Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Gebruiker on zo 29-05-2016 at 21:27:36,03. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Downloads\zoek (2).exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 29-5-2016 21:29:17 Zoek.exe System Restore Point Created Successfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Reset Hosts File ====================== # Copyright (c) 1993-2006 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost ==== Empty Folders Check ====================== C:\PROGRA~2\Freemake deleted successfully C:\PROGRA~3\Freemake deleted successfully C:\Users\Gebruiker\AppData\Local\ActiveSync deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe C:\WINDOWS\SysWOW64\svchost.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\Gebruiker\AppData\Local\Microsoft\BingSvc\BingSvc.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVAST Software\Avast\avastui.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Windows\SysWOW64\prevhost.exe C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\Users\Gebruiker\Downloads\zoek (2).exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\p6xulgba.default-1464020546821\prefs.js: user_pref("browser.startup.homepage", "http://nos.nl/"); Added to C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\p6xulgba.default-1464020546821\prefs.js: user_pref("browser.startup.homepage", "http://www.google.nl/"); user_pref("browser.newtab.url", "about:newtab"); Deleted from C:\Users\GEBRUI~1\AppData\Roaming\Thunderbird\Profiles\gvxios7q.default\prefs.js: Added to C:\Users\GEBRUI~1\AppData\Roaming\Thunderbird\Profiles\gvxios7q.default\prefs.js: user_pref("browser.startup.homepage", "http://www.google.nl/"); user_pref("browser.newtab.url", "about:newtab"); ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Freemake not found "C:\Windows\Installer\16f72814.msi" not found C:\Users\Gebruiker\ZHPDiag3.exe deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 3968 MB CPU Info: Intel(R) Core(TM) i3-4330 CPU @ 3.50GHz CPU Speed: 3566,1 MHz Sound Card: Luidsprekers (Realtek High Defi | Realtek Digital Output(Optical) | Realtek Digital Output (Realtek | Display Adapters: Intel(R) HD Graphics 4600 | Intel(R) HD Graphics 4600 | Intel(R) HD Graphics 4600 Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1920 X 1080 - 32 bit Network: Network Present Network Adapters: Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (H: | ) H: ATAPI iHAS124 W Ports: COM1 LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 344,8GB | I: 585,9GB Hard Disks - Free: C: 202,7GB | I: 561,7GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 10/28/13 | ALASKA - 1072009 Time Zone: West-Europa (standaardtijd) Motherboard *: ASUSTeK COMPUTER INC. H87M-PRO Country: Nederland Language: NLD ==== System Specs (Software) ====================== Default Browser: Firefox 46.0.1 Internet Explorer Version: 11.306.10586.0 Mozilla Firefox version: 46.0.1 (x86 nl) Google Chrome version: 50.0.2661.102 Adobe Reader version: 15.16.20039.185268 Sun Java version: 1.8.0_91 (32-bit) Sun Java version: 1.8.0_91 (64-bit) Flash Player version: 21.0.0.242 Shockwave Player version: 12.2.4r194 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2016-05-28 17:50:55 8D26DAE92B9995B082AE5B6BC2FB70DB 52184 ----a-w- C:\WINDOWS\avastSS.scr 2016-05-22 15:42:54 2617877C5761B8A696FD0368861EE6E4 4515256 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2016-05-22 15:47:10 79422D76818752C6D935A97C8FFC4EEA 44147 ----a-w- C:\WINDOWS\SysWOW64\license.rtf 2016-05-22 15:43:24 EC21FC40C74206DAB19F1A8F9132EFAB 890368 ----a-w- C:\WINDOWS\SysWOW64\AppxPackaging.dll 2016-05-22 15:43:24 CD36155EE56E94B4E8830FA90822511F 503296 ----a-w- C:\WINDOWS\SysWOW64\SettingSync.dll 2016-05-22 15:43:24 C8F351BE29CEA63BC5EE5A175576B7F3 1105920 