:30 C57E960CD2C7F64AE0295DF0423FE071 1444352 ----a-w- C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-05-14 08:33:30 C23A52581FEA6CD49A49160BFA794BF7 6952088 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-05-14 08:33:30 B8AC85F66A12455FB3F2FDB916B1C679 498176 ----a-w- C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-05-14 08:33:30 B74C5FA6221607F864C62090F74FDB80 799744 ----a-w- C:\WINDOWS\SysWOW64\SRH.dll 2016-05-14 08:33:30 B4102814D9B1D1FC6C39869D7F224E12 303104 ----a-w- C:\WINDOWS\SysWOW64\atmfd.dll 2016-05-14 08:33:30 ACE2B02BA07DF7F13F59D07F7A38AA18 161792 ----a-w- C:\WINDOWS\SysWOW64\msorcl32.dll 2016-05-14 08:33:30 A8EF9AEDACF24908E12E910BF3977DC9 703840 ----a-w- C:\WINDOWS\SysWOW64\WWAHost.exe 2016-05-14 08:33:30 9B60985A87BA2FED9F57DA30F191098E 315904 ----a-w- C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-05-14 08:33:30 91ED19257EAA98C1C95A7E5F0FF07FF0 10240 ----a-w- C:\WINDOWS\SysWOW64\oleacchooks.dll 2016-05-14 08:33:30 856AD15FD2D187EA8435564A135C85C0 228352 ----a-w- C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-05-14 08:33:30 7F0A9630C78E3783680CC9620C4E09C0 6740992 ----a-w- C:\WINDOWS\SysWOW64\mstscax.dll 2016-05-14 08:33:30 7A2A3BAAA05C8124D95B2915E904F900 141664 ----a-w- C:\WINDOWS\SysWOW64\wermgr.exe 2016-05-14 08:33:30 4D2E3D6BC01E7A5E9C6F9AFDBFAF98BB 220064 ----a-w- C:\WINDOWS\SysWOW64\sqmapi.dll 2016-05-14 08:33:30 49A21B514FC10B2D55499D58DC78E862 45568 ----a-w- C:\WINDOWS\SysWOW64\jsproxy.dll 2016-05-14 08:33:30 4135F625D8F20D76FB29F86FE7A4CC48 93696 ----a-w- C:\WINDOWS\SysWOW64\fontsub.dll 2016-05-14 08:33:30 38EE252AD45EB7D6834F718B9487D3F9 538736 ----a-w- C:\WINDOWS\SysWOW64\wer.dll 2016-05-14 08:33:30 2C0BBF7FC5526D7285BEAD239895C473 682496 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2016-05-14 08:33:30 2BFF4D19D7FC686C150879A2FD5BAE77 2229760 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2016-05-14 08:33:30 1A341701906986F1865766C6849269FC 323072 ----a-w- C:\WINDOWS\SysWOW64\oleacc.dll 2016-05-14 08:26:03 6F2CA3BDD1C78C465BC0C1E5DDA15B28 2629632 ----a-w- C:\WINDOWS\SysWOW64\NlsLexicons0009.dll 2016-05-14 08:26:03 14129011499850E46153AB0E6C325F87 4847616 ----a-w- C:\WINDOWS\SysWOW64\NlsData0009.dll 2016-05-14 08:12:06 F432E0E5B0958F4982D40EB622FBD7FC 35480 ----a-w- C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-05-14 08:12:06 BF9CAA33ADD4C21C118148B5CFC5494B 778936 ----a-w- C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-05-14 08:12:06 6F391E9286733CC6B34FC0FAB23B8DF3 103120 ----a-w- C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-05-14 07:47:14 6587CEC591522F2D0EFE091B59ACCBCC 77832 ----a-w- C:\WINDOWS\SysWOW64\OpenCL.DLL 2016-05-05 08:13:21 6587CEC591522F2D0EFE091B59ACCBCC 77832 ----a-w- C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll 2016-05-05 08:13:20 B722809B4641DEE6C74913540203222F 48136 ----a-w- C:\WINDOWS\SysWOW64\igfxexps32.dll 2016-05-05 08:13:20 A669346D8453603DA003048FF500F7F0 204840 ----a-w- C:\WINDOWS\SysWOW64\iglhcp32.dll 2016-05-05 08:13:20 A28D6FA203CE094BDE7ED8CEC6079E42 299488 ----a-w- C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe 2016-05-05 08:13:20 9A3EF9453095648E90559DCC74E67096 304136 ----a-w- C:\WINDOWS\SysWOW64\IntelOpenCL32.dll 2016-05-05 08:13:20 6C4A4FAA3B539DD9DD484FB8BC9BE8B2 1170640 ----a-w- C:\WINDOWS\SysWOW64\iglhsip32.dll 2016-05-05 08:13:19 D1F1358122D3444E23DFBF64C3EC15CD 1775624 ----a-w- C:\WINDOWS\SysWOW64\igfxcmjit32.dll 2016-05-05 08:13:19 9EA7A1F172FC600BB7CCDC5B31335DE1 172552 ----a-w- C:\WINDOWS\SysWOW64\igfx11cmrt32.dll 2016-05-05 08:13:19 81D97A36C5AE235951AF1A8F4DA627ED 179600 ----a-w- C:\WINDOWS\SysWOW64\igfxcmrt32.dll 2016-05-05 08:13:15 E67C9E8DEF48F8470978584110720A20 3726232 ----a-w- C:\WINDOWS\SysWOW64\igdusc32.dll 2016-05-05 08:13:13 E2D6A8E977FEC4FF644C654C63960800 10675896 ----a-w- C:\WINDOWS\SysWOW64\igdumdim32.dll 2016-05-05 08:13:12 C05E4F3E4DF7DAAE6C66EDD8AE34B8AA 1803784 ----a-w- C:\WINDOWS\SysWOW64\igdrcl32.dll 2016-05-05 08:13:12 5CC80F7B49572FB4AAFB14291886B10D 390928 ----a-w- C:\WINDOWS\SysWOW64\igdmd32.dll 2016-05-05 08:13:11 EFC90543024C0F60981F0D313739CA94 200200 ----a-w- C:\WINDOWS\SysWOW64\igdde32.dll 2016-05-05 08:13:11 E19A3AA5AA3A5BBE4A2FA912B52A3789 161288 ----a-w- C:\WINDOWS\SysWOW64\igdail32.dll 2016-05-05 08:13:11 8ADD5AEC043A697722DC3A19BA977361 338952 ----a-w- C:\WINDOWS\SysWOW64\igdbcl32.dll 2016-05-05 08:13:11 1BA124AC8854B5035354760B4FD4C3A4 17854984 ----a-w- C:\WINDOWS\SysWOW64\igdfcl32.dll 2016-05-05 08:13:08 0DB0220856FA31E9AA34245A36F4A414 12007936 ----a-w- C:\WINDOWS\SysWOW64\igd10iumd32.dll 2016-05-05 08:13:07 08CE3D776E06980A44A3162FA51C6CB4 6518792 ----a-w- C:\WINDOWS\SysWOW64\ig7icd32.dll 2016-05-05 08:12:44 208F948C25CBEE7D9E395A5B31238764 591640 ----a-w- C:\WINDOWS\SysWOW64\MBTHX32.dll 2016-05-05 08:12:43 B81E11533A94ACB118CF0E09099E5BC2 784312 ----a-w- C:\WINDOWS\SysWOW64\MBAPO32.dll 2016-05-05 08:12:42 609C0C35A038430CACCC1C414FA258AF 1764432 ----a-w- C:\WINDOWS\SysWOW64\MBAPO232.dll 2016-05-05 08:12:36 3454EBB2B716D769D752D02690D50B00 12126952 ----a-w- C:\WINDOWS\SysWOW64\MaxxVoiceAPO30.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2016-05-14 16:17:02 FA05A804701A1BF900577A0F7C14B59E 24604672 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2016-05-14 16:16:56 A1144CA95D4C30449331D3DF39F295F9 970752 ----a-w- C:\WINDOWS\Sysnative\kerberos.dll 2016-05-14 16:16:55 3602BE2186C15362DF2B5C489AC1B1D1 22379008 ----a-w- C:\WINDOWS\Sysnative\edgehtml.dll 2016-05-14 16:16:52 D2EF3FDF915BBA7C9832FA890DD4D85A 16984576 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2016-05-14 16:16:43 0BECECA1B6DA7B022FC9502D22B9E9B3 22561256 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2016-05-14 16:16:41 75A22EF6AC813D4FE63E30C3C292F871 11545088 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2016-05-14 16:16:40 24F2141493C1A2F6FDEC8C3FA5A95CDE 6605504 ----a-w- C:\WINDOWS\Sysnative\windows.storage.dll 2016-05-14 16:16:39 614EF7EFFE6896791CC8E4D045F37579 7977472 ----a-w- C:\WINDOWS\Sysnative\mos.dll 2016-05-14 16:16:36 5EED294E19B8293E4F0845CED31489BA 13383168 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2016-05-14 16:16:35 62D33462C8781DA354519488A571A9AD 7832576 ----a-w- C:\WINDOWS\Sysnative\Chakra.dll 2016-05-14 16:16:28 03DE6DE0019FFC0DE60759A893BD8B3F 1819208 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2016-05-14 16:16:27 89FE1A65D15DE2AA9CBF86AA6A731557 7474528 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2016-05-14 16:16:25 F6718A9F2B5BFA1A42618F63BC890713 5502976 ----a-w- C:\WINDOWS\Sysnative\d2d1.dll 2016-05-14 16:16:22 7E500CCA3EC66C419F2E4BBDE8617647 4894208 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2016-05-14 16:16:21 8F225A78F60DB08D4691C1C27CF644F2 6974464 ----a-w- C:\WINDOWS\Sysnative\Windows.Data.Pdf.dll 2016-05-14 16:16:19 1B8A57EC632457E909A06957CB216806 7200256 ----a-w- C:\WINDOWS\Sysnative\BingMaps.dll 2016-05-14 16:16:18 E4B5C9FEF4C8978CF75B584188868AF8 2582016 ----a-w- C:\WINDOWS\Sysnative\MFMediaEngine.dll 2016-05-14 16:16:16 3F943A9A21814C6A394FBB8F1D4E622D 1401024 ----a-w- C:\WINDOWS\Sysnative\appraiser.dll 2016-05-14 16:16:16 2A643E48326E427C6A43005EC29F314D 2444288 ----a-w- C:\WINDOWS\Sysnative\twinui.appcore.dll 2016-05-14 16:16:11 8A88DBA247BFF23BD284C2189F41FDA5 2280960 ----a-w- C:\WINDOWS\Sysnative\wuaueng.dll 2016-05-14 16:16:08 087FBBC026DCC0F693E91079B9901B7E 2166784 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentServer.dll 2016-05-14 16:16:07 1A944DC7982279E73C4181DD5D50E021 3591168 ----a-w- C:\WINDOWS\Sysnative\win32kfull.sys 2016-05-14 16:16:07 19D88BF131158F4286294C372B4410B3 1946112 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2016-05-14 16:16:06 C57CBD3D0A4B832F3DC18250FC02C3DE 46784 ----a-w- C:\WINDOWS\Sysnative\CompatTelRunner.exe 2016-05-14 16:16:06 AB17E08B47FECDAF0E1349797A6C41A4 1184960 ----a-w- C:\WINDOWS\Sysnative\aeinv.dll 2016-05-14 16:16:06 5BDA53E18911DEAB35F03AA1C3213A78 3673424 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2016-05-14 16:16:05 F172E5709824756634091047826E7A9F 1319424 ----a-w- C:\WINDOWS\Sysnative\wifinetworkmanager.dll 2016-05-14 16:16:05 082DC7D3704A17FF022D70C577785254 2066432 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentExtensions.dll 2016-05-14 16:16:04 F83E3BAEF5931399978A31753B22D0BE 713920 ----a-w- C:\WINDOWS\Sysnative\generaltel.dll 2016-05-14 16:16:04 7539A3BF1DC12C53D6DDE078BE888951 190144 ----a-w- C:\WINDOWS\Sysnative\DeviceCensus.exe 2016-05-14 16:16:03 0C8655AAC4EA262F62B00DCDA4639819 2598912 ----a-w- C:\WINDOWS\Sysnative\NetworkMobileSettings.dll 2016-05-14 16:16:02 FD60606E2E7F74D7104A5DA1210D38E6 460800 ----a-w- C:\WINDOWS\Sysnative\MapConfiguration.dll 2016-05-14 16:16:02 78A9EBBAC348ACD9AF5B72ECF90944A7 853504 ----a-w- C:\WINDOWS\Sysnative\MapsStore.dll 2016-05-14 16:16:01 DA5108028A00B865BBECB1980EB05EB8 1997328 ----a-w- C:\WINDOWS\Sysnative\KernelBase.dll 2016-05-14 16:16:00 C1D51970E74AB5FFE46FE624BFE900C6 1731072 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2016-05-14 16:16:00 6D8365722FBB3E58FC2B10FEA00BE840 514752 ----a-w- C:\WINDOWS\Sysnative\devinv.dll 2016-05-14 16:16:00 5FD7FDCE260C2ADE6CFFBC141657E8C0 939520 ----a-w- C:\WINDOWS\Sysnative\MapControlCore.dll 2016-05-14 16:16:00 54D6AEA7933377556BBBEC5F45539922 673280 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.dll 2016-05-14 16:15:59 F75A1710366B5C6B02D3C061DAA4C578 529920 ----a-w- C:\WINDOWS\Sysnative\LogonController.dll 2016-05-14 16:15:59 A8ECAFE7C58ABABA7CB1C377B7A7E309 984576 ----a-w- C:\WINDOWS\Sysnative\SettingSyncCore.dll 2016-05-14 16:15:59 0BF8D8C7EC9FB15D6480A12101E88B71 606720 ----a-w- C:\WINDOWS\Sysnative\wcmsvc.dll 2016-05-14 16:15:59 090AAD83736B45769D2688E3BC1AB80A 1092464 ----a-w- C:\WINDOWS\Sysnative\mfplat.dll 2016-05-14 16:15:58 DBD087566420D945303C278A4FD90E60 440320 ----a-w- C:\WINDOWS\Sysnative\CredProvDataModel.dll 2016-05-14 16:15:58 5C156EC4E44E30331BCC865A3B61D839 585728 ----a-w- C:\WINDOWS\Sysnative\winlogon.exe 2016-05-14 16:15:58 00A8CD22CCF7FA34501038C3C35186BD 498960 ----a-w- C:\WINDOWS\Sysnative\MFCaptureEngine.dll 2016-05-14 16:15:57 EBE067467C144B097CEF5F609F6ABF43 865792 ----a-w- C:\WINDOWS\Sysnative\AzureSettingSyncProvider.dll 2016-05-14 16:15:57 D5D0D1345DEAC9D08A6A5B146A29ADBE 1390080 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Shell.dll 2016-05-14 16:15:57 79BF53E386256057C30EF606DC3CFDFB 870400 ----a-w- C:\WINDOWS\Sysnative\modernexecserver.dll 2016-05-14 16:15:56 86BE19C6A177AEB93302EA5C4FBE2D11 754664 ----a-w- C:\WINDOWS\Sysnative\CoreMessaging.dll 2016-05-14 16:15:56 2453622FF2CCB1BA1DFA588207E9C7A4 294592 ----a-w- C:\WINDOWS\Sysnative\invagent.dll 2016-05-14 16:15:56 0676A6C9A6EECA48E14B9AE13B0E3508 1387520 ----a-w- C:\WINDOWS\Sysnative\win32kbase.sys 2016-05-14 16:15:55 ECF260CA5837CE3174AAAE450C1888C6 605184 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2016-05-14 16:15:55 85A676350B7A349B1DFB47654FBF8C71 804352 ----a-w- C:\WINDOWS\Sysnative\jscript.dll 2016-05-14 16:15:55 191A50C760243B5B8E08E0A1CA0B1F7C 821760 ----a-w- C:\WINDOWS\Sysnative\TokenBroker.dll 2016-05-14 16:15:54 6EA247B3631FE0181583566B9D828B22 413536 ----a-w- C:\WINDOWS\Sysnative\wifitask.exe 2016-05-14 16:15:54 5DA95027DF2317174E8C39B4A8D1FCD8 1213440 ----a-w- C:\WINDOWS\Sysnative\wwansvc.dll 2016-05-14 16:15:53 A5C14F8FE076B41778C56F2414F5D246 650304 ----a-w- C:\WINDOWS\Sysnative\dxgi.dll 2016-05-14 16:15:52 ACC6B16066D073AA0E20B044BFEF9CD1 471552 ----a-w- C:\WINDOWS\Sysnative\NetSetupShim.dll 2016-05-14 16:15:52 82BC3D304654F8EBEFABDDC2AD70AFE3 497152 ----a-w- C:\WINDOWS\Sysnative\tileobjserver.dll 2016-05-14 16:15:51 99DDB4A100F6013E6B6B269880F0C936 988160 ----a-w- C:\WINDOWS\Sysnative\NMAA.dll 2016-05-14 16:15:51 93C28A95FC5CA7F420343AC9693E05E6 1594920 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2016-05-14 16:15:51 70C5D325E1BBD9C771542375F9DE5711 303216 ----a-w- C:\WINDOWS\Sysnative\LockAppHost.exe 2016-05-14 16:15:50 F5F7CE3E32536F1A37FB3972F27A814F 1399224 ----a-w- C:\WINDOWS\Sysnative\user32.dll 2016-05-14 16:15:50 52C95CFC459242ECBD8A557A197F6FF6 725776 ----a-w- C:\WINDOWS\Sysnative\SHCore.dll 2016-05-14 16:15:50 3CFA0EA6ABC10436D998F7958912387C 1848072 ----a-w- C:\WINDOWS\Sysnative\crypt32.dll 2016-05-14 16:15:49 A29004CC4FE3A06B5C71969F6411FD41 287232 ----a-w- C:\WINDOWS\Sysnative\provhandlers.dll 2016-05-14 16:15:49 810B7BA7636930BD6A21A93296FBCA51 292864 ----a-w- C:\WINDOWS\Sysnative\provengine.dll 2016-05-14 16:15:49 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\WINDOWS\Sysnative\aepic.dll 2016-05-14 16:15:48 F7DD01F464ED3ADB8477CD5FD1DE6CF4 356864 ----a-w- C:\WINDOWS\Sysnative\ActivationManager.dll 2016-05-14 16:15:48 ABF13620065E258771320165E0759761 1776768 ----a-w- C:\WINDOWS\Sysnative\WindowsCodecs.dll 2016-05-14 16:15:48 82C4028BABC9BADCD89600F5084E4543 479232 ----a-w- C:\WINDOWS\Sysnative\schannel.dll 2016-05-14 16:15:47 F1CC271FBAD94FBD3D69BC6BE443C33B 1056256 ----a-w- C:\WINDOWS\Sysnative\JpMapControl.dll 2016-05-14 16:15:47 F00A2E895B61858DBB3FE870495E37FA 210432 ----a-w- C:\WINDOWS\Sysnative\wcmcsp.dll 2016-05-14 16:15:47 7F0318ECC1E6E566D02F218DD59CEA84 484352 ----a-w- C:\WINDOWS\Sysnative\DataSenseHandlers.dll 2016-05-14 16:15:46 C49BB15138D9A7AE2901692CA30E11D1 181248 ----a-w- C:\WINDOWS\Sysnative\shacct.dll 2016-05-14 16:15:46 50E41D3203DA334DBBD2B3B6C7EA64CD 988672 ----a-w- C:\WINDOWS\Sysnative\SharedStartModel.dll 2016-05-14 16:15:46 489EDA0C433F5B0AA54033F523F2C80E 269824 ----a-w- C:\WINDOWS\Sysnative\moshostcore.dll 2016-05-14 16:15:46 1997A751EF0FB9889E6642428DC4CAB2 1161120 ----a-w- C:\WINDOWS\Sysnative\rpcrt4.dll 2016-05-14 16:15:45 8B4111E094EDDBED23EFA1FF8B5F314A 613376 ----a-w- C:\WINDOWS\Sysnative\SettingSync.dll 2016-05-14 16:15:45 5470B002C5E5D4DC8C4C330EAE8A685D 619296 ----a-w- C:\WINDOWS\Sysnative\d3d10level9.dll 2016-05-14 16:15:44 FE42F8A07885E518ED1E846C93E4B78C 617984 ----a-w- C:\WINDOWS\Sysnative\StorSvc.dll 2016-05-14 16:15:44 F1DF87BCF5429D48484E78FB1933326B 848896 ----a-w- C:\WINDOWS\Sysnative\wuapi.dll 2016-05-14 16:15:44 A55AB67676D0E90C279E36AF78EECCFA 515072 ----a-w- C:\WINDOWS\Sysnative\OneDriveSettingSyncProvider.dll 2016-05-14 16:15:44 734B3E9E4DA94DD093C6759CA0C2AA1E 4775424 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2016-05-14 16:15:44 1D7F891D7ADCE1A6824FCB57D6768E14 689152 ----a-w- C:\WINDOWS\Sysnative\ieproxy.dll 2016-05-14 16:15:43 56B24B359838BE86B013C2CFD38BDFC4 72704 ----a-w- C:\WINDOWS\Sysnative\moshost.dll 2016-05-14 16:15:43 33C215D1F36A184FB0C0F83ECBE12B5B 351232 ----a-w- C:\WINDOWS\Sysnative\NgcCtnr.dll 2016-05-14 16:15:42 C1C81AAF533552B3C4D9F11A5FF97700 291360 ----a-w- C:\WINDOWS\Sysnative\wininit.exe 2016-05-14 16:15:42 0B28F2ACE5103586D322AD98FAA01309 870912 ----a-w- C:\WINDOWS\Sysnative\MPSSVC.dll 2016-05-14 16:15:41 EED30CDEAB6E4B45CBF1BD5298952049 550656 ----a-w- C:\WINDOWS\Sysnative\directmanipulation.dll 2016-05-14 16:15:41 CFF943806EBAD5CFAC26FD3DF304E79F 1073152 ----a-w- C:\WINDOWS\Sysnative\RDXService.dll 2016-05-14 16:15:41 3C52661045548D78EC0EB76495CB978F 66560 ----a-w- C:\WINDOWS\Sysnative\MosHostClient.dll 2016-05-14 16:15:41 0CFE0F27EC828D9659FD8BF3A529F7B1 166400 ----a-w- C:\WINDOWS\Sysnative\SubscriptionMgr.dll 2016-05-14 16:15:40 C991F0E48492D1550279F901AB2332B0 390496 ----a-w- C:\WINDOWS\Sysnative\wlanapi.dll 2016-05-14 16:15:40 7AAA9916AA10F4B0E9743798A5BA6549 649216 ----a-w- C:\WINDOWS\Sysnative\ngcsvc.dll 2016-05-14 16:15:40 679DD4763AA8028B2F26651D3D02A2E1 582656 ----a-w- C:\WINDOWS\Sysnative\ngccredprov.dll 2016-05-14 16:15:40 37E893F5A0BB0DCF89D8464F4D5E0C3D 217440 ----a-w- C:\WINDOWS\Sysnative\AppxAllUserStore.dll 2016-05-14 16:15:40 242DA5F2A6D9C5DFE2F99127BD2077A4 92352 ----a-w- C:\WINDOWS\Sysnative\acmigration.dll 2016-05-14 16:15:39 0FB83658FBB2C5A18AB98C5C94DB9FAF 289792 ----a-w- C:\WINDOWS\Sysnative\NgcCtnrSvc.dll 2016-05-14 16:15:38 B9B902C12D6872DE9135B0A7C1ACA5A8 565600 ----a-w- C:\WINDOWS\Sysnative\SettingSyncHost.exe 2016-05-14 16:15:38 B28EA19205448B34303D006D50E9E65A 74752 ----a-w- C:\WINDOWS\Sysnative\MosStorage.dll 2016-05-14 16:15:37 B985F4CC9D63594D8D3DCADAC07F257E 130560 ----a-w- C:\WINDOWS\Sysnative\CloudDomainJoinDataModelServer.dll 2016-05-14 16:15:37 A1BFD44C6343BDF582828EAB6B4CBDE5 630784 ----a-w- C:\WINDOWS\Sysnative\PhoneProviders.dll 2016-05-14 16:15:37 5907323899BCEFA32BF6B002F2493C09 76288 ----a-w- C:\WINDOWS\Sysnative\ngcpopkeysrv.dll 2016-05-14 16:15:36 E650C69B5CA9B786AD91E3E7F962A0EE 848896 ----a-w- C:\WINDOWS\Sysnative\samsrv.dll 2016-05-14 16:15:36 72229D3836EA9697F5E13AAEA85F8688 204048 ----a-w- C:\WINDOWS\Sysnative\rsaenh.dll 2016-05-14 16:15:35 E706406D61508D207F6B41CA4AD30891 127488 ----a-w- C:\WINDOWS\Sysnative\VEDataLayerHelpers.dll 2016-05-14 16:15:35 3655A59A1E16307F2F6475AC037C1EE4 87040 ----a-w- C:\WINDOWS\Sysnative\MDMAppInstaller.exe 2016-05-14 16:15:34 981F6C7FB2338CC7889BA4D37C1A9DCE 69632 ----a-w- C:\WINDOWS\Sysnative\EnterpriseDesktopAppMgmtCSP.dll 2016-05-14 16:15:32 EDF39F56DDF4116DCC8779A65EF8D6C5 58208 ----a-w- C:\WINDOWS\Sysnative\dwminit.dll 2016-05-14 16:15:32 7CEC266216126BC9A0E1072E1A7E5702 279040 ----a-w- C:\WINDOWS\Sysnative\ListSvc.dll 2016-05-14 16:15:31 45FA01F8B7971ACB65202038E34D04A3 86528 ----a-w- C:\WINDOWS\Sysnative\wpdbusenum.dll 2016-05-14 16:15:30 D906EFF6ADB6704071C903E62867AC23 696672 ----a-w- C:\WINDOWS\Sysnative\NetSetupEngine.dll 2016-05-14 16:15:30 C1FCA0AED814F1E814700833EF8E0616 179712 ----a-w- C:\WINDOWS\Sysnative\BrowserSettingSync.dll 2016-05-14 16:15:30 4766A523BD8265F3082662A49C382680 26408 ----a-w- C:\WINDOWS\Sysnative\wuauclt.exe 2016-05-14 16:15:29 5E903356FCDC2C7011E5341A1C2D48E9 192000 ----a-w- C:\WINDOWS\Sysnative\provisioningcsp.dll 2016-05-14 16:15:28 DCC42EF91745E4AB13602B9A4D86DDC4 115040 ----a-w- C:\WINDOWS\Sysnative\NetSetupApi.dll 2016-05-14 16:15:28 C417C35D0B714320708A1C18673ACE6C 104448 ----a-w- C:\WINDOWS\Sysnative\BluetoothApis.dll 2016-05-14 16:15:28 5DBA65D48CB7B17E241BB7430745C2E0 59392 ----a-w- C:\WINDOWS\Sysnative\hmkd.dll 2016-05-14 16:15:27 D0F9C288251907FD44B96837DBDF0A50 320000 ----a-w- C:\WINDOWS\Sysnative\cryptngc.dll 2016-05-14 16:15:27 A2953084546B1F46B5CCC7FC57A72C1B 314880 ----a-w- C:\WINDOWS\Sysnative\RDXTaskFactory.dll 2016-05-14 16:15:26 90A52EBAC043CFCA92E5F3DEAD4BBB4C 48128 ----a-w- C:\WINDOWS\Sysnative\wups.dll 2016-05-14 16:15:26 0BFEB4862FC2422DAC67EE95C278ECE0 111616 ----a-w- C:\WINDOWS\Sysnative\updatepolicy.dll 2016-05-14 16:15:25 33931A5F8E8B4446C547B020409D66C4 436736 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentClient.dll 2016-05-14 16:15:20 ED309332DA910BE791F40F09F6FC50B5 38400 ----a-w- C:\WINDOWS\Sysnative\ByteCodeGenerator.exe 2016-05-14 16:15:20 AB1738C51C1C1F41A885467E7BB0D37B 285696 ----a-w- C:\WINDOWS\Sysnative\VEEventDispatcher.dll 2016-05-14 16:15:19 315CFB6974B5111E3E62E9A512C92B25 151040 ----a-w- C:\WINDOWS\Sysnative\VEStoreEventHandlers.dll 2016-05-14 16:15:19 09098FB07B47765865492C53B66E29E5 764928 ----a-w- C:\WINDOWS\Sysnative\Chakradiag.dll 2016-05-14 16:15:18 7DDC2D8133CC1CA646134CC450C02C15 28672 ----a-w- C:\WINDOWS\Sysnative\mapsupdatetask.dll 2016-05-14 16:15:17 FE3A72E9BC5515509517D9BF41144252 414720 ----a-w- C:\WINDOWS\Sysnative\bcastdvr.exe 2016-05-14 16:15:17 DE1C434F0F89C37687D34FB8A8E77B46 120320 ----a-w- C:\WINDOWS\Sysnative\MapsBtSvc.dll 2016-05-14 16:15:17 C3534256AF526A16AADBA335AA99D58F 63488 ----a-w- C:\WINDOWS\Sysnative\wshbth.dll 2016-05-14 16:15:17 77DE2FC672F423C2DFCF2A12DB74197C 89088 ----a-w- C:\WINDOWS\Sysnative\MapsCSP.dll 2016-05-14 16:15:16 1AF7E0BA5D1AEA3DEF1CF05B070803FA 89600 ----a-w- C:\WINDOWS\Sysnative\NFCProvisioningPlugin.dll 2016-05-14 16:15:15 BD3F339FE542C30BB4A88F34A597728C 134656 ----a-w- C:\WINDOWS\Sysnative\wificonnapi.dll 2016-05-14 16:15:14 9C6EE1DE9CF7B77FF550A737816EB6DB 207360 ----a-w- C:\WINDOWS\Sysnative\NetSetupSvc.dll 2016-05-14 16:15:13 F70CB98E5669D44CBFA6F3EBF534977F 86528 ----a-w- C:\WINDOWS\Sysnative\AppCapture.dll 2016-05-14 16:15:10 9B034D049D1C6EC9BED55D2F27D86ED9 2186 ----a-w- C:\WINDOWS\Sysnative\AppxProvisioning.xml 2016-05-14 08:42:03 79422D76818752C6D935A97C8FFC4EEA 44147 ----a-w- C:\WINDOWS\Sysnative\license.rtf 2016-05-14 08:34:02 C3F15E167CB84E2E6027AF17D49D5904 372224 ----a-w- C:\WINDOWS\Sysnative\MDEServer.exe 2016-05-14 08:34:02 BC767AD01E4DAFD08C21D5D07CC290C9 567808 ----a-w- C:\WINDOWS\Sysnative\MCRecvSrc.dll 2016-05-14 08:34:02 6E76BB89EED6C2BD7B1E7B5F9A1C41F0 320000 ----a-w- C:\WINDOWS\Sysnative\MSFlacDecoder.dll 2016-05-14 08:34:01 FEBBA212353E4FA90C6164AA970B772F 536256 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2016-05-14 08:34:01 D79FFE2219AE3BA3B871BA2D39B16519 1152328 ----a-w- C:\WINDOWS\Sysnative\mfasfsrcsnk.dll 2016-05-14 08:34:01 C9BFE1D6420BFADB249162039C321F63 1131520 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Audio.dll 2016-05-14 08:34:01 BD70B866034C1366D74CCBB5CA97395E 2544264 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2016-05-14 08:34:01 AF13258A6E8FD57CE0B9C6BEDCDF80CB 144896 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Devices.dll 2016-05-14 08:34:01 92F74BF86088520654BD5636A69E37F1 848168 ----a-w- C:\WINDOWS\Sysnative\mfsvr.dll 2016-05-14 08:34:01 834D1648124F0F2729462BF79DB0C2CD 369912 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2016-05-14 08:34:01 751F5B6AF16546162E06211AF1FC2979 794888 ----a-w- C:\WINDOWS\Sysnative\mfds.dll 2016-05-14 08:34:01 669F733F85FEBE6F7438C66CBF7FD3FD 1062480 ----a-w- C:\WINDOWS\Sysnative\mfmp4srcsnk.dll 2016-05-14 08:34:01 48E90F12346EE70764CEE435826ABD31 493568 ----a-w- C:\WINDOWS\Sysnative\mfmkvsrcsnk.dll 2016-05-14 08:34:01 468D29ECE0AD7700B790A20FA2765313 408120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2016-05-14 08:34:01 42BF7FA295F453618104B5A50BEE105B 275456 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2016-05-14 08:34:01 350CFCC870E30BEE151F3DFB83BD0178 1017032 ----a-w- C:\WINDOWS\Sysnative\mfsrcsnk.dll 2016-05-14 08:34:01 32F3BA2C4849ED727508C021F999E147 3428864 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.dll 2016-05-14 08:34:01 2A2C0983B6FE62F02E7183335B1F5C20 1054208 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2016-05-14 08:34:01 28343B7C30E6AF073B02288EB579D984 476728 ----a-w- C:\WINDOWS\Sysnative\msvproc.dll 2016-05-14 08:34:01 218CEC10714AF029BF4D8BCE600AD1DA 819648 ----a-w- C:\WINDOWS\Sysnative\mfmpeg2srcsnk.dll 2016-05-14 08:34:00 47323DE2A684895004CE63EC66FB4AB4 401408 ----a-w- C:\WINDOWS\Sysnative\sharemediacpl.dll 2016-05-14 08:33:59 FDBDA93BA9CD3B78060705B41BFCF92D 288256 ----a-w- C:\WINDOWS\Sysnative\fveui.dll 2016-05-14 08:33:59 F72F137EEFF89D0B5A2FB8867B4ACEED 402432 ----a-w- C:\WINDOWS\Sysnative\FWPUCLNT.DLL 2016-05-14 08:33:59 F6B9E6CB351D86A0C318B37E14B97656 196608 ----a-w- C:\WINDOWS\Sysnative\fwpolicyiomgr.dll 2016-05-14 08:33:59 F374C27099807E99A156953F8416D34A 361472 ----a-w- C:\WINDOWS\Sysnative\bdesvc.dll 2016-05-14 08:33:59 E9B10E704AD5B1BA5E531809C89A085B 93184 ----a-w- C:\WINDOWS\Sysnative\wpninprc.dll 2016-05-14 08:33:59 E34A89A196F45473D61CCDAB193293D1 119808 ----a-w- C:\WINDOWS\Sysnative\BitLockerDeviceEncryption.exe 2016-05-14 08:33:59 E083BE4900FCBB6BC42943438DCF2CAD 176128 ----a-w- C:\WINDOWS\Sysnative\SystemSettings.DeviceEncryptionHandlers.dll 2016-05-14 08:33:59 CA24B0764C9DFE243D15A8708580673B 107520 ----a-w- C:\WINDOWS\Sysnative\BdeHdCfgLib.dll 2016-05-14 08:33:59 C8B840675B83DC8A257B075BFE5F9357 261376 ----a-w- C:\WINDOWS\Sysnative\LsaIso.exe 2016-05-14 08:33:59 AA97AC06BFA15DA23C7C9C145A226C2D 25600 ----a-w- C:\WINDOWS\Sysnative\wfapigp.dll 2016-05-14 08:33:59 A15D9F32A84660FA62F9D27577B0F105 324608 ----a-w- C:\WINDOWS\Sysnative\fvecpl.dll 2016-05-14 08:33:59 9AE80C03EA83537F17B286ECBBA13D43 184320 ----a-w- C:\WINDOWS\Sysnative\fwbase.dll 2016-05-14 08:33:59 712AE16ED8FC7F2363F7EA1D8F6D546A 821248 ----a-w- C:\WINDOWS\Sysnative\fvewiz.dll 2016-05-14 08:33:59 6A5290128257BC733107E7819648CA76 526336 ----a-w- C:\WINDOWS\Sysnative\FirewallAPI.dll 2016-05-14 08:33:59 6A0745D04DFB6E37A6D0FEE339A0B742 556032 ----a-w- C:\WINDOWS\Sysnative\PsmServiceExtHost.dll 2016-05-14 08:33:59 258BCD1FE978849EDB02D131FD1F7893 989536 ----a-w- C:\WINDOWS\Sysnative\SecConfig.efi 2016-05-14 08:33:59 091D5AE5E663A66EE73B539AF7C32EC5 69632 ----a-w- C:\WINDOWS\Sysnative\fveskybackup.dll 2016-05-14 08:33:52 95A03F67830FDCB950E70261128D540D 957952 ----a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL 2016-05-14 08:33:52 37F5E2385CB4D10AB42186974B9C241A 794112 ----a-w- C:\WINDOWS\Sysnative\BFE.DLL 2016-05-14 08:33:48 24146738C422814EEB2A98FF1FC5C6E1 338432 ----a-w- C:\WINDOWS\Sysnative\ncbservice.dll 2016-05-14 08:33:47 E0932D924DA7C363F40E5B90DC9D2669 129536 ----a-w- C:\WINDOWS\Sysnative\flvprophandler.dll 2016-05-14 08:33:47 C78D43083400B8FAE408FEB1E99F9DA8 1847808 ----a-w- C:\WINDOWS\Sysnative\WMPDMC.exe 2016-05-14 08:33:47 3E80E2B0C0010154CC504DC51BE21968 14252544 ----a-w- C:\WINDOWS\Sysnative\wmp.dll 2016-05-14 08:33:43 82E25186617BA6C15010F0D47C705705 65536 ----a-w- C:\WINDOWS\Sysnative\basesrv.dll 2016-05-14 08:33:40 F0D97E9816795E1AAA17396ABD2660C4 4827136 ----a-w- C:\WINDOWS\Sysnative\ExplorerFrame.dll 2016-05-14 08:33:40 EA30B6E587862DF15E35525C60CCAFA9 838144 ----a-w- C:\WINDOWS\Sysnative\uDWM.dll 2016-05-14 08:33:40 E2B2525EF375D716E0DE6FE8F3ADCEDB 365568 ----a-w- C:\WINDOWS\Sysnative\atmfd.dll 2016-05-14 08:33:40 CFF415024C353DA284731CB72FE3F8FF 770640 ----a-w- C:\WINDOWS\Sysnative\iuilp.dll 