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-05-22 15:43:24 C86784A6F08E733BE19D62C82182FA7D 266752 ----a-w- C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2016-05-22 15:43:24 C117F577BB0CC6545EA181FBB3FACE99 980352 ----a-w- C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2016-05-22 15:43:24 B65549A1CDB2C827AD022A3F35994FCF 2180136 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2016-05-22 15:43:24 B073C14F8B76DF8652415488C22F10A1 670928 ----a-w- C:\WINDOWS\SysWOW64\mfds.dll 2016-05-22 15:43:24 AF209F751EB761084CEFE2CF10E1CE8D 895080 ----a-w- C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-05-22 15:43:24 A7583A49B0F4A91E5B2E154C3582DF82 420928 ----a-w- C:\WINDOWS\SysWOW64\msvproc.dll 2016-05-22 15:43:24 A34EDEA5F401143A0190642EABA28518 709688 ----a-w- C:\WINDOWS\SysWOW64\mfsvr.dll 2016-05-22 15:43:24 A19A2DDCC69FF16B5FB68AD4F02B564A 480256 ----a-w- C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-05-22 15:43:24 964DE3052B6A869EFBC86930DD51E8BD 379392 ----a-w- C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-05-22 15:43:24 92B98A16E41005D74CF7B2EF28AB1FCF 26112 ----a-w- C:\WINDOWS\SysWOW64\wsdchngr.dll 2016-05-22 15:43:24 888D41F5EFD6995491326C0DEEA2124A 713824 ----a-w- C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2016-05-22 15:43:24 52FEDEA32F2BBFCD3AAA83FD39852C1A 2061824 ----a-w- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-05-22 15:43:24 49CF99392314B7CAD65DE8A05ABFE30D 882720 ----a-w- C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-05-22 15:43:24 463DA1563BB9C1849527967BA80C1810 287712 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll 2016-05-22 15:43:24 359765C7C700F7CED909A69C5DBBD943 140800 ----a-w- C:\WINDOWS\SysWOW64\BrowserSettingSync.dll 2016-05-22 15:43:24 2CE163D00A7DA251D77F7B39E267382B 925064 ----a-w- C:\WINDOWS\SysWOW64\mfplat.dll 2016-05-22 15:43:24 287FAD133D3E5F47DB367B86DC523631 2798080 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-05-22 15:43:24 1587235261E629DFFAA0C39A72CAD1A6 667648 ----a-w- C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-05-22 15:43:24 05B15BD9C92BE52F35A2295B22C5D892 168448 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2016-05-22 15:43:24 03B7C4D05DB7FF060E49FA900FCE627E 451928 ----a-w- C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2016-05-22 15:43:23 8D9CB9BB31AC17112D75456E928C3839 103936 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2016-05-22 15:43:21 B315EB17077EF082A79922D4EA47DBF4 163328 ----a-w- C:\WINDOWS\SysWOW64\fwbase.dll 2016-05-22 15:43:21 AA7CBB3B7A7BFC41E9EC4EF645797DFA 502104 ----a-w- C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-05-22 15:43:21 9F6F693FD7738B8DA4B420E46E973F35 2919832 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2016-05-22 15:43:21 9DEB4C56FAAB147839BF68B6C28A38FC 164864 ----a-w- C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2016-05-22 15:43:21 9A9CDAB4049BDB383C5CA8746F44E4CB 269824 ----a-w- C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2016-05-22 15:43:21 96101F3B90BDE894A862CDF1B808A03F 84832 ----a-w- C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-05-22 15:43:21 7734BD0E9C8ED7DC48F559A67D0A79F4 20480 ----a-w- C:\WINDOWS\SysWOW64\wfapigp.dll 2016-05-22 15:43:21 550ECFF3C3808065169BFEA6C2B7837C 400896 ----a-w- C:\WINDOWS\SysWOW64\winspool.drv 2016-05-22 15:43:21 160CC95D34D62B6A72F9E4E3EE52EBCC 369664 ----a-w- C:\WINDOWS\SysWOW64\FirewallAPI.dll 2016-05-22 15:43:10 AD1B282BDE4A19D7CE2D405409DBB8D0 1497088 ----a-w- C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-05-22 15:43:09 780795062541AF34415CCCE4072FBBB8 12586496 ----a-w- C:\WINDOWS\SysWOW64\wmp.dll 2016-05-22 15:43:09 5A77C7C30E117F60ACCEF43E2EA6841D 12125696 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2016-05-22 15:43:09 22120EE8EC8AC405618FEA768071E267 19344384 