2016-05-14 08:33:40 A74CEC306AB99D74559F7075EDB60A9B 451584 ----a-w- C:\WINDOWS\Sysnative\werui.dll 2016-05-14 08:33:40 A4CA6FE3F02C6299EED8B7296DC902D6 12800 ----a-w- C:\WINDOWS\Sysnative\oleacchooks.dll 2016-05-14 08:33:40 7185B16516478DF0061C2561C1B072CE 228352 ----a-w- C:\WINDOWS\Sysnative\wsqmcons.exe 2016-05-14 08:33:40 68B34C3558BEE0F6B822FA603E9AE441 258280 ----a-w- C:\WINDOWS\Sysnative\sqmapi.dll 2016-05-14 08:33:40 60C04811AC0BB0BFC5E00D293B8F4464 630632 ----a-w- C:\WINDOWS\Sysnative\fontdrvhost.exe 2016-05-14 08:33:40 2989A5B700D1C706ED496CCA75DCFA67 7533568 ----a-w- C:\WINDOWS\Sysnative\mstscax.dll 2016-05-14 08:33:40 14D75B31BA6A28F4A46D7432B48C26B3 45568 ----a-w- C:\WINDOWS\Sysnative\atmlib.dll 2016-05-14 08:33:40 0D7BB44BFFFA4E153F4EA1E05522D2C3 37376 ----a-w- C:\WINDOWS\Sysnative\LaunchWinApp.exe 2016-05-14 08:33:40 0C8955B4BB1E9D588B4B62D0BD2E5E78 411648 ----a-w- C:\WINDOWS\Sysnative\oleacc.dll 2016-05-14 08:33:40 04EDE78320552097AC7EB3CE69A4A0BD 118272 ----a-w- C:\WINDOWS\Sysnative\fontsub.dll 2016-05-14 08:33:39 FF07BE14ED82E218C3EEE7C986118A2E 307712 ----a-w- C:\WINDOWS\Sysnative\usbmon.dll 2016-05-14 08:33:39 F8FAB3E1281FB937DB1C8109842A9534 3994624 ----a-w- C:\WINDOWS\Sysnative\SettingsHandlers_nt.dll 2016-05-14 08:33:39 E5E09ABD5171EB8622821059D8757F43 239616 ----a-w- C:\WINDOWS\Sysnative\credprovhost.dll 2016-05-14 08:33:39 D3406F98BD98633780820C5EDBA9A5B4 166400 ----a-w- C:\WINDOWS\Sysnative\AboveLockAppHost.dll 2016-05-14 08:33:39 D20C52607024BD08A88CF1CA6B339C9B 517632 ----a-w- C:\WINDOWS\Sysnative\winspool.drv 2016-05-14 08:33:39 D1241DFC397FA8CCFB4BB4B63AAD31AC 755712 ----a-w- C:\WINDOWS\Sysnative\spoolsv.exe 2016-05-14 08:33:39 CFF6A3799F83060D3FF538564E4264CA 374008 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsAdminFlows.exe 2016-05-14 08:33:39 B471A4DA6F8DFF957B6F109FA182C366 3575296 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsThresholdAdminFlowUI.dll 2016-05-14 08:33:39 8AF0CBE3FC6129C42D7A2A73B681F226 1118208 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2016-05-14 08:33:39 717FDDACE38C314CA5A517E12162CC6D 216576 ----a-w- C:\WINDOWS\Sysnative\QuickActionsDataModel.dll 2016-05-14 08:33:39 6758ABE6A73AE709A6C74F121C666CC1 841216 ----a-w- C:\WINDOWS\Sysnative\win32spl.dll 2016-05-14 08:33:39 3F8466CC13D1F614C8FAC24B1C030D59 214528 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Scanners.dll 2016-05-14 08:33:39 335995302980B83CA6B1974A84AC6009 730344 ----a-w- C:\WINDOWS\Sysnative\Windows.Internal.Shell.Broker.dll 2016-05-14 08:33:39 1BF000CFA56FD272B4ECAC167CDF6A8F 1211904 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Cred.dll 2016-05-14 08:33:39 12D83590FEF1C8C28DBF3323C61E831A 31232 ----a-w- C:\WINDOWS\Sysnative\wsdchngr.dll 2016-05-14 08:33:37 F8083C536BEDE61AFB4069D8A8C16DA7 456704 ----a-w- C:\WINDOWS\Sysnative\ipnathlp.dll 2016-05-14 08:33:37 C3BB5D3E3DD24AC0BFA9223F2877F136 76800 ----a-w- C:\WINDOWS\Sysnative\NetCfgNotifyObjectHost.exe 2016-05-14 08:33:37 A78E76034D230AFE6B74B57BAF8C8BF2 27648 ----a-w- C:\WINDOWS\Sysnative\WiFiConfigSP.dll 2016-05-14 08:33:37 84ADBF35DAF6404148AE85973BE26D59 48640 ----a-w- C:\WINDOWS\Sysnative\wfdprov.dll 2016-05-14 08:33:37 610D0502400BDAFD4BB8EA10713234C7 74240 ----a-w- C:\WINDOWS\Sysnative\SMSRouter.dll 2016-05-14 08:33:37 6072C7DB85FD3FE8D308EE44865C04DE 305664 ----a-w- C:\WINDOWS\Sysnative\wifiprofilessettinghandler.dll 2016-05-14 08:33:37 53AC4B2658807691D2A485EE0F8A50E9 463360 ----a-w- C:\WINDOWS\Sysnative\wlansec.dll 2016-05-14 08:33:37 453740989239803FE363FF8B40EA2E08 2295808 ----a-w- C:\WINDOWS\Sysnative\wlansvc.dll 2016-05-14 08:33:37 0ED8556CB47EC7689D0046791F3427AE 26112 ----a-w- C:\WINDOWS\Sysnative\wlansvcpal.dll 2016-05-14 08:33:37 09918925526BC0B5B823CF1A2473D909 412672 ----a-w- C:\WINDOWS\Sysnative\wlanmsm.dll 2016-05-14 08:33:36 F4F6D943E788447DAE29DA217B6743E6 147456 ----a-w- C:\WINDOWS\Sysnative\mtxoci.dll 2016-05-14 08:33:36 F07301C282AA222C33F8C28B4F545275 591872 ----a-w- C:\WINDOWS\Sysnative\SmsRouterSvc.dll 2016-05-14 08:33:36 EF953237B34D1468B81A6AB260A3C524 1317640 ----a-w- C:\WINDOWS\Sysnative\winload.efi 2016-05-14 08:33:36 EBD07BD20B5E0E92A398566EF8720F79 31232 ----a-w- C:\WINDOWS\Sysnative\seclogon.dll 2016-05-14 08:33:36 DAFECF80513C6E6892BBEBB48D555A31 115712 ----a-w- C:\WINDOWS\Sysnative\srpapi.dll 2016-05-14 08:33:36 D842C2B65E77C13273B626317A5BC5C4 555520 ----a-w- C:\WINDOWS\Sysnative\SyncController.dll 2016-05-14 08:33:36 CD885F960066DDD538CD1BBD509A0EC0 69632 ----a-w- C:\WINDOWS\Sysnative\wininetlui.dll 2016-05-14 08:33:36 C1C169EFA8E5E30A0A521C0409CAC153 874968 ----a-w- C:\WINDOWS\Sysnative\winresume.exe 2016-05-14 08:33:36 BE8C62B0B7BBA8F1152A6A7FCF248404 915456 ----a-w- C:\WINDOWS\Sysnative\configurationclient.dll 2016-05-14 08:33:36 BE7D6EA3650F1C25076335A9C1F3D59B 1098240 ----a-w- C:\WINDOWS\Sysnative\dosvc.dll 2016-05-14 08:33:36 B37F21B4C25BF10605A196791F93E324 360448 ----a-w- C:\WINDOWS\Sysnative\vaultsvc.dll 2016-05-14 08:33:36 B0236F0FB7402381A50F2EBF031C49CF 1030416 ----a-w- C:\WINDOWS\Sysnative\winresume.efi 2016-05-14 08:33:36 AEBD5FCFBFF0294A2D87048D4F5417CB 74424 ----a-w- C:\WINDOWS\Sysnative\easinvoker.exe 2016-05-14 08:33:36 AE6A68A065D4C26AF4BEFAA53623B266 2755584 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2016-05-14 08:33:36 A2902A998C3A8A049D26235A75DBE300 174592 ----a-w- C:\WINDOWS\Sysnative\easwrt.dll 2016-05-14 08:33:36 9BE5ECE2F17B3BEDE6FDE1175BD23266 376536 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.MediaControl.dll 2016-05-14 08:33:36 9822B613AEB1CF24E05EFEE748160637 25088 ----a-w- C:\WINDOWS\Sysnative\irmon.dll 2016-05-14 08:33:36 96BAB1499995B85B91C312BA5114CA03 1322248 ----a-w- C:\WINDOWS\Sysnative\ole32.dll 2016-05-14 08:33:36 92291BFE95AD37CF486BD3E4B31F746B 1141504 ----a-w- C:\WINDOWS\Sysnative\winload.exe 2016-05-14 08:33:36 7A0E065E46156F9288AE32B1E0399247 52224 ----a-w- C:\WINDOWS\Sysnative\jsproxy.dll 2016-05-14 08:33:36 77B2F9C522467B1FC8770028D09534DB 91648 ----a-w- C:\WINDOWS\Sysnative\asycfilt.dll 2016-05-14 08:33:36 703430E9FFF072334B247B5E88428331 288768 ----a-w- C:\WINDOWS\Sysnative\vaultcli.dll 2016-05-14 08:33:36 6E04BBE242E2889B37300C4DF5CE1126 3449168 ----a-w- C:\WINDOWS\Sysnative\WSService.dll 2016-05-14 08:33:36 6870232D80480DA4FF1FBE3373FCA06E 965632 ----a-w- C:\WINDOWS\Sysnative\SRH.dll 2016-05-14 08:33:36 5D88798FC34BB61C74256CDD66BDD205 318976 ----a-w- C:\WINDOWS\Sysnative\domgmt.dll 2016-05-14 08:33:36 5CB565C1A0A30D76D7B099EEF9654297 256000 ----a-w- C:\WINDOWS\Sysnative\accountaccessor.dll 2016-05-14 08:33:36 290D24F50396B379338790B8E8D1C503 1714688 ----a-w- C:\WINDOWS\Sysnative\SRHInproc.dll 2016-05-14 08:33:36 28CFFDB411375B2BBB0EBF295ABAEF29 382464 ----a-w- C:\WINDOWS\Sysnative\wuuhext.dll 2016-05-14 08:33:36 1F3D69B0AE210874DDC300C3EF1C9CCD 438784 ----a-w- C:\WINDOWS\Sysnative\AccountsRt.dll 2016-05-14 08:33:36 167176E3A8B095C2E807D27CBE6AB0D3 1902592 ----a-w- C:\WINDOWS\Sysnative\msxml3.dll 2016-05-14 08:33:36 023338E1DA5B6E5C2EFC7E5ADA7929C5 685568 ----a-w- C:\WINDOWS\Sysnative\scapi.dll 2016-05-14 08:33:35 F432ACF44EABBE3EB98F613E1573DA6F 334736 ----a-w- C:\WINDOWS\Sysnative\policymanager.dll 2016-05-14 08:33:35 F40C5151476B066A4061E67DFA641657 128512 ----a-w- C:\WINDOWS\Sysnative\dmcsps.dll 2016-05-14 08:33:35 EEA1E99FBC7D91A1A271012F2B4567BB 60416 ----a-w- C:\WINDOWS\Sysnative\PimIndexMaintenanceClient.dll 2016-05-14 08:33:35 EA195B8BC11C1CDB313CFD456EFFA0E9 997376 ----a-w- C:\WINDOWS\Sysnative\schedsvc.dll 2016-05-14 08:33:35 E432FCF8572682126C3362AA856DC4AE 221184 ----a-w- C:\WINDOWS\Sysnative\PhoneCallHistoryApis.dll 2016-05-14 08:33:35 E1D8055043DF089DB8ADB67C21DF2CC4 70656 ----a-w- C:\WINDOWS\Sysnative\POSyncServices.dll 2016-05-14 08:33:35 DEFF4C7B937F60923980D4BB7D1724B8 274944 ----a-w- C:\WINDOWS\Sysnative\ExSMime.dll 2016-05-14 08:33:35 DD877B48C28AB34197AD88902971B81D 45056 ----a-w- C:\WINDOWS\Sysnative\UserDataLanguageUtil.dll 2016-05-14 08:33:35 DD57E9F1482E1A9BD2514F6D017DF58A 258560 ----a-w- C:\WINDOWS\Sysnative\UserDataAccountApis.dll 2016-05-14 08:33:35 D169A4C1EDA2F63545628420014F2FE3 808800 ----a-w- C:\WINDOWS\Sysnative\WWAHost.exe 2016-05-14 08:33:35 CB902A15DD21B363FECA5DCCF34F5C57 1224704 ----a-w- C:\WINDOWS\Sysnative\Unistore.dll 2016-05-14 08:33:35 C6856D20BE1DB90407C9154B0EC319B9 77824 ----a-w- C:\WINDOWS\Sysnative\provpackageapidll.dll 2016-05-14 08:33:35 B82C04128A96A05139F9F58ED07D0DB2 3351040 ----a-w- C:\WINDOWS\Sysnative\msi.dll 2016-05-14 08:33:35 B6877446C93D3110E56C90CF13CBEC89 45568 ----a-w- C:\WINDOWS\Sysnative\UserDataTypeHelperUtil.dll 2016-05-14 08:33:35 B3B3BF36976D72C06C2D3524AC040643 81144 ----a-w- C:\WINDOWS\Sysnative\netapi32.dll 2016-05-14 08:33:35 B232CE503C6666873E7B9E4BA769C524 92160 ----a-w- C:\WINDOWS\Sysnative\policymanagerprecheck.dll 2016-05-14 08:33:35 AC71C0A77ED618382D5422C6AB1747E4 169472 ----a-w- C:\WINDOWS\Sysnative\mdmmigrator.dll 2016-05-14 08:33:35 A617BE5E429A035A1CA8217C1B16F0BB 134656 ----a-w- C:\WINDOWS\Sysnative\browser.dll 2016-05-14 08:33:35 A249C98D869623F1AF0DB4BCFFF6D2A8 68096 ----a-w- C:\WINDOWS\Sysnative\UserDataPlatformHelperUtil.dll 2016-05-14 08:33:35 9FDAC1F65E074C1CF12C3E80BD5195E4 176640 ----a-w- C:\WINDOWS\Sysnative\mdmregistration.dll 2016-05-14 08:33:35 95D2BD6AC94FB337AF69F8AFE056BEBE 147808 ----a-w- C:\WINDOWS\Sysnative\wermgr.exe 2016-05-14 08:33:35 94612B9F7FC2B1A5C6D337C649B346F1 278528 ----a-w- C:\WINDOWS\Sysnative\NotificationObjFactory.dll 2016-05-14 08:33:35 93E597D2B5C653E94680E8B8E1C59B36 641536 ----a-w- C:\WINDOWS\Sysnative\enterprisecsps.dll 2016-05-14 08:33:35 91F08041D932816D0D9607F68578A87E 34816 ----a-w- C:\WINDOWS\Sysnative\dmenterprisediagnostics.dll 2016-05-14 08:33:35 907B65AD953EA159B573A0BCC82F6DB0 243712 ----a-w- C:\WINDOWS\Sysnative\cemapi.dll 2016-05-14 08:33:35 8EC4F381818F8A073DEC52C6D1ED9C76 86016 ----a-w- C:\WINDOWS\Sysnative\DeviceEnroller.exe 2016-05-14 08:33:35 8790833B243AB6DD22A1F86FFB26B689 1052160 ----a-w- C:\WINDOWS\Sysnative\MsSpellCheckingFacility.dll 2016-05-14 08:33:35 85EE46E85C3E76809BC454A50564ECD6 418304 ----a-w- C:\WINDOWS\Sysnative\dmenrollengine.dll 2016-05-14 08:33:35 81B78E1782DB1BA758FDA7B993C9FEB5 91136 ----a-w- C:\WINDOWS\Sysnative\browserbroker.dll 2016-05-14 08:33:35 7E81E3E0D7F83BFE3C3975020B6C7F12 163840 ----a-w- C:\WINDOWS\Sysnative\TimeBrokerServer.dll 2016-05-14 08:33:35 7C20F3EC0BA5ACB8ED40CDEF41B0AC56 779384 ----a-w- C:\WINDOWS\Sysnative\taskschd.dll 2016-05-14 08:33:35 70BA4CAAC5D621DCE88082DA0B1FF014 23552 ----a-w- C:\WINDOWS\Sysnative\ExtrasXmlParser.dll 2016-05-14 08:33:35 6855984AA46D2452A7C518787E1F2643 1996288 ----a-w- C:\WINDOWS\Sysnative\ActiveSyncProvider.dll 2016-05-14 08:33:35 61C99C1A4BB5EE14563ED321A859ACB6 726528 ----a-w- C:\WINDOWS\Sysnative\ChatApis.dll 2016-05-14 08:33:35 4C5D035670EB045123DCF87EE2FDB33B 162816 ----a-w- C:\WINDOWS\Sysnative\enrollmentapi.dll 2016-05-14 08:33:35 4C3A93515CA70A7017CBA3A6A95CF080 121856 ----a-w- C:\WINDOWS\Sysnative\AppointmentActivation.dll 2016-05-14 08:33:35 4BE54893EC2A3B26140DF44E7B6D4E99 230400 ----a-w- C:\WINDOWS\Sysnative\DAFWSD.dll 2016-05-14 08:33:35 492FB85E61768950CDD27C87AED6E8FA 587776 ----a-w- C:\WINDOWS\Sysnative\bisrv.dll 2016-05-14 08:33:35 3932940E0DB7A31B00A415F6B3D3E242 700416 ----a-w- C:\WINDOWS\Sysnative\AppointmentApis.dll 2016-05-14 08:33:35 38C87ECB57CB973AA5DA633B91778670 676352 ----a-w- C:\WINDOWS\Sysnative\WSDApi.dll 2016-05-14 08:33:35 333F190DFAE2E1EE500234B78ADDA297 640472 ----a-w- C:\WINDOWS\Sysnative\wer.dll 2016-05-14 08:33:35 2DDEA2BEDD3169F483C9BE610ADFE8B1 8705672 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Protection.PlayReady.dll 2016-05-14 08:33:35 2BCCAEB08EAF8C5D6BD024B3F020D0EA 790528 ----a-w- C:\WINDOWS\Sysnative\EmailApis.dll 2016-05-14 08:33:35 2362BCA98EAF8CE0487664467F720861 178176 ----a-w- C:\WINDOWS\Sysnative\psmsrv.dll 2016-05-14 08:33:35 21098276051C6BEBBA7C8EB79AAF4E22 938496 ----a-w- C:\WINDOWS\Sysnative\ContactApis.dll 2016-05-14 08:33:35 1D00BBEEE33FA7F64A8CBFF471968CB0 195072 ----a-w- C:\WINDOWS\Sysnative\VCardParser.dll 2016-05-14 08:33:35 1A0945D67F0499600E7B43A69210EC5B 41984 ----a-w- C:\WINDOWS\Sysnative\TimeBrokerClient.dll 2016-05-14 08:33:35 11C782F631D915895E56FC1CD8214E51 100232 ----a-w- C:\WINDOWS\Sysnative\omadmapi.dll 2016-05-14 08:33:35 04F7878E7017105AB782353231561749 252928 ----a-w- C:\WINDOWS\Sysnative\PimIndexMaintenance.dll 2016-05-14 08:33:35 03416DA86664FF2141A5820868B0B9B1 88576 ----a-w- C:\WINDOWS\Sysnative\AppxSysprep.dll 2016-05-14 08:33:35 020AD2DA67F206DC160053F88454A0D4 111616 ----a-w- C:\WINDOWS\Sysnative\UserDataTimeUtil.dll 2016-05-14 08:33:34 F7391A45172C10D8B79A239CDD8BA88B 209408 ----a-w- C:\WINDOWS\Sysnative\storewuauth.dll 