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2016-05-22 15:43:08 9CAC58EBAFB3E32711920568810CDCD7 307200 ----a-w- C:\WINDOWS\SysWOW64\ieproxy.dll 2016-05-22 15:43:08 80785EA474D952CC0CB2CF936E36DDE0 3666432 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2016-05-22 15:43:07 A404EA688829EF2657431CB34D0C72DF 5660160 ----a-w- C:\WINDOWS\SysWOW64\Chakra.dll 2016-05-22 15:43:07 3A5C07D5517087143701DBEB749F0EF1 18676224 ----a-w- C:\WINDOWS\SysWOW64\edgehtml.dll 2016-05-22 15:43:06 85ED26DB17B3270944C344E0E5B7C34A 1542816 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2016-05-22 15:43:00 2942FB92C23B77D3BD9D38117AF3663B 1557768 ----a-w- C:\WINDOWS\SysWOW64\KernelBase.dll 2016-05-22 15:42:56 F297B1F54D3FF42732C89C738AEC041F 141824 ----a-w- C:\WINDOWS\SysWOW64\easwrt.dll 2016-05-22 15:42:56 E9B121C13C171C28E8AF4871B52AABA0 450560 ----a-w- C:\WINDOWS\SysWOW64\SyncController.dll 2016-05-22 15:42:56 D408D20295BA135DC1B9B181FADF78DD 255168 ----a-w- C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-05-22 15:42:56 CD94405BB0A90B179E94BE23F4D2B79D 39424 ----a-w- C:\WINDOWS\SysWOW64\wfdprov.dll 2016-05-22 15:42:56 CA57FE09C1255009C9AC1462B7D7264D 957608 ----a-w- C:\WINDOWS\SysWOW64\ole32.dll 2016-05-22 15:42:56 C31BB8559C52E389B82A4B533C2FB39A 764928 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-05-22 15:42:56 B6506139C8A4CE3BDD3B4EFDF63A87B5 348672 ----a-w- C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-05-22 15:42:56 B4643C990D071EE99D9713336052F97B 193024 ----a-w- C:\WINDOWS\SysWOW64\credprovhost.dll 2016-05-22 15:42:56 B1D8636E375413D57B50BDE20CA5E710 358400 ----a-w- C:\WINDOWS\SysWOW64\AccountsRt.dll 2016-05-22 15:42:56 9E6DBA611E99BE75589D6A358F54364F 137728 ----a-w- C:\WINDOWS\SysWOW64\shacct.dll 2016-05-22 15:42:56 9DB69A637142A6C72DF22706CF2F6F7B 31744 ----a-w- C:\WINDOWS\SysWOW64\TimeBrokerClient.dll 2016-05-22 15:42:56 9CD20753821A4F28AA797B5C9A24050F 9918976 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2016-05-22 15:42:56 97E96ABEBCB6CF556406781C47C5282A 78848 ----a-w- C:\WINDOWS\SysWOW64\asycfilt.dll 2016-05-22 15:42:56 96BFB1E4B3F38D999E418D286BE45BFB 118272 ----a-w- C:\WINDOWS\SysWOW64\mtxoci.dll 2016-05-22 15:42:56 8CE4D365EF60DA0A098757371DD43752 88576 ----a-w- C:\WINDOWS\SysWOW64\olepro32.dll 2016-05-22 15:42:56 7D276C5DF303462091092C3311027D30 129024 ----a-w- C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2016-05-22 15:42:56 692E62EA6039478321AE5D24A68E1FE2 4074160 ----a-w- C:\WINDOWS\SysWOW64\explorer.exe 2016-05-22 15:42:56 5D9BB3289D25FDEA1B2DD491C9771778 21123320 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2016-05-22 15:42:56 5A98CF000F5202776E4A58438AB2E070 4412928 ----a-w- C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-05-22 15:42:56 525FC35182F9660E2A7DCC75607535DC 707608 ----a-w- C:\WINDOWS\SysWOW64\rpcrt4.dll 2016-05-22 15:42:56 51DF6FC12B5EF8CA87414D79C98CBC7A 395264 ----a-w- C:\WINDOWS\SysWOW64\wlansec.dll 2016-05-22 15:42:56 4AE45F3077E79A3E3B22996F80DA9E7A 354304 ----a-w- C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-05-22 15:42:56 3D3BBD2DA5660B0B6C9F6A8B9401648C 337920 ----a-w- C:\WINDOWS\SysWOW64\wlanmsm.dll 2016-05-22 15:42:56 32A696B0A48CCCCE5FC8E8E572FD4E90 434688 ----a-w- C:\WINDOWS\SysWOW64\LogonController.dll 2016-05-22 15:42:56 30F680D95B0CCABE46C775672C912C0A 306832 ----a-w- C:\WINDOWS\SysWOW64\wlanapi.dll 2016-05-22 15:42:56 2BECAD7E55AB723F361254477270ED2F 1707520 ----a-w- C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll 2016-05-22 15:42:56 197948552BE23DACBEF10ECC8168FD11 29696 ----a-w- C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-05-22 15:42:56 122F8F0FAF690B88FBDE2DB097740AB6 569744 ----a-w- C:\WINDOWS\SysWOW64\SHCore.dll 2016-05-22 15:42:56 100E983F59F3BF3A3F8BFA327CF9B438 157184 ----a-w- C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2016-05-22 15:42:56 0BF6FDE72035DDC32FAF24344853B80B 777728 ----a-w- C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2016-05-22 15:42:55 F40196C743D54C56C7C2CCDD6FDE262E 572272 ----a-w- C:\WINDOWS\SysWOW64\taskschd.dll 2016-05-22 15:42:55 B9378EA1892974391D15D54E57056130 151040 ----a-w- C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-05-22 15:42:55 9B034D049D1C6EC9BED55D2F27D86ED9 2186 ----a-w- C:\WINDOWS\SysWOW64\AppxProvisioning.xml 2016-05-22 15:42:55 64229C17CFE9262689EAE3E852D3975F 296488 ----a-w- C:\WINDOWS\SysWOW64\policymanager.dll 2016-05-22 15:42:55 594D1C58958A1F980336964B643784F3 3671040 ----a-w- C:\WINDOWS\SysWOW64\msi.dll 2016-05-22 15:42:55 1B26C71109A2EA27DD6684719BF493EC 188256 ----a-w- C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2016-05-22 15:42:49 EB5DBA11B7C79B28A759AF12F03A17BB 769536 ----a-w- C:\WINDOWS\SysWOW64\ContactApis.dll 2016-05-22 15:42:49 E9E7FA1FC796ADC16A1169736EFC7AF3 84480 ----a-w- C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2016-05-22 15:42:49 E46FCEC3EAC209AFCDB2825386E51423 415232 ----a-w- C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-05-22 15:42:49 E34395496B11CF5C8C5B6D2E438BFA43 18944 ----a-w- C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-05-22 15:42:49 DFB54165665C7E369A59B273C91B90B0 800768 ----a-w- C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-05-22 15:42:49 BC5D8155DBA7DC0E4F92430701C19901 161280 ----a-w- C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-05-22 15:42:49 AD1EC1102124182624F1224768FFAE96 564224 ----a-w- C:\WINDOWS\SysWOW64\WSDApi.dll 2016-05-22 15:42:49 AB48B90C4DB88D2F31D1A6F460F76D29 241664 ----a-w- C:\WINDOWS\SysWOW64\cryptngc.dll 2016-05-22 15:42:49 9F8A026A9643F89B4E451539A7AAC0C9 50176 ----a-w- C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-05-22 15:42:49 98DA2DE9A1AC739DF3750F7DABECC9CF 6295552 ----a-w- C:\WINDOWS\SysWOW64\mos.dll 2016-05-22 15:42:49 93B7ED5F44D9C3FB0A74C059E1B9E68B 89088 ----a-w- C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-05-22 15:42:49 897906025BD3616BF9C30A3979A73DEE 712704 ----a-w- C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-05-22 15:42:49 806D3A66BBC91F7F2B4FCC337C13EFAE 239104 ----a-w- C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2016-05-22 15:42:49 7D51637A2E604113F1A4E96FF3F2727C 51128 ----a-w- C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-05-22 15:42:49 75B5C1588D3703F44004D3EB2BD358AD 129024 ----a-w- C:\WINDOWS\SysWOW64\CallHistoryClient.dll 2016-05-22 15:42:49 6C2B2CA75F486449921ED10A39DB9799 69744 ----a-w- C:\WINDOWS\SysWOW64\netapi32.dll 2016-05-22 15:42:49 6BC0E961EA78AFD90348C8E05896A7DC 784896 ----a-w- C:\WINDOWS\SysWOW64\NMAA.dll 2016-05-22 15:42:49 620737C11CD32E03299E0B60BC896230 552960 ----a-w- C:\WINDOWS\SysWOW64\AppointmentApis.dll 2016-05-22 15:42:49 5A212173FC0622865F409B16ED77C9DF 98304 ----a-w- C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-05-22 15:42:49 56315A6A6598E701BB0A5F506DA6143E 200704 ----a-w- C:\WINDOWS\SysWOW64\cemapi.dll 2016-05-22 15:42:49 4B9DE8EAA2E16C34E018749F325BAEFF 949248 ----a-w- C:\WINDOWS\SysWOW64\Unistore.dll 2016-05-22 15:42:49 486919689633D1C0DADA718DF1A3E7FB 219648 ----a-w- C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-05-22 15:42:49 43AE8C9F7D031AB3DBEADA4C17D8C682 150528 ----a-w- C:\WINDOWS\SysWOW64\VCardParser.dll 2016-05-22 15:42:49 40591C3BEBAEA638423B10863315D93F 87040 ----a-w- C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-05-22 15:42:49 3B1F2F6F89F3F4ED75C5FADDB2E7CFE1 56320 ----a-w- C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-05-22 15:42:49 3AEDE16F62921F443DDE37440C84B6F1 5205504 ----a-w- C:\WINDOWS\SysWOW64\BingMaps.dll 2016-05-22 15:42:49 3A1BD59AF5A0D20438D1E44FCF5EA4E8 349696 ----a-w- C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-05-22 