2016-05-14 08:33:34 F5B8CC586CE9D6187F412B5DFE932468 33280 ----a-w- C:\WINDOWS\Sysnative\wuautoappupdate.dll 2016-05-14 08:33:34 DA4F2FBA02ADB65797953219ABEF0C44 58400 ----a-w- C:\WINDOWS\Sysnative\SensorsNativeApi.dll 2016-05-14 08:33:34 D8F3E820C39808C00A687AED554D23C0 859136 ----a-w- C:\WINDOWS\Sysnative\Windows.ApplicationModel.Store.dll 2016-05-14 08:33:34 D0CCDC8D0D00DA363F9D87C2E9A803EF 1297752 ----a-w- C:\WINDOWS\Sysnative\LicenseManager.dll 2016-05-14 08:33:34 CD8C4364BC6040C0226638EF37E13CBB 161280 ----a-w- C:\WINDOWS\Sysnative\CallHistoryClient.dll 2016-05-14 08:33:34 C59CF7385D070450643D61C8ADEFFE3C 958976 ----a-w- C:\WINDOWS\Sysnative\RemoteNaturalLanguage.dll 2016-05-14 08:33:34 AB416599057FFDC84E28BBB6DA69EADC 235008 ----a-w- C:\WINDOWS\Sysnative\MTF.dll 2016-05-14 08:33:34 A34D9229F8D3A7164247213C9A283DB0 189952 ----a-w- C:\WINDOWS\Sysnative\WiFiDisplay.dll 2016-05-14 08:33:34 8FFFDB163436D790369E39700B8A7DC1 27648 ----a-w- C:\WINDOWS\Sysnative\LicenseManagerShellext.exe 2016-05-14 08:33:34 45D26646E3AD737E5DE3DB91CCCE7DBA 339968 ----a-w- C:\WINDOWS\Sysnative\SensorService.dll 2016-05-14 08:33:34 3F4461644840A3C5572DDC726C36BDF7 92160 ----a-w- C:\WINDOWS\Sysnative\SensorsNativeApi.V2.dll 2016-05-14 08:33:34 2E165E1CF278FC2B4959B825642A595B 558080 ----a-w- C:\WINDOWS\Sysnative\MBMediaManager.dll 2016-05-14 08:33:34 2771EBB565F5C121E66060B173991D4D 1490432 ----a-w- C:\WINDOWS\Sysnative\UserDataService.dll 2016-05-14 08:33:34 1AE232355968BBCA3787B5B35DCA0FD0 550912 ----a-w- C:\WINDOWS\Sysnative\StoreAgent.dll 2016-05-14 08:33:34 087FF4F0D29833949962F8EE60DA345E 199168 ----a-w- C:\WINDOWS\Sysnative\InstallAgent.exe 2016-05-14 08:33:34 04BB77409644685810DBD63D86F5720E 99328 ----a-w- C:\WINDOWS\Sysnative\ngckeyenum.dll 2016-05-14 08:33:34 0271B5C23A375E008C34024088D0F396 1575936 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Speech.dll 2016-05-14 08:33:31 F66EEB5365413D4B968C5B51D25F88B8 141560 ----a-w- C:\WINDOWS\Sysnative\AuthHost.exe 2016-05-14 08:33:31 F0BBBF8807D5725102A9EB06AEB9C1C5 58368 ----a-w- C:\WINDOWS\Sysnative\browcli.dll 2016-05-14 08:33:31 E8A201E7ACF39359D99EEDD3D059E5AC 1395712 ----a-w- C:\WINDOWS\Sysnative\UIAutomationCore.dll 2016-05-14 08:33:31 DB2911201B4AAC79AF712C5551F0C41D 688640 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.Connectivity.dll 2016-05-14 08:33:31 DB0C2721BE0E21EAA0C4C70B07F481DE 3078144 ----a-w- C:\WINDOWS\Sysnative\esent.dll 2016-05-14 08:33:31 D9A795240A84C9E3DA78BC1B9E239FCF 95744 ----a-w- C:\WINDOWS\Sysnative\samlib.dll 2016-05-14 08:33:31 D22A2DEC01300ECEB41D22AB60B1E4B3 66048 ----a-w- C:\WINDOWS\Sysnative\OnDemandConnRouteHelper.dll 2016-05-14 08:33:31 BEF109D45139E2646C116DD9B6E53E3C 847360 ----a-w- C:\WINDOWS\Sysnative\netlogon.dll 2016-05-14 08:33:31 B8CBDF64077D764D26E6E0255270B7BF 224256 ----a-w- C:\WINDOWS\Sysnative\PackageStateRoaming.dll 2016-05-14 08:33:31 B7C13F4BE0263F3A8303404A96F4246D 358752 ----a-w- C:\WINDOWS\Sysnative\msv1_0.dll 2016-05-14 08:33:31 AFAF7063071A1124985A63382B2BC34C 161792 ----a-w- C:\WINDOWS\Sysnative\AppxSip.dll 2016-05-14 08:33:31 A6969BAD3166EDA1C79988DD782A87CF 888320 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.dll 2016-05-14 08:33:31 A407435633C74CB1D6911DC05A90D939 2912256 ----a-w- C:\WINDOWS\Sysnative\CertEnroll.dll 2016-05-14 08:33:31 9A3E17CDB177913C2A111C80F3D0DBB4 686976 ----a-w- C:\WINDOWS\Sysnative\dnsapi.dll 2016-05-14 08:33:31 99D5C132D5085DACBFF909C3AAF832AC 2624512 ----a-w- C:\WINDOWS\Sysnative\InputService.dll 2016-05-14 08:33:31 998015F786B2B9EE029FB556393CF848 78040 ----a-w- C:\WINDOWS\Sysnative\wkscli.dll 2016-05-14 08:33:31 92FB4032354D2074DA0DC9E70D8305B1 1388032 ----a-w- C:\WINDOWS\Sysnative\lsasrv.dll 2016-05-14 08:33:31 87F0EA669FB37C03207A8870C3B91174 1410560 ----a-w- C:\WINDOWS\Sysnative\Windows.Web.Http.dll 2016-05-14 08:33:31 7E0078F1EFEB6F8F47CF85C1D73C7EBC 328192 ----a-w- C:\WINDOWS\Sysnative\profsvc.dll 2016-05-14 08:33:31 7890990143812A452858058BBD52149F 297472 ----a-w- C:\WINDOWS\Sysnative\thumbcache.dll 2016-05-14 08:33:31 77981E6F98F4A8743D3AEB1A8AF4DE09 108544 ----a-w- C:\WINDOWS\Sysnative\InputLocaleManager.dll 2016-05-14 08:33:31 7118498F6E48758A2EF5A7D1982E2B62 1139712 ----a-w- C:\WINDOWS\Sysnative\XblGameSave.dll 2016-05-14 08:33:31 703F15FBAEA94F88FD5E12EFA94A0F7E 2656952 ----a-w- C:\WINDOWS\Sysnative\CoreUIComponents.dll 2016-05-14 08:33:31 6D31FB3E4263749BD994B3895322D799 982016 ----a-w- C:\WINDOWS\Sysnative\AppxPackaging.dll 2016-05-14 08:33:31 63939B50C5C103FA71A419BCEA5B1CF0 26112 ----a-w- C:\WINDOWS\Sysnative\TokenBrokerCookies.exe 2016-05-14 08:33:31 5DFAF8BE5A3CABAABF6795BC09EB7876 948736 ----a-w- C:\WINDOWS\Sysnative\XblAuthManager.dll 2016-05-14 08:33:31 594FDF2DB7568C73C282B282845E30CF 36352 ----a-w- C:\WINDOWS\Sysnative\tbauth.dll 2016-05-14 08:33:31 5839A317C25F70979433E0905DFABB1B 284672 ----a-w- C:\WINDOWS\Sysnative\dnsrslvr.dll 2016-05-14 08:33:31 56C238ACFE4CB020D3E38508249039EA 87040 ----a-w- C:\WINDOWS\Sysnative\tzautoupdate.dll 2016-05-14 08:33:31 51449675B00C62F970B497A2FBF1BC46 787456 ----a-w- C:\WINDOWS\Sysnative\Windows.Web.dll 2016-05-14 08:33:31 5066575F39AEECAA7A9E03C0FA007A90 881664 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Input.Inking.dll 2016-05-14 08:33:31 50007CDB0F9801A7186F3E81D3377D12 2773096 ----a-w- C:\WINDOWS\Sysnative\d3d11.dll 2016-05-14 08:33:31 497EB340D13433E8FE53625103E0C2D0 146432 ----a-w- C:\WINDOWS\Sysnative\AuthBroker.dll 2016-05-14 08:33:31 46E51F35566F8B73540D56EAA0A97E46 175616 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Core.TextInput.dll 2016-05-14 08:33:31 3EEB5260D4321F7F124955E1D228FDF2 274944 ----a-w- C:\WINDOWS\Sysnative\DisplayManager.dll 2016-05-14 08:33:31 2F0FA6F60BC9A971BFBF31D1D2C8AF08 167936 ----a-w- C:\WINDOWS\Sysnative\dafBth.dll 2016-05-14 08:33:31 2804ACDD73835F051CE71DA4DB25337D 110584 ----a-w- C:\WINDOWS\Sysnative\srvcli.dll 2016-05-14 08:33:31 0D9E0BDCCCE10F07A7B66A61B27C1F71 116224 ----a-w- C:\WINDOWS\Sysnative\FontProvider.dll 2016-05-14 08:33:30 FBC8C56814642A7CA88ACBCA8DD1121F 145408 ----a-w- C:\WINDOWS\Sysnative\dssvc.dll 2016-05-14 08:33:30 F7526C133AC265F283012E9CD751F873 625000 ----a-w- C:\WINDOWS\Sysnative\ClipSVC.dll 2016-05-14 08:33:30 AB3F697651DDAE1C424C9B2412EFBB59 1239552 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Bluetooth.dll 2016-05-14 08:33:30 9CB84B6398F10BCF0CE357F2C7B6056D 286720 ----a-w- C:\WINDOWS\Sysnative\deviceaccess.dll 2016-05-14 08:33:30 728146F5877FD08DE65B21817ABB19A8 765952 ----a-w- C:\WINDOWS\Sysnative\fveapi.dll 2016-05-14 08:33:30 5B5F518D6487FDCC9C40A74D3C72B8EE 828928 ----a-w- C:\WINDOWS\Sysnative\Windows.AccountsControl.dll 2016-05-14 08:33:30 5118193C56A2F8D07554395B78A6FDCC 223232 ----a-w- C:\WINDOWS\Sysnative\fveapibase.dll 2016-05-14 08:33:30 4098813724BDAC23A74DD6E75CA360CC 450560 ----a-w- C:\WINDOWS\Sysnative\Windows.Internal.Bluetooth.dll 2016-05-14 08:33:30 3C994D13A234D0E33D592CDF55F09B01 628736 ----a-w- C:\WINDOWS\Sysnative\MessagingDataModel2.dll 2016-05-14 08:33:30 15D174719872A30F2FDD6B5B1B8BA5D9 1613664 ----a-w- C:\WINDOWS\Sysnative\diagtrack.dll 2016-05-14 08:33:30 0FEE16BB03B1A97A70121165E7414903 67584 ----a-w- C:\WINDOWS\Sysnative\profext.dll 2016-05-14 08:26:03 F44AA79DF45B1CAE6E6C64372D846AA5 6359040 ----a-w- C:\WINDOWS\Sysnative\NlsData0009.dll 2016-05-14 08:26:03 E52612EA0C1C1ACD3ABFD09534F6AAE6 5739520 ----a-w- C:\WINDOWS\Sysnative\prm0009.dll 2016-05-14 08:26:03 8F1CD3FABC7F24FE329FE39A3EB58C58 2629632 ----a-w- C:\WINDOWS\Sysnative\NlsLexicons0009.dll 2016-05-14 08:12:02 E91942A0D00C6AA014B2EA33EE0ED0A3 35480 ----a-w- C:\WINDOWS\Sysnative\TsWpfWrp.exe 2016-05-14 08:12:02 E2296A6174894682DF8F0FF29FDDCC82 1166520 ----a-w- C:\WINDOWS\Sysnative\PresentationNative_v0300.dll 2016-05-14 08:12:02 C5FEF4B4A7FB961ECDB0AB07DBCF379E 124624 ----a-w- C:\WINDOWS\Sysnative\PresentationCFFRasterizerNative_v0300.dll 2016-05-14 08:11:47 48E7F01CD9246CAF86702F5CB9100C9F 1087488 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2016-05-14 08:11:47 20B48DC4AF4492B31A756528444BDA8C 304752 ----a-w- C:\WINDOWS\Sysnative\systemreset.exe 2016-05-14 07:47:14 3FF007DCE48038E858DA50353324D50D 81416 ----a-w- C:\WINDOWS\Sysnative\OpenCL.DLL 2016-05-05 08:13:38 F92CD71D1F33737C1B44520A4FA46F41 190868 ----a-w- C:\WINDOWS\Sysnative\resTHA.cui 2016-05-05 08:13:38 F437178473513F674448DDD563E21EC6 156836 ----a-w- C:\WINDOWS\Sysnative\resNLD.cui 2016-05-05 08:13:38 DD636076410053695210D7FE335B4612 157668 ----a-w- C:\WINDOWS\Sysnative\resROM.cui 2016-05-05 08:13:38 D49A6F32AF0C0CACD3E28011752CD7BB 179252 ----a-w- C:\WINDOWS\Sysnative\resRUS.cui 2016-05-05 08:13:38 C0E4A8CD76BAF7E34DD884C2B11F9157 153508 ----a-w- C:\WINDOWS\Sysnative\resNOR.cui 2016-05-05 08:13:38 BE427823C85F7356B08F87D7A3652A0F 157012 ----a-w- C:\WINDOWS\Sysnative\resSKY.cui 2016-05-05 08:13:38 B61D17AB060B76EF699D5C561DF5937D 154628 ----a-w- C:\WINDOWS\Sysnative\resSVE.cui 2016-05-05 08:13:38 8DA2EE8AF3BA9795D5858A03419E2582 157140 ----a-w- C:\WINDOWS\Sysnative\resPLK.cui 2016-05-05 08:13:38 7FF2CC47007D028C70D260CD3BE3A3E9 156228 ----a-w- C:\WINDOWS\Sysnative\resPTB.cui 2016-05-05 08:13:38 790ABA99CCCA436A7F14BED99054676C 154484 ----a-w- C:\WINDOWS\Sysnative\resSLV.cui 2016-05-05 08:13:38 6811F7D1D1DD791AD5EF4B34021DDA41 156116 ----a-w- C:\WINDOWS\Sysnative\resTRK.cui 2016-05-05 08:13:38 53BC9C2E21EFB2F6383316B8F7E49B5E 155940 ----a-w- C:\WINDOWS\Sysnative\resPTG.cui 2016-05-05 08:13:37 DF222231EEB1A30C571C939E8D093B3E 159716 ----a-w- C:\WINDOWS\Sysnative\resFRA.cui 2016-05-05 08:13:37 D2DC0F286A18CD604D614796EEF43DD7 155460 ----a-w- C:\WINDOWS\Sysnative\resFIN.cui 2016-05-05 08:13:37 C4635F995A560E940CB53D856C4C2262 157860 ----a-w- C:\WINDOWS\Sysnative\resITA.cui 2016-05-05 08:13:37 93BFE18055C725BE62F326BF21A8BBEE 157572 ----a-w- C:\WINDOWS\Sysnative\resESN.cui 2016-05-05 08:13:37 7D71A8DA29E4793E4903A69F7E1904DB 155060 ----a-w- C:\WINDOWS\Sysnative\resHRV.cui 2016-05-05 08:13:37 7A746D9E4CE17816EF79A9D281549C9C 158004 ----a-w- C:\WINDOWS\Sysnative\resKOR.cui 2016-05-05 08:13:37 6CFDEC7F925B4FB7B790691604CB45D8 164356 ----a-w- C:\WINDOWS\Sysnative\resHEB.cui 2016-05-05 08:13:37 2E20C34A1C4187F74B595095E588B661 159732 ----a-w- C:\WINDOWS\Sysnative\resHUN.cui 2016-05-05 08:13:37 2A494F1A69642804A69EEC07B1961DDA 151684 ----a-w- C:\WINDOWS\Sysnative\resENU.cui 2016-05-05 08:13:37 0B3FF7F09EE2F2CB46E5A6666295E8F4 164404 ----a-w- C:\WINDOWS\Sysnative\resJPN.cui 2016-05-05 08:13:36 90B669D2378C6C604C66E7A3EF10A30E 157892 ----a-w- C:\WINDOWS\Sysnative\resDEU.cui 2016-05-05 08:13:36 7EE04EA51220641630C60B6C1D381766 156132 ----a-w- C:\WINDOWS\Sysnative\resCSY.cui 2016-05-05 08:13:36 7500547A42B144BAECCF3FB2F8C394AC 153028 ----a-w- C:\WINDOWS\Sysnative\resDAN.cui 2016-05-05 08:13:36 6659852D082515116691907217EE12CF 149060 ----a-w- C:\WINDOWS\Sysnative\resCHS.cui 2016-05-05 08:13:36 4C753D32EE16231059379157A5F13EB2 149924 ----a-w- C:\WINDOWS\Sysnative\resCHT.cui 2016-05-05 08:13:36 45B13DCD38BD8D5400FCAD7488B3A776 164932 ----a-w- C:\WINDOWS\Sysnative\resARA.cui 2016-05-05 08:13:36 02233DAB3FA1D7E0D29E4A92E39B27EA 183476 ----a-w- C:\WINDOWS\Sysnative\resELL.cui 2016-05-05 08:13:21 F390D4AC8E8820C1FF38CE61BF5522F1 1478632 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiSecureSourceFilter64.dll 2016-05-05 08:13:21 D12F2974884D6A5B276B8ECBB139F6C5 668136 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiAudioFilter64.dll 2016-05-05 08:13:21 C6DB28C213FB901E1A9177599F225196 366560 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiSilenceFilter64.dll 2016-05-05 08:13:21 BD5A64A59AE4C581D0FE75E73ABDFFC7 232424 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiUtils64.dll 2016-05-05 08:13:21 AB394B2CB85789C18D2575C3B20AF8E2 452576 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiUMS64.exe 2016-05-05 08:13:21 9BBBB7E00611C7A6EA64D3E7374FC47C 2516360 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiVAD64.exe 2016-05-05 08:13:21 99A19D1FD429A75765161F9760ADE922 625640 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiMux64.dll 2016-05-05 08:13:21 974577FB784397A766D64AF055EC64FF 150504 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiMCUMD64.dll 2016-05-05 08:13:21 8E1DC4C86925BA6A4FD1A6D33C2E25AC 199656 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiDDEAgent64.dll 2016-05-05 08:13:21 3FF007DCE48038E858DA50353324D50D 81416 ----a-w- C:\WINDOWS\Sysnative\Intel_OpenCL_ICD64.dll 2016-05-05 08:13:21 29BD0D3D6101D2ECD46DE8D0B74EC32B 116200 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiLogServer64.dll 2016-05-05 08:13:21 21618C7F652F06AE199739166AE2747A 881128 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiWinNextAgent64.dll 2016-05-05 08:13:20 