15:42:49 39E7BAB659A6AB4419A908E578BE7029 56320 ----a-w- C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-05-22 15:42:49 395F9E50709FAE503C339047207E46CF 540160 ----a-w- C:\WINDOWS\SysWOW64\ChatApis.dll 2016-05-22 15:42:49 395AC69CCD9E2D590775AA6ADD2AE1D2 649728 ----a-w- C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-05-22 15:42:49 392434472351B2DA0499AEC962E988CE 37888 ----a-w- C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-05-22 15:42:49 3547D79A60007624BFEBAFCAE158E992 169984 ----a-w- C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2016-05-22 15:42:49 31657EDEEA6039E71C708BDA61AB62D5 37888 ----a-w- C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-05-22 15:42:49 2C84609F09FD003FA955567D395EEA8A 575488 ----a-w- C:\WINDOWS\SysWOW64\EmailApis.dll 2016-05-22 15:42:49 2823A28AB08EE9DCE85436C700799D66 80384 ----a-w- C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2016-05-22 15:42:49 265DB46FE368D8F701A74976D3823ADC 986976 ----a-w- C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-05-22 15:42:49 259517866C369BCC5990292BCB57E709 223744 ----a-w- C:\WINDOWS\SysWOW64\ExSMime.dll 2016-05-22 15:42:49 242708810A22D373904539EDF39FFAD1 196608 ----a-w- C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2016-05-22 15:42:49 1AEBF2230422716D8CE1BEBCBAE961D3 48128 ----a-w- C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll 2016-05-22 15:42:49 1159023FAA938BF54C7C033D2BC643BE 59904 ----a-w- C:\WINDOWS\SysWOW64\MosStorage.dll 2016-05-22 15:42:49 0D19695F93813C63B4656E42536892FA 47104 ----a-w- C:\WINDOWS\SysWOW64\hmkd.dll 2016-05-22 15:42:49 0188F4F7264EE585DE518FD02DDD9F79 711680 ----a-w- C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-05-22 15:42:48 FA6CCFE5305E3D276F06A104EAA83029 4759040 ----a-w- C:\WINDOWS\SysWOW64\d2d1.dll 2016-05-22 15:42:48 E7BD4D15CDC5A1E162256CFADCA92344 1337240 ----a-w- C:\WINDOWS\SysWOW64\user32.dll 2016-05-22 15:42:48 E793B893135F3B6942B6230D45E27610 61440 ----a-w- C:\WINDOWS\SysWOW64\samlib.dll 2016-05-22 15:42:48 D28C3C4AAB51D00FD6EFA07F6DCC1CBA 1862008 ----a-w- C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-05-22 15:42:48 C122D52ED9662F09EC2650B010544468 73872 ----a-w- C:\WINDOWS\SysWOW64\srvcli.dll 2016-05-22 15:42:48 B65D241B81A010B6A78CCEEA900CCFC0 56320 ----a-w- C:\WINDOWS\SysWOW64\wkscli.dll 2016-05-22 15:42:48 A825405D442EB9A2526468E16296DD58 513368 ----a-w- C:\WINDOWS\SysWOW64\d3d10level9.dll 2016-05-22 15:42:48 89C74675E6DE7888153B1F6644772774 1536088 ----a-w- C:\WINDOWS\SysWOW64\crypt32.dll 2016-05-22 15:42:48 70128BC69D515F2D38577D2438861424 133632 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-05-22 15:42:48 6DFDAD2B0EA3385069276DF547F4CAC8 2186864 ----a-w- C:\WINDOWS\SysWOW64\d3d11.dll 2016-05-22 15:42:48 6D062C6E2C47B3DCDE8F4C3FDB634DEE 83456 ----a-w- C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-05-22 15:42:48 6A7ACABAE92C837F5C1330188EAE36AE 535080 ----a-w- C:\WINDOWS\SysWOW64\dnsapi.dll 2016-05-22 15:42:48 408AF8141C4A44BC120F4204F8F79A75 1944576 ----a-w- C:\WINDOWS\SysWOW64\InputService.dll 2016-05-22 15:42:48 3EB91A44E6BCD05CA257E113FCA1DA0C 43520 ----a-w- C:\WINDOWS\SysWOW64\browcli.dll 2016-05-22 15:42:48 3ABE2040F4F9BDDD008EC5D4713D5ABE 294752 ----a-w- C:\WINDOWS\SysWOW64\msv1_0.dll 2016-05-22 15:42:48 362C9AA8696C74CD38F1416FF866C25C 522176 ----a-w- C:\WINDOWS\SysWOW64\dxgi.dll 2016-05-22 15:42:48 3249EA75874EE3DD3FCBA141656DF210 713728 ----a-w- C:\WINDOWS\SysWOW64\netlogon.dll 2016-05-22 15:42:48 318E2A6EC26C9703A5B273B015672660 388608 ----a-w- C:\WINDOWS\SysWOW64\schannel.dll 2016-05-22 15:42:48 25E42F5C3FDE0E96BF3C16814DC7A688 1372304 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll 2016-05-22 15:42:48 25B0BAA64D6D62873FAA7719DB64015C 183904 ----a-w- C:\WINDOWS\SysWOW64\rsaenh.dll 2016-05-22 15:42:48 15F732C297CE4B169D85214A96A16559 792064 ----a-w- C:\WINDOWS\SysWOW64\kerberos.dll 2016-05-22 15:42:48 10564E7A7EE807FF580E34A94ACF5590 1522152 ----a-w- C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-05-22 15:42:44 CA2EA5401563387162E61444AE15AF59 53248 ----a-w- C:\WINDOWS\SysWOW64\profext.dll 2016-05-22 15:42:44 8E8FBA400CD678AB46D46BB24921A051 342528 ----a-w- C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-05-22 15:42:44 89C06DA6E3B3C06F69E2CAFB3431CAF5 31232 ----a-w- C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe 2016-05-22 15:42:44 468AA89AF32BEE9D6B0ABBDF7C88CF20 5240960 ----a-w- C:\WINDOWS\SysWOW64\windows.storage.dll 2016-05-22 15:42:44 402A33FCE08200518FB0012A6BF2E966 2722816 ----a-w- C:\WINDOWS\SysWOW64\esent.dll 2016-05-22 15:42:44 15E75D27F0C67A7A21D5A514601F0E5A 135168 ----a-w- C:\WINDOWS\SysWOW64\AppxSip.dll 2016-05-22 15:42:43 FB01CB67364FF3AA677F0CFD8C958E50 5324288 ----a-w- C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-05-22 15:42:43 FAD56D0A789345614220D9B770DF400A 465760 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-05-22 15:42:43 EAF904785CA7849C66F6DC2EF0A0E0E7 22528 ----a-w- C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2016-05-22 15:42:43 D57F7D9FB771CA0B434E975F76413430 1072128 ----a-w- C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-05-22 15:42:43 C9B1E5A2FE0C7BF75B8B751311331EB4 2604032 ----a-w- C:\WINDOWS\SysWOW64\CertEnroll.dll 2016-05-22 15:42:43 BF769A5BEA8E50F12264746D30D57C6F 52736 ----a-w- C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2016-05-22 15:42:43 AC42505CBCEE5825BB2695C34E43B1D0 184832 ----a-w- C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2016-05-22 15:42:43 7C7CC816CEEB07022EBCC6B779B16E1D 521728 ----a-w- C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2016-05-22 15:42:43 7C557ABB26C2B2D930AA005FF6A8C025 592384 ----a-w- C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-05-22 15:42:43 717DDEC1ABA5678EDC9F2AF1044BAA69 2000896 ----a-w- C:\WINDOWS\SysWOW64\twinui.appcore.dll 2016-05-22 15:42:43 6DA0B412C0DD9DDB5382527488A5AD2E 237056 ----a-w- C:\WINDOWS\SysWOW64\thumbcache.dll 2016-05-22 15:42:43 5E52C817BCF919CF11CD523A2EC4A456 638464 ----a-w- C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-05-22 15:42:43 5AEDC6D333BC8D8B1DE5928FCE2150DB 400896 ----a-w- C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-05-22 15:42:43 4B71644224F39A390B6DCC482B3D582A 639488 ----a-w- C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-05-22 15:42:43 2E947792E9B1C738E33FD5794B1650F9 30208 ----a-w- C:\WINDOWS\SysWOW64\tbauth.dll 2016-05-22 15:42:43 1D04327817511268754ED6F177DAD3E8 754176 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-05-22 15:42:43 053E2D136DB8A4743E4C40D5D979834B 200704 ----a-w- C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-05-22 15:42:42 FD639F1372389D7C5990663D6A100CFE 541304 ----a-w- C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-05-22 15:42:42 FC90756CB632C0E4AC0D6A60AF2DF9AD 585216 ----a-w- C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2016-05-22 15:42:42 F5814ED9E8B83F872FBDCB139B001C8A 23552 ----a-w- C:\WINDOWS\SysWOW64\wups.dll 2016-05-22 15:42:42 EBD26D676238C0B3938AFF925043576F 394752 ----a-w- C:\WINDOWS\SysWOW64\werui.dll 2016-05-22 15:42:42 E48F0A089D9BAE356BF14FE3A16B1147 489984 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.dll 2016-05-22 15:42:42 E07F85C08C025B08F25150E60CB69B44 37376 ----a-w- C:\WINDOWS\SysWOW64\atmlib.dll 2016-05-22 15:42:42 DA97C8A8C517210E4ACA90E45C836E80 80896 ----a-w- C:\WINDOWS\SysWOW64\BluetoothApis.dll 2016-05-22 15:42:42 D5BF10F0C309C82820813A7190CE1F5F 65536 ----a-w- C:\WINDOWS\SysWOW64\wininetlui.dll 2016-05-22 15:42:42 D1600085065675F98F41A01DCD03AA6E 854528 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2016-05-22 15:42:42 