F26306CA88FA0BD803A79F3BAA0E6D10 240432 ----a-w- C:\WINDOWS\Sysnative\iglhcp64.dll 2016-05-05 08:13:20 EB15C47EC115E074C19614CAE0325D37 4033000 ----a-w- C:\WINDOWS\Sysnative\IntelWiDiAAC64.dll 2016-05-05 08:13:20 DC09F79852DFE9A957ADC4A917AAE29D 27656 ----a-w- C:\WINDOWS\Sysnative\igfxEMLibv2_0.dll 2016-05-05 08:13:20 D8D19E718075D7B3DCA6B668968F3A87 266208 ----a-w- C:\WINDOWS\Sysnative\igfxHK.exe 2016-05-05 08:13:20 D0CF59A2F35FB028BA3F1732E0D1A129 269832 ----a-w- C:\WINDOWS\Sysnative\igfxLHM.dll 2016-05-05 08:13:20 CE12AB540A39C6D695DD556118150A2D 22536 ----a-w- C:\WINDOWS\Sysnative\igfxLHMLib.dll 2016-05-05 08:13:20 C43B14D81B5F40A7F20108DDF647111E 394248 ----a-w- C:\WINDOWS\Sysnative\IntelOpenCL64.dll 2016-05-05 08:13:20 BDB7715B7121BAC65B49ED1A20EB4762 27656 ----a-w- C:\WINDOWS\Sysnative\igfxEMLib.dll 2016-05-05 08:13:20 BBD33D80F5208FE34A54EEA8552F5A9A 391648 ----a-w- C:\WINDOWS\Sysnative\igfxTray.exe 2016-05-05 08:13:20 B226B85123619EF1394339C1B5EB5A8D 43494 ----a-w- C:\WINDOWS\Sysnative\iglhxc64.vp 2016-05-05 08:13:20 94ED4F871997E5DFC610DC1649C38911 43256 ----a-w- C:\WINDOWS\Sysnative\iglhxg64.vp 2016-05-05 08:13:20 87D272A2CAE9850C1845A56B7A7A3ABA 1174832 ----a-w- C:\WINDOWS\Sysnative\iglhsip64.dll 2016-05-05 08:13:20 715DBDBED4599E798F94EDF6003F75B6 42079 ----a-w- C:\WINDOWS\Sysnative\iglhxo64_dev.vp 2016-05-05 08:13:20 6F306BAEEF21075AD527138061C615E5 206856 ----a-w- C:\WINDOWS\Sysnative\igfxCoIn_v4358.dll 2016-05-05 08:13:20 6E9392C7BC5A96AAC89882D910A6F2AD 2582 ----a-w- C:\WINDOWS\Sysnative\iglhxs64.vp 2016-05-05 08:13:20 6C0F36ABFE80433B352FA7748ED887BF 2813952 ----a-w- C:\WINDOWS\Sysnative\iglhxa64.cpa 2016-05-05 08:13:20 69CAB38C40864023F6F96B94261F8BE2 388616 ----a-w- C:\WINDOWS\Sysnative\igfxOSP.dll 2016-05-05 08:13:20 5CD266D67DC46AAF2A569980B43B5C2C 213984 ----a-w- C:\WINDOWS\Sysnative\igfxext.exe 2016-05-05 08:13:20 55C71EDC47B57E5115B40095EEC9E205 43816 ----a-w- C:\WINDOWS\Sysnative\iglhxc64_dev.vp 2016-05-05 08:13:20 3B6EF4F03F2DE75A3B7DDF627A3EC146 44025 ----a-w- C:\WINDOWS\Sysnative\iglhxo64.vp 2016-05-05 08:13:20 2FCCF7939D4D3F392AB3C0F5F40039DD 1125 ----a-w- C:\WINDOWS\Sysnative\iglhxa64.vp 2016-05-05 08:13:20 26D5D96A154CA199F3F11DCE1242B29F 22536 ----a-w- C:\WINDOWS\Sysnative\igfxLHMLibv2_0.dll 2016-05-05 08:13:20 1A1A25E902728F8BC14365C6A7F62F71 49936 ----a-w- C:\WINDOWS\Sysnative\igfxexps.dll 2016-05-05 08:13:20 04590E9E52E13EF34B2AA02C7EA2431B 43298 ----a-w- C:\WINDOWS\Sysnative\iglhxg64_dev.vp 2016-05-05 08:13:19 FA1BC8B5D88A67BF5893BEB18729E0D8 209648 ----a-w- C:\WINDOWS\Sysnative\igfxcmrt64.dll 2016-05-05 08:13:19 CC124755782A2366CFA90E01F47E0D22 226824 ----a-w- C:\WINDOWS\Sysnative\igfxDTCM.dll 2016-05-05 08:13:19 C7025ED9332D112CD4DAD7C8E92F30B1 549344 ----a-w- C:\WINDOWS\Sysnative\igfxEM.exe 2016-05-05 08:13:19 C6B5714EE703CE75BF4CC2F0A068C7C2 28168 ----a-w- C:\WINDOWS\Sysnative\igfxDILib.dll 2016-05-05 08:13:19 BE8148B25062A0008741050DDC831CD3 272904 ----a-w- C:\WINDOWS\Sysnative\igfxCPL.cpl 2016-05-05 08:13:19 B4607D004BAC24D0204FB60FC5A28D48 28168 ----a-w- C:\WINDOWS\Sysnative\igfxDILibv2_0.dll 2016-05-05 08:13:19 A93B4E0D9F460480D6273A3D77CBC41B 103944 ----a-w- C:\WINDOWS\Sysnative\igfxCUIServicePS.dll 2016-05-05 08:13:19 A1361355DBA7C761BA4A09BFF0A85D06 302088 ----a-w- C:\WINDOWS\Sysnative\igfxDI.dll 2016-05-05 08:13:19 99381DBFE7D1EC55EBFFC818D5B4C261 2044424 ----a-w- C:\WINDOWS\Sysnative\igfxcmjit64.dll 2016-05-05 08:13:19 8D48192378591B7020555BE0F2053F7D 202248 ----a-w- C:\WINDOWS\Sysnative\igfx11cmrt64.dll 2016-05-05 08:13:19 78D2D935BE4765FDB8161552F2522181 87048 ----a-w- C:\WINDOWS\Sysnative\igfxDHLibv2_0.dll 2016-05-05 08:13:19 6A9C613D0F5F9676D128F39B63ACE45B 337888 ----a-w- C:\WINDOWS\Sysnative\igfxCUIService.exe 2016-05-05 08:13:19 48A9AF61097634E154ED4F919072DD06 690696 ----a-w- C:\WINDOWS\Sysnative\igfxDH.dll 2016-05-05 08:13:19 2645C797FA81819282FFA26F1B1743B2 77320 ----a-w- C:\WINDOWS\Sysnative\igfxDHLib.dll 2016-05-05 08:13:17 DF1172DFB2923614BC532B49E9CC37C9 4702968 ----a-w- C:\WINDOWS\Sysnative\igdusc64.dll 2016-05-05 08:13:13 A0173A39C31CAB18600FB1A950CF771A 11157656 ----a-w- C:\WINDOWS\Sysnative\igdumdim64.dll 2016-05-05 08:13:13 375E39F22DCD410825D568BB5C74429F 2004488 ----a-w- C:\WINDOWS\Sysnative\igdrcl64.dll 2016-05-05 08:13:12 F77B6AE1E631056A4FA530D5386C3A43 480592 ----a-w- C:\WINDOWS\Sysnative\igdmd64.dll 2016-05-05 08:13:11 CC18A47914689EB82DA0ACF013FBCA5C 383496 ----a-w- C:\WINDOWS\Sysnative\igdbcl64.dll 2016-05-05 08:13:11 B6E428E02148357877B157CC0639DA9E 179720 ----a-w- C:\WINDOWS\Sysnative\igdail64.dll 2016-05-05 08:13:11 3E492F4CC8B2A725C51B68086593CCA1 238600 ----a-w- C:\WINDOWS\Sysnative\igdde64.dll 2016-05-05 08:13:11 12CB3AE81052C37215BA30B3CF0F3521 22922760 ----a-w- C:\WINDOWS\Sysnative\igdfcl64.dll 2016-05-05 08:13:10 D9C74EDF95BE6C7DFC8B363148CF3BD1 12442464 ----a-w- C:\WINDOWS\Sysnative\igd10iumd64.dll 2016-05-05 08:13:08 E1613D873D534D3F93D324D9A8ABA749 8531456 ----a-w- C:\WINDOWS\Sysnative\ig7icd64.dll 2016-05-05 08:13:06 FF4C71A9C9E979093B0C6EF11FF1EB4D 4398048 ----a-w- C:\WINDOWS\Sysnative\Gfxv2_0.exe 2016-05-05 08:13:06 D37320565FACC2334FBC7993D6FAD4FA 418264 ----a-w- C:\WINDOWS\Sysnative\CustomModeAppv2_0.exe 2016-05-05 08:13:06 C8BDEA886BE61A97D11C573A9D71AFF1 564696 ----a-w- C:\WINDOWS\Sysnative\DPTopologyApp.exe 2016-05-05 08:13:06 B5D649BC07BE8C33245A0E8DB3673071 978400 ----a-w- C:\WINDOWS\Sysnative\GfxUIEx.exe 2016-05-05 08:13:06 8E7709B5E45FB5AAADB8AF8D3036001D 564192 ----a-w- C:\WINDOWS\Sysnative\DPTopologyAppv2_0.exe 2016-05-05 08:13:06 899E708E589C09700BFF1C73CB7D7002 895 ----a-w- C:\WINDOWS\Sysnative\Gfxv2_0.exe.config 2016-05-05 08:13:06 899E708E589C09700BFF1C73CB7D7002 895 ----a-w- C:\WINDOWS\Sysnative\DPTopologyAppv2_0.exe.config 2016-05-05 08:13:06 899E708E589C09700BFF1C73CB7D7002 895 ----a-w- C:\WINDOWS\Sysnative\CustomModeAppv2_0.exe.config 2016-05-05 08:13:06 69EA6698680C130BB37C7CE74B70E583 111624 ----a-w- C:\WINDOWS\Sysnative\IccLibDll_x64.dll 2016-05-05 08:13:06 59075B2A63DF6A568123218BF4DC2696 889 ----a-w- C:\WINDOWS\Sysnative\Gfxv4_0.exe.config 2016-05-05 08:13:06 59075B2A63DF6A568123218BF4DC2696 889 ----a-w- C:\WINDOWS\Sysnative\DPTopologyApp.exe.config 2016-05-05 08:13:06 59075B2A63DF6A568123218BF4DC2696 889 ----a-w- C:\WINDOWS\Sysnative\CustomModeApp.exe.config 2016-05-05 08:13:06 2EE4EAD74F81CF031A152AC139334B1A 418784 ----a-w- C:\WINDOWS\Sysnative\CustomModeApp.exe 2016-05-05 08:13:06 2DDE65958D6BE538ABBE8B0EE1A9828D 175072 ----a-w- C:\WINDOWS\Sysnative\difx64.exe 2016-05-05 08:13:06 0E2B7D35E3DDD21AF04FB4D98C2BCF7F 316245 ----a-w- C:\WINDOWS\Sysnative\DisplayAudiox64.cab 2016-05-05 08:13:06 01D3E316E0698FA10AB2DB1C6A168F1A 4401632 ----a-w- C:\WINDOWS\Sysnative\Gfxv4_0.exe 2016-05-05 08:12:58 EB87A6767DD0FA015B12D2794A8AFAD9 232712 ----a-w- C:\WINDOWS\Sysnative\SRSTSH64.dll 2016-05-05 08:12:58 9285E398676D7F0844FAC985D6CAE0D9 176480 ----a-w- C:\WINDOWS\Sysnative\SRSWOW64.dll 2016-05-05 08:12:58 83355A91F58A6CE21306A8EB3700989C 220136 ----a-w- C:\WINDOWS\Sysnative\SRSHP64.dll 2016-05-05 08:12:58 6C897FCD7572FB61E9E05ADB2FF92B92 545824 ----a-w- C:\WINDOWS\Sysnative\SRSTSX64.dll 2016-05-05 08:12:55 937DB60EFC94893F5B1AC1A663D10946 2935544 ----a-w- C:\WINDOWS\Sysnative\RtPgEx64.dll 2016-05-05 08:12:55 7D1D1E76256D04C50B5D7C717BB8BFBB 174632 ----a-w- C:\WINDOWS\Sysnative\RtkXInterface64.dll 2016-05-05 08:12:55 3A0ED30EC203AB405AC6C65186219C42 2719992 ----a-w- C:\WINDOWS\Sysnative\RTSnMg64.cpl 2016-05-05 08:12:55 35A0CE6C3AF3186E0B1059E0F6E61989 355496 ----a-w- C:\WINDOWS\Sysnative\RtlCPAPI64.dll 2016-05-05 08:12:51 2BB1BC151D5A79183E8F8F8A4461BE17 32392 ----a-w- C:\WINDOWS\Sysnative\RtkCoLDR64.dll 2016-05-05 08:12:50 48B45BC094776A2D95938A5A9AC39123 187280 ----a-w- C:\WINDOWS\Sysnative\RtkCfg64.dll 2016-05-05 08:12:49 EAD62F2BDBA154861F5501AC05EA020C 120720 ----a-w- C:\WINDOWS\Sysnative\RTEEL64A.dll 2016-05-05 08:12:49 99153C3BA37648A92D57F8C8D5AE905C 97976 ----a-w- C:\WINDOWS\Sysnative\RTEEG64A.dll 2016-05-05 08:12:49 86FC3DA55EDBC0116B750FFFDB85D6A1 399464 ----a-w- C:\WINDOWS\Sysnative\RTEEP64A.dll 2016-05-05 08:12:49 57AB299130B2AA8AD7A2AFC1F114BEAA 225504 ----a-w- C:\WINDOWS\Sysnative\RTEED64A.dll 2016-05-05 08:12:49 4F29264133616A93C78182916890451E 3309264 ----a-w- C:\WINDOWS\Sysnative\RtkApi64.dll 2016-05-05 08:12:48 F42A543DEC39E1D9901340AFB93BDD43 659872 ----a-w- C:\WINDOWS\Sysnative\RtDataProc64.dll 2016-05-05 08:12:48 EDE434CD0A6CDE4FB38DD777DD580BD5 333288 ----a-w- C:\WINDOWS\Sysnative\RP3DHT64.dll 2016-05-05 08:12:48 A5C241E09F28CD949410C598DB3733C8 333288 ----a-w- C:\WINDOWS\Sysnative\RP3DAA64.dll 2016-05-05 08:12:48 0BCA2BE0556ACF03602EA10142BBB4F5 1351176 ----a-w- C:\WINDOWS\Sysnative\RTCOM64.dll 2016-05-05 08:12:47 F6F6ACDEEA1FAC43D67D8B49C6029B0A 2999808 ----a-w- C:\WINDOWS\Sysnative\RltkAPO64.dll 2016-05-05 08:12:46 F65B296395303FC47F898BD0919AC9E4 161952 ----a-w- C:\WINDOWS\Sysnative\R4EEL64A.dll 2016-05-05 08:12:46 CF5DE40D23D46CB8DE4E51ED13AB24B8 460440 ----a-w- C:\WINDOWS\Sysnative\R4EED64A.dll 2016-05-05 08:12:46 61CB98C77EF49813AFFDBA348648736E 1766136 ----a-w- C:\WINDOWS\Sysnative\RCoInstII64.dll 2016-05-05 08:12:46 56AB869A5CCF01290FBBD43518D5E4B7 94168 ----a-w- C:\WINDOWS\Sysnative\R4EEG64A.dll 2016-05-05 08:12:46 4BDE19772FD3EEF42B4455470AC43EBD 7181616 ----a-w- C:\WINDOWS\Sysnative\R4EEP64A.dll 2016-05-05 08:12:46 42516A3156BADBF03D5ADECAAFD6A85B 144184 ----a-w- C:\WINDOWS\Sysnative\R4EEA64A.dll 2016-05-05 08:12:46 23BBC5F5C35C8C8E1A5BEA8529A04C87 72130584 ----a-w- C:\WINDOWS\Sysnative\RCORES64.dat 2016-05-05 08:12:44 F9EDBA29BC133222B92AE179A49F4DC4 79296 ----a-w- C:\WINDOWS\Sysnative\MBPPCn64.dll 2016-05-05 08:12:44 7F60F79717479FCAA56C551B9AF721AB 422432 ----a-w- C:\WINDOWS\Sysnative\MBWrp64.dll 2016-05-05 08:12:44 39515D07688AD1A5ACD2B146A89D9A09 84048 ----a-w- C:\WINDOWS\Sysnative\MBppld64.dll 2016-05-05 08:12:44 3879C23FA0D3A5281EEB12194442E59D 657304 ----a-w- C:\WINDOWS\Sysnative\MBTHX64.dll 2016-05-05 08:12:43 CA9ECB75AF510B30C5BC86FEDC640C8A 2001056 ----a-w- C:\WINDOWS\Sysnative\MBAPO264.dll 2016-05-05 08:12:43 2AE0CDDF411CA15DBE47E3A359FAC39B 930848 ----a-w- C:\WINDOWS\Sysnative\MBAPO64.dll 2016-05-05 08:12:42 FC06E7B353B32712E71C7AAC2C733A83 692520 ----a-w- C:\WINDOWS\Sysnative\MaxxVolumeSDAPO.dll 2016-05-05 08:12:37 7F8ADC12A84D7C872017F1B32F3F938B 13242880 ----a-w- C:\WINDOWS\Sysnative\MaxxVoiceAPO3064.dll 2016-05-05 08:12:36 B4102FE6B68EC61E9E71FBC4B7C79DB8 212256 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioVienna264.dll 2016-05-05 08:12:36 041177A6CC86570ADB4F51CB82ED552A 1015608 ----a-w- C:\WINDOWS\Sysnative\MaxxVoiceAPO2064.dll 2016-05-05 08:12:31 D58BC0F71762B576B1D2CEFC485A5FB6 3709056 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioMeters64.exe 2016-05-05 08:12:30 B96274E10EDB3CA0F1E7F6D7F391A5AF 2058880 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioEQ64.dll 2016-05-05 08:12:29 F28E8BD57773DA4942C7C1AFFF1787F3 1231248 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioAPO5064.dll 2016-05-05 08:12:29 D242764A692D7011AE904D915A18C54A 1183352 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioAPO4064.dll 2016-05-05 08:12:29 9FAE061B7A12D062991780812EB6B615 693032 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioAPO30.dll 2016-05-05 08:12:29 75BF511287538F1155D1577C8D0333EF 342280 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioAPO20.dll 2016-05-05 08:12:29 6B60DFE00F6864081EC29C8A1D3D96BC 1416832 ----a-w- C:\WINDOWS\Sysnative\MaxxAudioAPO6064.dll 2016-05-05 08:12:25 DD2F36194E3149205AAED2FDE78EE79F 264896 ----a-w- C:\WINDOWS\Sysnative\DTSLFXAPO64.dll 2016-05-05 08:12:25 DA117AF4A3E443D6145E6FAB4B359B16 517464 ----a-w- C:\WINDOWS\Sysnative\DTSNeoPCDLL64.dll 2016-05-05 08:12:25 C57683FAA0083A941FE6373D51087D68 723232 ----a-w- C:\WINDOWS\Sysnative\DTSVoiceClarityDLL64.dll 2016-05-05 08:12:25 B9979C472DD6640F975F756FFD5ED266 1804936 ----a-w- C:\WINDOWS\Sysnative\DTSS2SpeakerDLL64.dll 2016-05-05 08:12:25 906427EB752B8D1CCCDA09855995F667 742536 ----a-w- C:\WINDOWS\Sysnative\DTSSymmetryDLL64.dll 2016-05-05 08:12:25 8D7BF9A2EBE56A6A8178F11E7E1511D2 458016 ----a-w- C:\WINDOWS\Sysnative\DTSLimiterDLL64.dll 2016-05-05 08:12:25 6CC422AEC94E1E7B0176A359841F39AA 1613720 ----a-w- C:\WINDOWS\Sysnative\DTSS2HeadphoneDLL64.dll 2016-05-05 08:12:25 6250ADADF5131D351EADAB6B4306AB2E 263944 ----a-w- C:\WINDOWS\Sysnative\DTSGFXAPONS64.dll 2016-05-05 08:12:25 58F3D02F053BDF12CDEEB6B1F457610C 453848 ----a-w- C:\WINDOWS\Sysnative\DTSGainCompensatorDLL64.dll 2016-05-05 08:12:25 2F54C1DAA74E3A0E6824129099AAAFA3 1530872 ----a-w- C:\WINDOWS\Sysnative\DTSBoostDLL64.dll 2016-05-05 08:12:25 10E62390A2AD87B2FE4E7FFB6EA1117A 264968 ----a-w- C:\WINDOWS\Sysnative\DTSGFXAPO64.dll 2016-05-05 08:12:25 05E4BEB7C7D175A873C75BAF3C815B2D 3269440 ----a-w- C:\WINDOWS\Sysnative\FMAPO64.dll 2016-05-05 08:12:24 1AED24C4903AF8D4D56DCB04B7CC6382 7104888 ----a-w- C:\WINDOWS\Sysnative\DDPP64A.dll 2016-05-05 08:12:24 058B517DD0EE6C0913C5F14BCC54BA7B 759208 ----a-w- C:\WINDOWS\Sysnative\DTSBassEnhancementDLL64.dll 2016-05-05 08:12:23 FD5605A96E4AC7BE9F81D8382E16D862 339136 ----a-w- C:\WINDOWS\Sysnative\DDPO64A.dll 2016-05-05 08:12:22 C16F11A0D653118E4D0D040B2AD05498 128512 ----a-w- C:\WINDOWS\Sysnative\AERTAR64.dll 2016-05-05 08:12:22 7EB011CB243BCB7C406B0614F030879F 283928 ----a-w- C:\WINDOWS\Sysnative\DDPA64.dll 2016-05-05 08:12:22 783D907CFE09B26046623AEF2CD2EC77 588120 ----a-w- C:\WINDOWS\Sysnative\AERTAC64.dll 2016-05-05 08:12:22 6622C412E26D8FD0494D568C6F886CF5 1991784 ----a-w- C:\WINDOWS\Sysnative\DDPD64A.dll 2016-05-05 08:12:22 4F670FBCB38ADF9C18208E72D48B018F 131024 ----a-w- C:\WINDOWS\Sysnative\CONEQMSAPOGUILibrary.dll 2016-05-05 08:12:21 940B032A1CA24A6649B68F1C67254E4C 108696 ----a-w- C:\WINDOWS\Sysnative\RtNicProp64.