CC68ABFB0AA40F62E7BD740101A0C92B 1117184 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-05-22 15:42:42 CC2F923F02D8EB36D0C442CE709B6CD9 1139712 ----a-w- C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-05-22 15:42:42 CA3C908B5C24293F1F1FB89301D63F16 1588224 ----a-w- C:\WINDOWS\SysWOW64\msxml3.dll 2016-05-22 15:42:42 C9D7861D1C984E1997A3778A97DD1AF9 162816 ----a-w- C:\WINDOWS\SysWOW64\MTF.dll 2016-05-22 15:42:42 C57E960CD2C7F64AE0295DF0423FE071 1444352 ----a-w- C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-05-22 15:42:42 C23A52581FEA6CD49A49160BFA794BF7 6952088 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-05-22 15:42:42 B91176A909798C7EAC28AB4FE786CA53 705536 ----a-w- C:\WINDOWS\SysWOW64\wuapi.dll 2016-05-22 15:42:42 B8AC85F66A12455FB3F2FDB916B1C679 498176 ----a-w- C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-05-22 15:42:42 B74C5FA6221607F864C62090F74FDB80 799744 ----a-w- C:\WINDOWS\SysWOW64\SRH.dll 2016-05-22 15:42:42 B4102814D9B1D1FC6C39869D7F224E12 303104 ----a-w- C:\WINDOWS\SysWOW64\atmfd.dll 2016-05-22 15:42:42 ACE2B02BA07DF7F13F59D07F7A38AA18 161792 ----a-w- C:\WINDOWS\SysWOW64\msorcl32.dll 2016-05-22 15:42:42 A8EF9AEDACF24908E12E910BF3977DC9 703840 ----a-w- C:\WINDOWS\SysWOW64\WWAHost.exe 2016-05-22 15:42:42 A1A9DDD5C6A335C0B97423A2F75C9299 453472 ----a-w- C:\WINDOWS\SysWOW64\directmanipulation.dll 2016-05-22 15:42:42 9B60985A87BA2FED9F57DA30F191098E 315904 ----a-w- C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2016-05-22 15:42:42 98DA8D97E83C73E7AD7A142A801E1898 2193408 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2016-05-22 15:42:42 91ED19257EAA98C1C95A7E5F0FF07FF0 10240 ----a-w- C:\WINDOWS\SysWOW64\oleacchooks.dll 2016-05-22 15:42:42 856AD15FD2D187EA8435564A135C85C0 228352 ----a-w- C:\WINDOWS\SysWOW64\deviceaccess.dll 2016-05-22 15:42:42 8450005F7BA8662A64E3FB7B0C3EE836 51712 ----a-w- C:\WINDOWS\SysWOW64\wshbth.dll 2016-05-22 15:42:42 7F0A9630C78E3783680CC9620C4E09C0 6740992 ----a-w- C:\WINDOWS\SysWOW64\mstscax.dll 2016-05-22 15:42:42 7A2A3BAAA05C8124D95B2915E904F900 141664 ----a-w- C:\WINDOWS\SysWOW64\wermgr.exe 2016-05-22 15:42:42 4ECC2FAF9F29066636E06253C0D7FA06 503296 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2016-05-22 15:42:42 4D2E3D6BC01E7A5E9C6F9AFDBFAF98BB 220064 ----a-w- C:\WINDOWS\SysWOW64\sqmapi.dll 2016-05-22 15:42:42 49A21B514FC10B2D55499D58DC78E862 45568 ----a-w- C:\WINDOWS\SysWOW64\jsproxy.dll 2016-05-22 15:42:42 460CDD92C5283DCB9E35AF2B8DB7F200 461824 ----a-w- C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-05-22 15:42:42 4135F625D8F20D76FB29F86FE7A4CC48 93696 ----a-w- C:\WINDOWS\SysWOW64\fontsub.dll 2016-05-22 15:42:42 38EE252AD45EB7D6834F718B9487D3F9 538736 ----a-w- C:\WINDOWS\SysWOW64\wer.dll 2016-05-22 15:42:42 35E635469515D564CE418DDCC7B7BC96 1500160 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2016-05-22 15:42:42 3166A46AA132AACD035C7163108F2DA1 103936 ----a-w- C:\WINDOWS\SysWOW64\updatepolicy.dll 2016-05-22 15:42:42 30E3DC9ED2C6641709AC961CB7CE72BB 647680 ----a-w- C:\WINDOWS\SysWOW64\jscript.dll 2016-05-22 15:42:42 2C0BBF7FC5526D7285BEAD239895C473 682496 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2016-05-22 15:42:42 2BFF4D19D7FC686C150879A2FD5BAE77 2229760 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2016-05-22 15:42:42 1F90253211F8E102D814F4DE4D550B85 1626624 ----a-w- C:\WINDOWS\SysWOW64\dwmcore.dll 2016-05-22 15:42:42 1A341701906986F1865766C6849269FC 323072 ----a-w- C:\WINDOWS\SysWOW64\oleacc.dll 2016-05-22 15:42:42 0561104CC8619EC5A53848F642434235 13018112 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-05-22 15:34:15 F432E0E5B0958F4982D40EB622FBD7FC 35480 ----a-w- C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-05-22 15:34:15 BF9CAA33ADD4C21C118148B5CFC5494B 778936 ----a-w- C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-05-22 