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2016-05-14 16:16:10 48D8729FACC784900B831212AE56F824 1996640 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2016-05-14 16:15:57 01C01ED15ED56B98088CE1D5A0965E6A 577368 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys 2016-05-14 16:15:46 CFFE69B6C276A3418687109EA8AC9E7D 330072 ----a-w- C:\WINDOWS\Sysnative\drivers\pci.sys 2016-05-14 16:15:46 B880BE37452AB1D4AA93845F58EF7960 95072 ----a-w- C:\WINDOWS\Sysnative\drivers\sdport.sys 2016-05-14 16:15:39 A289FE26F5D8B5121D84DDEE6241CC26 954368 ----a-w- C:\WINDOWS\Sysnative\drivers\bthport.sys 2016-05-14 16:15:39 357910142E9285B978689B1DB4EFA00A 393568 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys 2016-05-14 16:15:35 C330883C06E2D4CE4F6982F048265D37 335712 ----a-w- C:\WINDOWS\Sysnative\drivers\fastfat.sys 2016-05-14 16:15:34 E7463CE8579A0418A98BE9BE42C647D7 534872 ----a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2016-05-14 16:15:34 50DFE05C698E9B0A63D95E3D669A105C 638816 ----a-w- C:\WINDOWS\Sysnative\drivers\fvevol.sys 2016-05-14 16:15:31 C0752D58193603B6ED762B4027C65E1B 155136 ----a-w- C:\WINDOWS\Sysnative\drivers\hidclass.sys 2016-05-14 16:15:30 82D3B1F4D80057826AA649D78147DE36 63488 ----a-w- C:\WINDOWS\Sysnative\drivers\UcmCx.sys 2016-05-14 16:15:30 2A87EA182EA333D79AA0B03833EA67F2 131424 ----a-w- C:\WINDOWS\Sysnative\drivers\ufxsynopsys.sys 2016-05-14 16:15:29 8F2523C9D8F1448FF2156452AF60FA00 87552 ----a-w- C:\WINDOWS\Sysnative\drivers\filecrypt.sys 2016-05-14 16:15:29 67B9684B8272D5EBD1CCBB1DBD425EC8 99680 ----a-w- C:\WINDOWS\Sysnative\drivers\pdc.sys 2016-05-14 16:15:27 4AAD6547953D373A1EB5B2DF583D868B 67072 ----a-w- C:\WINDOWS\Sysnative\drivers\usbser.sys 2016-05-14 16:15:14 A0718F7B48F08347800FB29844A6AF91 112640 ----a-w- C:\WINDOWS\Sysnative\drivers\bthenum.sys 2016-05-14 16:15:14 281439D412441B2A39B63D20EE3E5D88 84992 ----a-w- C:\WINDOWS\Sysnative\drivers\BTHUSB.SYS 2016-05-14 08:34:00 1A490555FD330CA2764D89191177C867 285696 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb10.sys 2016-05-14 08:33:52 083A727D784009F9CCFB120C7841B7AF 2403680 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2016-05-14 08:33:43 E582DA849A58524E645545FB68B6625D 1152864 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2016-05-14 08:33:43 19BD8A88AAC580592668B070AC0727D9 2152280 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2016-05-14 08:33:40 935823F79CBEDB91637B63D37E3A5A36 148480 ----a-w- C:\WINDOWS\Sysnative\drivers\dfsc.sys 2016-05-14 08:33:40 0B3B0C1D86050355676640488FA897D3 430944 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2016-05-14 08:33:39 2BC2E99623119521EEF7910A11D0FDE0 694784 ----a-w- C:\WINDOWS\Sysnative\drivers\WdiWiFi.sys 2016-05-14 08:33:37 E3C82823B22463BC38AA4F8ADA852624 104960 ----a-w- C:\WINDOWS\Sysnative\drivers\rasl2tp.sys 2016-05-14 08:33:37 AA4CD20708B7E0412A5316D7E2875103 530432 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2016-05-14 08:33:37 A4411C522D41707D5BCA817A5BB9E30B 114688 ----a-w- C:\WINDOWS\Sysnative\drivers\bridge.sys 2016-05-14 08:33:36 EDDB0D726DBECDFC1DBCC6DB464E5A13 146272 ----a-w- C:\WINDOWS\Sysnative\drivers\appid.sys 2016-05-14 08:33:35 63C3F74DC398A1C1A77E39DFB9C312CA 1089888 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2016-05-14 08:33:31 3B866F8CB10719A5AF9E410B1B149714 605440 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2016-05-14 08:33:31 28B8E1C6CBCF9FFE2FABFF3160C26ADF 258912 ----a-w- C:\WINDOWS\Sysnative\drivers\ufx01000.sys 2016-05-14 08:33:30 F279536122B83FD0D8E158AA753E1B7C 238592 ----a-w- C:\WINDOWS\Sysnative\drivers\xboxgip.sys 2016-05-14 08:33:30 DA0807D87A62D076C29C4E30F1E84F46 26112 ----a-w- C:\WINDOWS\Sysnative\drivers\xinputhid.sys 2016-05-14 08:33:30 B24408471C1BCB17FC44F5B47EA8DEA3 277856 ----a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2016-05-14 08:33:30 AEEF76F938188EBF27DF70C1806877F2 181248 ----a-w- C:\WINDOWS\Sysnative\drivers\rfcomm.sys 2016-05-14 08:33:30 9E9D58F5E1702955B2F4D62996F80E8E 378208 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2016-05-14 08:33:30 8949F77132A4F8F3BA17C6727099F002 127840 ----a-w- C:\WINDOWS\Sysnative\drivers\USBSTOR.SYS 2016-05-14 08:33:30 8359F776CA899E761852F2293B724EAE 185184 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2016-05-14 08:33:30 469441BAE3FF8A16826FC62C51EF5E18 563552 ----a-w- C:\WINDOWS\Sysnative\drivers\acpi.sys 2016-05-14 08:33:30 3B3BF88BB54CB9A18DE1EF07292B5A3D 245760 ----a-w- C:\WINDOWS\Sysnative\drivers\BthLEEnum.sys 2016-05-14 08:33:30 249A563C48DFD9E42A37587653E003BB 83968 ----a-w- C:\WINDOWS\Sysnative\drivers\serial.sys 2016-05-14 08:33:30 0731E8F4D8D3B8D3FD98A46A8ABFE0A0 333824 ----a-w- C:\WINDOWS\Sysnative\drivers\portcls.sys 2016-05-14 07:47:43 DE8F1C08787A9C00BCCE541545372ABA 31095 ----a-w- C:\WINDOWS\Sysnative\drivers\rtwavesEFX.dat 2016-05-14 07:47:43 B999812ACF16518997420F1A821170B8 10945 ----a-w- C:\WINDOWS\Sysnative\drivers\rtwavesMFX.dat 2016-05-14 07:47:43 797996BCBD6BF2F59A457E52CFE259F1 849474 ----a-w- C:\WINDOWS\Sysnative\drivers\rtwavesskdy.dat 2016-05-14 07:47:39 7ACFCDA199BB242556933AB53572948C 188557 ----a-w- C:\WINDOWS\Sysnative\drivers\RTWAVES40.dat 2016-05-14 07:46:54 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2016-05-14 07:46:38 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2016-05-14 07:46:32 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_SynTP_01011.Wdf 2016-05-05 08:13:12 9CE4D3A79D3180AC5A141E2F7E7137F4 3811288 ----a-w- C:\WINDOWS\Sysnative\drivers\igdkmd64.sys 2016-05-05 08:12:55 7D7FBC9504575D97885A858EA93684F5 5804772 ----a-w- C:\WINDOWS\Sysnative\drivers\rtvienna.dat 2016-05-05 08:12:54 48AC5F706780BCC34811EA89A0727189 4518136 ----a-w- C:\WINDOWS\Sysnative\drivers\RTKVHD64.sys 2016-05-05 08:12:48 2969708DAC7DB9A4FDC2DD706FDE1096 2880873 ----a-w- C:\WINDOWS\Sysnative\drivers\RTAIODAT.DAT 2016-05-05 08:12:21 EFC1803A4EED1E15A698721D873931B9 896744 ----a-w- C:\WINDOWS\Sysnative\drivers\rt640x64.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2016-05-14 08:13:02 -------- d-----w- C:\Program Files\Reference Assemblies 2016-05-14 08:13:02 -------- d-----w- C:\Program Files\MSBuild 2016-05-14 07:47:21 -------- d-----w- C:\Program Files\Realtek 2016-05-14 07:47:08 -------- d-----w- C:\Program Files\Intel 2016-05-14 07:46:21 -------- d-----w- C:\Program Files\Synaptics 2016-05-09 19:28:50 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2016-05-16 14:05:07 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2016-05-14 08:13:02 -------- d-----w- C:\PROGRA~2\Reference Assemblies 2016-05-14 08:13:02 -------- d-----w- C:\PROGRA~2\MSBuild 2016-05-14 07:47:02 -------- d-----w- C:\PROGRA~2\COMMON~1\Intel ======= C: ===== ====== C:\Users\Cecile\AppData\Roaming ====== 2016-05-16 07:00:26 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\AvgSetupLog 2016-05-14 08:47:39 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft 2016-05-14 08:30:00 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\DataSharing 2016-05-14 08:08:50 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages 2016-05-14 08:04:31 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Avg 2016-05-14 08:01:11 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg 2016-05-14 07:50:43 -------- d-s---r- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 2016-05-14 07:50:43 -------- d-----w- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2016-05-14 07:50:43 -------- d-----w- C:\Users\Cecile\AppData\Roaming 2016-05-14 07:50:43 -------- d-----w- C:\Users\Cecile\AppData\Local\Temp 2016-05-14 07:50:43 -------- d-----w- C:\Users\Cecile\AppData\Local\Microsoft 2016-05-14 07:50:43 -------- d-----w- C:\Users\Cecile\AppData\Local 2016-05-14 07:50:43 -------- d-----r- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2016-05-14 07:50:43 -------- d-----r- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2016-05-14 07:50:43 -------- d-----r- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2016-05-14 07:50:43 -------- d-----r- C:\Users\Cecile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs 2016-05-14 07:50:42 -------- d-----w- C:\Users\Administrator\AppData\Roaming 2016-05-14 07:50:42 -------- d-----w- C:\Users\Administrator\AppData\Local\Temp 2016-05-14 07:50:42 -------- d-----w- C:\Users\Administrator\AppData\Local\Microsoft 2016-05-14 07:50:42 -------- d-----w- C:\Users\Administrator\AppData\Local 2016-05-13 20:35:10 861C9A5CD23911419B860C57EF1590FE 70040764 ----a-w- C:\Users\Cecile\AppData\Local\Temp.zip ====== C:\Users\Cecile ====== 2016-05-16 14:04:53 -------- d-----w- C:\Users\Cecile\.oracle_jre_usage 2016-05-16 14:02:53 34CC302C512B0B4F6485F324F6171ED3 738368 ----a-w- C:\Users\Cecile\Downloads\JavaSetup8u91.exe 2016-05-14 08:17:37 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Cecile\ntuser.ini 2016-05-14 07:50:43 -------- d--h--w- C:\Users\Cecile\AppData 2016-05-14 07:50:42 -------- d--h--w- C:\Users\Administrator\AppData 2016-05-14 07:47:39 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\ProgramData\DP45977C.lfl 2016-05-08 06:32:29 56427CD7A2529AEAB14A7FEA8F945554 6882192 ----a-w- C:\Users\Cecile\Downloads\ccsetup517 (2).exe 2016-05-08 06:32:18 56427CD7A2529AEAB14A7FEA8F945554 6882192 ----a-w- C:\Users\Cecile\Downloads\ccsetup517 (1).exe 2016-05-08 06:32:14 56427CD7A2529AEAB14A7FEA8F945554 6882192 ----a-w- C:\Users\Cecile\Downloads\ccsetup517.exe ====== C: exe-files == 2016-05-16 14:04:37 DE2D3B374C6EFA769028B811A1203FB1 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\jjs.exe 2016-05-16 14:04:37 D8065554BA4D664A55F57F76E1B4F9E3 77888 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2launcher.exe 2016-05-16 14:04:37 D26A12768BFA19B5565F82DF16B85192 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\kinit.exe 2016-05-16 14:04:37 D117B71E46E9156F1C88146E6F5EDB03 191552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaw.exe 2016-05-16 14:04:37 CCCE1ACFFBFCB34B5F3CD157A78522F8 68672 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\javacpl.exe 2016-05-16 14:04:37 BA45896DE4744CC7AB7EAECF59D6758C 16448 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\orbd.exe 2016-05-16 14:04:37 B6AAFABF90E5FE4683690793F2963388 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\keytool.exe 2016-05-16 14:04:37 AFD756C629D5527D1CFE3BE9D6EBB416 30784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\jabswitch.exe 2016-05-16 14:04:37 AFB89E0B881A2F9F0135AB8984B9FC53 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\pack200.exe 2016-05-16 14:04:37 76E017B33C2C0F72CBBDB77251B00658 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\rmid.exe 2016-05-16 14:04:37 6C58D1081EC589813A197E81CA5CB85C 159296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\unpack200.exe 2016-05-16 14:04:37 56B31942246558D41498912CA9868DF2 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\servertool.exe 2016-05-16 14:04:37 38E67313028C22B78E26D7860494015E 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\policytool.exe 2016-05-16 14:04:37 2EBB23647400B52B56815FEBC59DCCF7 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\ktab.exe 2016-05-16 14:04:37 2C02E97DF732010028B565DA92F3CB0F 51776 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssvagent.exe 2016-05-16 14:04:37 2ABC222E2C3E728136516D6390BDF447 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\klist.exe 2016-05-16 14:04:37 28AC474C021D764DF31736CB9B47DD88 191040 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\java.exe 2016-05-16 14:04:37 1F3D5C9A2D230CDE5B2120AA0F3721B6 16448 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\tnameserv.exe 2016-05-16 14:04:37 1CB2916C0CC541F2A4AC28DAC03F1833 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\rmiregistry.exe 2016-05-16 14:04:37 0BA64EAF4F4080DA2FB79DCC05CB2A14 268352 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe 2016-05-16 14:04:37 09EABD6F36ECC85644DCE5C3BD709F29 15936 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\bin\java-rmi.exe 2016-05-14 16:15:29 E004E3D268827C6F2E500411D95DF85E 493056 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2016-05-14 16:15:28 97FF7539F4E46E86A802CD5876549ACA 476160 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2016-05-14 08:34:01 09D8EBC01776C2D117918993EDDC19B2 1474560 ----a-w- C:\Program Files\Windows Media Player\wmpnetwk.exe 2016-05-14 08:23:34 27C325E1EB78A41E767802D481C46EA0 8892608 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\OneDriveSetup.exe 2016-05-14 08:23:34 27C325E1EB78A41E767802D481C46EA0 8892608 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\OneDriveSetup.exe 2016-05-14 08:23:11 AE03FFEAAB0963E119CD7AF8032FB054 493256 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\OneDriveStandaloneUpdater.exe 2016-05-14 08:23:03 7AA1222AA05D17D4A727E52786AE7572 178888 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\FileSyncConfig.exe 2016-05-14 08:22:57 F75A4E3FDA266B6E4A9FC3075AE3D4C2 176840 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\FileCoAuth.exe 2016-05-14 06:36:27 FE68FB8AB9C418119D3DE8277B5797A9 1056504 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\uninstall.exe 2016-05-14 06:36:27 A03A95B389479B2ADE3A288FA2EA11D1 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeSvc2.exe 2016-05-14 06:36:27 95ACD8E9E6A81F0E0BB87C239DD4C55F 558616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeVirusScanner.exe 2016-05-14 06:36:27 9176E7BB1D046E91155DF27575A1CEFB 470448 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeTHlp64.exe 2016-05-14 06:36:27 6FA5A7AE9FE34171710429989A7DE483 505616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeTHlp.exe 2016-05-14 06:36:27 62EDC07EDF7C015DB1A41D543FA9A944 316488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iStart.exe 2016-05-14 06:36:27 450482B89EDA1D36BE209BF71B463A89 308744 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeBugReport.exe 2016-05-14 06:36:27 388264596C2E9157B71AAC28BE13356C 369488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeTray.exe 2016-05-14 06:36:27 11F6F9216D8F77EAC196B07D66E819EA 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafeSvc.exe 2016-05-14 06:36:26 EC7210A6E0806CFDE79565952F3E84CC 290936 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\ipcdl.exe 2016-05-14 06:36:26 5E6C3071AA5FE8626B807DB3327E6B4E 708360 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iSafe.exe 2016-05-14 06:36:25 A9BC31DC656F6854073C9E6BA311448E 890584 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\iDesk.exe 2016-05-14 06:36:25 5D0AF217AE5A09DB9264A9100017ABF0 451072 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\bugreport.exe 2016-05-14 06:17:00 8403D7F3CE4A175AE47FC4F27E472AE9 348432 ----a-w- C:\Program Files (x86)\AVG\Av\avgndisa.exe 2016-05-13 21:50:47 483C10E4803990419AE8AABE2ABB8413 78608 ----a-w- C:\ProgramData\AVG\Setup\av\avguirux.exe 2016-05-13 21:50:47 109FB80EEFB61CB32703A2CBCC94C1CE 6059744 ----a-w- C:\ProgramData\AVG\Setup\av\avgmfapx.exe 2016-05-13 21:46:14 076FE44992359FEA654AD3CB04A29E6E 1787664 ----a-w- C:\Program Files (x86)\AVG\Setup\avgsetupwrkx.exe 2016-05-13 21:46:12 539A84DED87DC5E6FD047192004334ED 704272 ----a-w- C:\Program Files (x86)\AVG\Setup\avgntdumpx.exe 2016-05-13 21:46:12 1EDFFD3A693CC4CCE0A50D54CB23F686 3288848 ----a-w- C:\Program Files (x86)\AVG\Setup\avgsetupx.exe 2016-05-13 21:26:58 FE68FB8AB9C418119D3DE8277B5797A9 1056504 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\uninstall.exe 2016-05-13 21:26:58 EC7210A6E0806CFDE79565952F3E84CC 290936 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\ipcdl.exe 2016-05-13 21:26:58 A9BC31DC656F6854073C9E6BA311448E 890584 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iDesk.exe 2016-05-13 21:26:58 A03A95B389479B2ADE3A288FA2EA11D1 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeSvc2.exe 2016-05-13 21:26:58 95ACD8E9E6A81F0E0BB87C239DD4C55F 558616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeVirusScanner.exe 2016-05-13 21:26:58 9176E7BB1D046E91155DF27575A1CEFB 470448 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeTHlp64.exe 2016-05-13 21:26:58 6FA5A7AE9FE34171710429989A7DE483 505616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeTHlp.exe 2016-05-13 21:26:58 62EDC07EDF7C015DB1A41D543FA9A944 316488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iStart.exe 2016-05-13 21:26:58 5E6C3071AA5FE8626B807DB3327E6B4E 708360 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafe.exe 2016-05-13 21:26:58 5D0AF217AE5A09DB9264A9100017ABF0 451072 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\bugreport.exe 2016-05-13 21:26:58 450482B89EDA1D36BE209BF71B463A89 308744 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeBugReport.exe 2016-05-13 21:26:58 388264596C2E9157B71AAC28BE13356C 369488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeTray.exe 2016-05-13 21:26:58 11F6F9216D8F77EAC196B07D66E819EA 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\iSafeSvc.exe 2016-05-13 20:56:38 FE68FB8AB9C418119D3DE8277B5797A9 1056504 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\uninstall.exe 2016-05-13 20:56:38 EC7210A6E0806CFDE79565952F3E84CC 290936 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\ipcdl.exe 2016-05-13 20:56:38 A9BC31DC656F6854073C9E6BA311448E 890584 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iDesk.exe 2016-05-13 20:56:38 A03A95B389479B2ADE3A288FA2EA11D1 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeSvc2.exe 2016-05-13 20:56:38 95ACD8E9E6A81F0E0BB87C239DD4C55F 558616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeVirusScanner.exe 2016-05-13 20:56:38 9176E7BB1D046E91155DF27575A1CEFB 470448 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeTHlp64.exe 2016-05-13 20:56:38 6FA5A7AE9FE34171710429989A7DE483 505616 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeTHlp.exe 2016-05-13 20:56:38 62EDC07EDF7C015DB1A41D543FA9A944 316488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iStart.exe 2016-05-13 20:56:38 5E6C3071AA5FE8626B807DB3327E6B4E 708360 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafe.exe 2016-05-13 20:56:38 5D0AF217AE5A09DB9264A9100017ABF0 451072 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\bugreport.exe 2016-05-13 20:56:38 450482B89EDA1D36BE209BF71B463A89 308744 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeBugReport.exe 2016-05-13 20:56:38 388264596C2E9157B71AAC28BE13356C 369488 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeTray.exe 2016-05-13 20:56:38 11F6F9216D8F77EAC196B07D66E819EA 118048 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\iSafeSvc.exe 2016-05-09 19:28:51 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Cecile.exe === C: other files == 2016-05-16 14:04:38 CB600FFB53D99A9B07EB870111BA7470 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_91\lib\deploy\ffjcext.zip 2016-05-14 16:16:10 48D8729FACC784900B831212AE56F824 1996640 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2016-05-14 16:16:07 1A944DC7982279E73C4181DD5D50E021 3591168 ----a-w- C:\Windows\System32\win32kfull.sys 2016-05-14 16:15:57 01C01ED15ED56B98088CE1D5A0965E6A 577368 ----a-w- C:\Windows\System32\drivers\dxgmms2.sys 2016-05-14 16:15:56 0676A6C9A6EECA48E14B9AE13B0E3508 1387520 ----a-w- C:\Windows\System32\win32kbase.sys 2016-05-14 16:15:46 CFFE69B6C276A3418687109EA8AC9E7D 330072 ----a-w- C:\Windows\System32\drivers\pci.sys 2016-05-14 16:15:46 B880BE37452AB1D4AA93845F58EF7960 95072 ----a-w- C:\Windows\System32\drivers\sdport.sys 2016-05-14 16:15:39 A289FE26F5D8B5121D84DDEE6241CC26 954368 ----a-w- C:\Windows\System32\drivers\bthport.sys 2016-05-14 16:15:39 357910142E9285B978689B1DB4EFA00A 393568 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2016-05-14 16:15:35 C330883C06E2D4CE4F6982F048265D37 335712 ----a-w- C:\Windows\System32\drivers\fastfat.sys 2016-05-14 16:15:34 E7463CE8579A0418A98BE9BE42C647D7 534872 ----a-w- C:\Windows\System32\drivers\USBHUB3.SYS 2016-05-14 16:15:34 50DFE05C698E9B0A63D95E3D669A105C 638816 ----a-w- C:\Windows\System32\drivers\fvevol.sys 2016-05-14 16:15:31 C0752D58193603B6ED762B4027C65E1B 155136 ----a-w- C:\Windows\System32\drivers\hidclass.sys 2016-05-14 16:15:30 82D3B1F4D80057826AA649D78147DE36 63488 ----a-w- C:\Windows\System32\drivers\UcmCx.sys 2016-05-14 16:15:30 2A87EA182EA333D79AA0B03833EA67F2 131424 ----a-w- C:\Windows\System32\drivers\ufxsynopsys.sys 2016-05-14 16:15:29 8F2523C9D8F1448FF2156452AF60FA00 87552 ----a-w- C:\Windows\System32\drivers\filecrypt.sys 2016-05-14 16:15:29 67B9684B8272D5EBD1CCBB1DBD425EC8 99680 ----a-w- C:\Windows\System32\drivers\pdc.sys 2016-05-14 16:15:27 4AAD6547953D373A1EB5B2DF583D868B 67072 ----a-w- C:\Windows\System32\drivers\usbser.sys 2016-05-14 16:15:14 A0718F7B48F08347800FB29844A6AF91 112640 ----a-w- C:\Windows\System32\drivers\bthenum.sys 2016-05-14 16:15:14 281439D412441B2A39B63D20EE3E5D88 84992 ----a-w- C:\Windows\System32\drivers\BTHUSB.SYS 2016-05-14 08:34:00 1A490555FD330CA2764D89191177C867 285696 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2016-05-14 08:33:52 083A727D784009F9CCFB120C7841B7AF 2403680 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2016-05-14 08:33:43 E582DA849A58524E645545FB68B6625D 1152864 ----a-w- C:\Windows\System32\drivers\ndis.sys 2016-05-14 08:33:43 19BD8A88AAC580592668B070AC0727D9 2152280 ----a-w- C:\Windows\System32\drivers\ntfs.sys 2016-05-14 08:33:40 935823F79CBEDB91637B63D37E3A5A36 148480 ----a-w- C:\Windows\System32\drivers\dfsc.sys 2016-05-14 08:33:40 0B3B0C1D86050355676640488FA897D3 430944 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2016-05-14 08:33:39 2BC2E99623119521EEF7910A11D0FDE0 694784 ----a-w- C:\Windows\System32\drivers\WdiWiFi.sys 2016-05-14 08:33:37 E3C82823B22463BC38AA4F8ADA852624 104960 ----a-w- C:\Windows\System32\drivers\rasl2tp.sys 2016-05-14 08:33:37 AA4CD20708B7E0412A5316D7E2875103 530432 ----a-w- C:\Windows\System32\drivers\nwifi.sys 2016-05-14 08:33:37 A4411C522D41707D5BCA817A5BB9E30B 114688 ----a-w- C:\Windows\System32\drivers\bridge.sys 2016-05-14 08:33:36 EDDB0D726DBECDFC1DBCC6DB464E5A13 146272 ----a-w- C:\Windows\System32\drivers\appid.sys 2016-05-14 08:33:35 63C3F74DC398A1C1A77E39DFB9C312CA 1089888 ----a-w- C:\Windows\System32\drivers\http.sys 2016-05-14 08:33:31 3B866F8CB10719A5AF9E410B1B149714 605440 ----a-w- C:\Windows\System32\drivers\cng.sys 2016-05-14 08:33:31 28B8E1C6CBCF9FFE2FABFF3160C26ADF 258912 ----a-w- C:\Windows\System32\drivers\ufx01000.sys 2016-05-14 08:33:30 F279536122B83FD0D8E158AA753E1B7C 238592 ----a-w- C:\Windows\System32\drivers\xboxgip.sys 2016-05-14 08:33:30 DA0807D87A62D076C29C4E30F1E84F46 26112 ----a-w- C:\Windows\System32\drivers\xinputhid.sys 2016-05-14 08:33:30 B24408471C1BCB17FC44F5B47EA8DEA3 277856 ----a-w- C:\Windows\System32\drivers\sdbus.sys 2016-05-14 08:33:30 AEEF76F938188EBF27DF70C1806877F2 181248 ----a-w- C:\Windows\System32\drivers\rfcomm.sys 2016-05-14 08:33:30 9E9D58F5E1702955B2F4D62996F80E8E 378208 ----a-w- C:\Windows\System32\drivers\USBXHCI.SYS 2016-05-14 08:33:30 8949F77132A4F8F3BA17C6727099F002 127840 ----a-w- C:\Windows\System32\drivers\USBSTOR.SYS 2016-05-14 08:33:30 8359F776CA899E761852F2293B724EAE 185184 ----a-w- C:\Windows\System32\drivers\dumpsd.sys 2016-05-14 08:33:30 469441BAE3FF8A16826FC62C51EF5E18 563552 ----a-w- C:\Windows\System32\drivers\acpi.sys 2016-05-14 08:33:30 3B3BF88BB54CB9A18DE1EF07292B5A3D 245760 ----a-w- C:\Windows\System32\drivers\BthLEEnum.sys 2016-05-14 08:33:30 249A563C48DFD9E42A37587653E003BB 83968 ----a-w- C:\Windows\System32\drivers\serial.sys 2016-05-14 08:33:30 0731E8F4D8D3B8D3FD98A46A8ABFE0A0 333824 ----a-w- C:\Windows\System32\drivers\portcls.sys 2016-05-14 08:24:37 F7D4D187D8F3490C11F6E4D7AED2B72D 56756 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prnport.vbs 2016-05-14 08:24:37 C36D1285B62C6739B465A285148E4000 51462 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prnqctl.vbs 2016-05-14 08:24:37 AB328741766A47CACE8978A24260C51A 7418 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\pubprn.vbs 2016-05-14 08:24:37 96289191763ACF8E4AB69F622262B15F 51312 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prndrvr.vbs 2016-05-14 08:24:37 816213C95FC12D011BF789213E1CC973 81048 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prnmngr.vbs 2016-05-14 08:24:37 31D7079AF27F244E6AA5B7A7C8FE75F3 105940 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prncnfg.vbs 2016-05-14 08:24:37 03E9BADC32A52E3CB44E4277803CFFF9 69882 ----a-w- C:\Windows\SysWOW64\Printing_Admin_Scripts\en-US\prnjobs.vbs 2016-05-14 08:24:30 F7D4D187D8F3490C11F6E4D7AED2B72D 56756 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prnport.vbs 2016-05-14 08:24:30 C36D1285B62C6739B465A285148E4000 51462 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prnqctl.vbs 2016-05-14 08:24:30 AB328741766A47CACE8978A24260C51A 7418 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\pubprn.vbs 2016-05-14 08:24:30 96289191763ACF8E4AB69F622262B15F 51312 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prndrvr.vbs 2016-05-14 08:24:30 816213C95FC12D011BF789213E1CC973 81048 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prnmngr.vbs 2016-05-14 08:24:30 31D7079AF27F244E6AA5B7A7C8FE75F3 105940 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prncnfg.vbs 2016-05-14 08:24:30 03E9BADC32A52E3CB44E4277803CFFF9 69882 ----a-w- C:\Windows\System32\Printing_Admin_Scripts\en-US\prnjobs.vbs 2016-05-14 08:22:55 8CF4163521FDB8E53482003C7EFA7121 5850 ----a-w- C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\CollectOneDriveLogs.bat 2016-05-14 06:52:24 563DA806D302577CEBD1D75A54BE4C14 11847 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\69F054FC.zip 2016-05-14 06:52:03 D728249DFDA3683C2F83595587D277D0 15315 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\69AC6348.zip 2016-05-14 06:36:47 D9782F749DA7DB16D4ADD36AB0C4C74A 67288 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\winxp\iSafeNetFilter.sys 2016-05-14 06:36:47 B3D0539ACB9A047EFF69EE8DD96CA84B 110112 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\iSafeKrnlKit.sys 2016-05-14 06:36:47 A21E9AB248B7D7A419FAF26B265F5CDE 103904 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\iSafeKrnlR3.sys 2016-05-14 06:36:47 9FB02FBA90F6AF59537A30C3DB9777C8 52392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\win7\iSafeNetFilter.sys 2016-05-14 06:36:47 913C4C8247B7839B6043EAF150966A83 59152 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\win7\iSafeNetFilter.sys 2016-05-14 06:36:47 9063E0E53B4AFEB93C491C29B7D6FA44 45032 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\iSafeKrnlMon.sys 2016-05-14 06:36:47 44B6C5BE718752F272EB1A70B0E116BD 61608 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\winxp\iSafeNetFilter.sys 2016-05-14 06:36:47 1694DF1FD10B8A11028BEE72FCC3CFBD 73232 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\iSafeKrnlR3.sys 2016-05-14 06:36:47 093A45CB22A0B33C30314CB3BF21C096 52440 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\iSafeKrnlMon.sys 2016-05-14 06:36:46 FD6F139F87DA6E8E4702DE91A7E649E9 227392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\iSafeKrnl.sys 2016-05-14 06:36:46 BFA3107D0755568C3B55CA3BCB5491C7 262344 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\iSafeKrnl.sys 2016-05-14 06:36:46 9C92380AB20769A6A0DFC1C8FBAF2A22 50280 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\iSafeKrnlBoot.sys 2016-05-14 06:36:46 5661199A34C677FAABF1CBE0D1C41455 97912 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x86\iSafeKrnlKit.sys 2016-05-14 06:36:46 10DAE7BD04498E1EBB7C1212003D4830 55056 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\5D776EB7upgd\sys\x64\iSafeKrnlBoot.sys 2016-05-13 21:26:58 FD6F139F87DA6E8E4702DE91A7E649E9 227392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\iSafeKrnl.sys 2016-05-13 21:26:58 D9782F749DA7DB16D4ADD36AB0C4C74A 67288 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\winxp\iSafeNetFilter.sys 2016-05-13 21:26:58 BFA3107D0755568C3B55CA3BCB5491C7 262344 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\iSafeKrnl.sys 2016-05-13 21:26:58 B3D0539ACB9A047EFF69EE8DD96CA84B 110112 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\iSafeKrnlKit.sys 2016-05-13 21:26:58 A21E9AB248B7D7A419FAF26B265F5CDE 103904 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\iSafeKrnlR3.sys 2016-05-13 21:26:58 9FB02FBA90F6AF59537A30C3DB9777C8 52392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\win7\iSafeNetFilter.sys 2016-05-13 21:26:58 9C92380AB20769A6A0DFC1C8FBAF2A22 50280 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\iSafeKrnlBoot.sys 2016-05-13 21:26:58 913C4C8247B7839B6043EAF150966A83 59152 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\win7\iSafeNetFilter.sys 2016-05-13 21:26:58 9063E0E53B4AFEB93C491C29B7D6FA44 45032 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\iSafeKrnlMon.sys 2016-05-13 21:26:58 5661199A34C677FAABF1CBE0D1C41455 97912 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\iSafeKrnlKit.sys 2016-05-13 21:26:58 44B6C5BE718752F272EB1A70B0E116BD 61608 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\winxp\iSafeNetFilter.sys 2016-05-13 21:26:58 1694DF1FD10B8A11028BEE72FCC3CFBD 73232 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x86\iSafeKrnlR3.sys 2016-05-13 21:26:58 10DAE7BD04498E1EBB7C1212003D4830 55056 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\iSafeKrnlBoot.sys 2016-05-13 21:26:58 093A45CB22A0B33C30314CB3BF21C096 52440 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\391F0D48upgd\sys\x64\iSafeKrnlMon.sys 2016-05-13 20:56:39 FD6F139F87DA6E8E4702DE91A7E649E9 227392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\iSafeKrnl.sys 2016-05-13 20:56:39 D9782F749DA7DB16D4ADD36AB0C4C74A 67288 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\winxp\iSafeNetFilter.sys 2016-05-13 20:56:39 BFA3107D0755568C3B55CA3BCB5491C7 262344 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\iSafeKrnl.sys 2016-05-13 20:56:39 B3D0539ACB9A047EFF69EE8DD96CA84B 110112 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\iSafeKrnlKit.sys 2016-05-13 20:56:39 A21E9AB248B7D7A419FAF26B265F5CDE 103904 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\iSafeKrnlR3.sys 2016-05-13 20:56:39 9FB02FBA90F6AF59537A30C3DB9777C8 52392 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\win7\iSafeNetFilter.sys 2016-05-13 20:56:39 9C92380AB20769A6A0DFC1C8FBAF2A22 50280 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\iSafeKrnlBoot.sys 2016-05-13 20:56:39 913C4C8247B7839B6043EAF150966A83 59152 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\win7\iSafeNetFilter.sys 2016-05-13 20:56:39 9063E0E53B4AFEB93C491C29B7D6FA44 45032 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\iSafeKrnlMon.sys 2016-05-13 20:56:39 5661199A34C677FAABF1CBE0D1C41455 97912 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\iSafeKrnlKit.sys 2016-05-13 20:56:39 44B6C5BE718752F272EB1A70B0E116BD 61608 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\winxp\iSafeNetFilter.sys 2016-05-13 20:56:39 1694DF1FD10B8A11028BEE72FCC3CFBD 73232 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x86\iSafeKrnlR3.sys 2016-05-13 20:56:39 10DAE7BD04498E1EBB7C1212003D4830 55056 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\iSafeKrnlBoot.sys 2016-05-13 20:56:39 093A45CB22A0B33C30314CB3BF21C096 52440 ----a-w- C:\Program Files (x86)\Elex-tech\YAC\tmp\21E13ADBupgd\sys\x64\iSafeKrnlMon.sys 2016-05-13 20:35:10 861C9A5CD23911419B860C57EF1590FE 70040764 ----a-w- C:\Users\Cecile\AppData\Local\Temp.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-2511135133-1098726628-852294653-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "AVG_UI"="C:\Program Files (x86)\AVG\Av\avuirunnerx.exe C:\Program Files (x86)\AVG\Av\avgui.exe" "AvgUi"="C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe /lps=fmw" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Cecile\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX4" "RtHDVBg_PushButton"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /IM" "IAStorIcon"="C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Folders ====================== 2015-04-27 12:58:23 1686 --sha-w- C:\Users\Cecile\AppData\Roaming\Microsoft\LastFlashConfig.wfc ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14/05/2016 19:01] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [22/11/2013 15:36] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\Dell SupportAssistAgent AutoUpdate" [C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{6B2090B5-D95A-45DE-A60F-576C1D6147DA}" [C:\WINDOWS\system32\msfeedssync.exe] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2015-12-21 21:05:52 -------- d-----w- C:\PROGRA~3\Ashampoo 2016-02-13 13:29:13 -------- d-----w- C:\PROGRA~3\USOShared 2016-02-13 13:34:23 -------- d-----w- C:\PROGRA~3\Microsoft OneDrive 2016-05-14 08:16:41 -------- d-sh--we C:\PROGRA~3\Application Data ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default user_pref("browser.startup.homepage", "about:home"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "arthurj8283@gmail.com"="C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default\extensions\arthurj8283@gmail.com" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default - AVG Web TuneUp - %ProfilePath%\extensions\avg@toolbar.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default 258693279212838A6A879A69A17BE215 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll - Shockwave Flash ==== Deleted Firefox Extensions ====================== C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\9we6mpt6.default\extensions\avg@toolbar.xpi deleted ==== Chromium Look ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions chfdnecihphmhljaaejmgoiahnihplgn - No path found[] Google Slides - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo AVG Web TuneUp - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn Google Sheets - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Docs Offline - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi Chrome Web Store Payments - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Cecile\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn deleted successfully C:\Users\Cecile\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" "Search Page"="http://search.delta-homes.com/web/?type=ds&ts=1432911602&z=7464be4cd0d6e9d8ae34f82g6zdc5obtageg3qce1w&from=wpm052932&uid=WDCXWD5000LPVX-75V0TT0_WX71A14L9878A14L9878&q={searchTerms}" "Default_Page_URL"="http://www.mystartsearch.com/?type=hp&ts=1427743649&from=sien&uid=WDCXWD5000LPVX-75V0TT0_WX71A14L9878A14L9878" "Search Bar"="http://www.bing.com/search?q={searchTerms}" "Default_Search_URL"="http://search.delta-homes.com/web/?type=ds&ts=1432911602&z=7464be4cd0d6e9d8ae34f82g6zdc5obtageg3qce1w&from=wpm052932&uid=WDCXWD5000LPVX-75V0TT0_WX71A14L9878A14L9878&q={searchTerms}" "Use Search Asst"="yes" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://www.bing.com/search?q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://www.bing.com/search?q={searchTerms}" "SearchAssistant"="http://www.bing.com/search?q={searchTerms}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.be/" "Use Search Asst"="no" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} - http://www.default-search.net/search?sid=476&aid=135&itype=n&ver=12302&tm=322&src=ds&p={searchTerms} HKLM\Wow6432Node\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}" HKLM\Wow6432Node\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} - http://www.bing.com/search?q={searchTerms} HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{E733165D-CBCF-4FDA-883E-ADEF965B476C}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - No_Url_Value HKCU\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{ED6AAE5A-5FAF-4838-B16C-C2CDF07180D2} - http://www.google.com/search?q={searchTerms} ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\searchengine@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\istart_ffnt@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_searchff@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\sweetsearch@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\defsearchp@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\arthurj8283@gmail.com deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\chfdnecihphmhljaaejmgoiahnihplgn deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Cecile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Cecile\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Cecile\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Cecile\AppData\Local\Microsoft\Windows\INetCache\IE\IBOUKJSN will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Cecile\AppData\Local\Mozilla\Firefox\Profiles\9we6mpt6.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Cecile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=736 folders=208 537942256 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Cecile\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Cecile\AppData\Local\Microsoft\Windows\INetCache\IE\IBOUKJSN" not found ==== EOF on ma 16/05/2016 at 16:54:48,61 ======================