15:34:14 6F391E9286733CC6B34FC0FAB23B8DF3 103120 ----a-w- C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-05-22 14:50:58 8128B54EAA48F9C06B19A86C87752996 28672 ----a-w- C:\WINDOWS\SysWOW64\AsIO.dll 2016-05-22 14:50:51 F16BF0E24EE8C8346376E6210C23D2E5 103944 ----a-w- C:\WINDOWS\SysWOW64\OpenCL.DLL ====== C:\WINDOWS\SysWOW64\drivers ===== 2016-05-22 14:50:58 798DE15F187C1F013095BBBEB6FB6197 15232 ----a-w- C:\WINDOWS\SysWOW64\drivers\AsIO.sys ====== C:\WINDOWS\Sysnative ===== 2016-05-28 17:51:05 7E8152C231FF349CEEEB12146D90E952 398152 ----a-w- C:\WINDOWS\Sysnative\aswBoot.exe 2016-05-22 15:47:10 79422D76818752C6D935A97C8FFC4EEA 44147 ----a-w- C:\WINDOWS\Sysnative\license.rtf 2016-05-22 15:43:24 E4B5C9FEF4C8978CF75B584188868AF8 2582016 ----a-w- C:\WINDOWS\Sysnative\MFMediaEngine.dll 2016-05-22 15:43:24 D79FFE2219AE3BA3B871BA2D39B16519 1152328 ----a-w- C:\WINDOWS\Sysnative\mfasfsrcsnk.dll 2016-05-22 15:43:24 C3F15E167CB84E2E6027AF17D49D5904 372224 ----a-w- C:\WINDOWS\Sysnative\MDEServer.exe 2016-05-22 15:43:24 BD70B866034C1366D74CCBB5CA97395E 2544264 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2016-05-22 15:43:24 BC767AD01E4DAFD08C21D5D07CC290C9 567808 ----a-w- C:\WINDOWS\Sysnative\MCRecvSrc.dll 2016-05-22 15:43:24 92F74BF86088520654BD5636A69E37F1 848168 ----a-w- C:\WINDOWS\Sysnative\mfsvr.dll 2016-05-22 15:43:24 6E76BB89EED6C2BD7B1E7B5F9A1C41F0 320000 ----a-w- C:\WINDOWS\Sysnative\MSFlacDecoder.dll 2016-05-22 15:43:24 48E90F12346EE70764CEE435826ABD31 493568 ----a-w- C:\WINDOWS\Sysnative\mfmkvsrcsnk.dll 2016-05-22 15:43:24 28343B7C30E6AF073B02288EB579D984 476728 ----a-w- C:\WINDOWS\Sysnative\msvproc.dll 2016-05-22 15:43:24 090AAD83736B45769D2688E3BC1AB80A 1092464 ----a-w- C:\WINDOWS\Sysnative\mfplat.dll 2016-05-22 15:43:24 00A8CD22CCF7FA34501038C3C35186BD 498960 ----a-w- C:\WINDOWS\Sysnative\MFCaptureEngine.dll 2016-05-22 15:43:23 FEBBA212353E4FA90C6164AA970B772F 536256 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2016-05-22 15:43:23 EBE067467C144B097CEF5F609F6ABF43 865792 ----a-w- C:\WINDOWS\Sysnative\AzureSettingSyncProvider.dll 2016-05-22 15:43:23 C9BFE1D6420BFADB249162039C321F63 1131520 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Audio.dll 2016-05-22 15:43:23 C1FCA0AED814F1E814700833EF8E0616 179712 ----a-w- C:\WINDOWS\Sysnative\BrowserSettingSync.dll 2016-05-22 15:43:23 AF13258A6E8FD57CE0B9C6BEDCDF80CB 144896 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Devices.dll 2016-05-22 15:43:23 8B4111E094EDDBED23EFA1FF8B5F314A 613376 ----a-w- C:\WINDOWS\Sysnative\SettingSync.dll 2016-05-22 15:43:23 834D1648124F0F2729462BF79DB0C2CD 369912 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2016-05-22 15:43:23 7CEC266216126BC9A0E1072E1A7E5702 279040 ----a-w- C:\WINDOWS\Sysnative\ListSvc.dll 2016-05-22 15:43:23 751F5B6AF16546162E06211AF1FC2979 794888 ----a-w- C:\WINDOWS\Sysnative\mfds.dll 2016-05-22 15:43:23 669F733F85FEBE6F7438C66CBF7FD3FD 1062480 ----a-w- C:\WINDOWS\Sysnative\mfmp4srcsnk.dll 2016-05-22 15:43:23 468D29ECE0AD7700B790A20FA2765313 408120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2016-05-22 15:43:23 42BF7FA295F453618104B5A50BEE105B 275456 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2016-05-22 15:43:23 350CFCC870E30BEE151F3DFB83BD0178 1017032 ----a-w- C:\WINDOWS\Sysnative\mfsrcsnk.dll 2016-05-22 15:43:23 32F3BA2C4849ED727508C021F999E147 3428864 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.dll 2016-05-22 15:43:23 2A2C0983B6FE62F02E7183335B1F5C20 1054208 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2016-05-22 15:43:23 218CEC10714AF029BF4D8BCE600AD1DA 819648 ----a-w- C:\WINDOWS\Sysnative\mfmpeg2srcsnk.dll 2016-05-22 15:43:21 FDBDA93BA9CD3B78060705B41BFCF92D 288256 ----a-w- C:\WINDOWS\Sysnative\fveui.dll 2016-05-22 15:43:21 F72F137EEFF89D0B5A2FB8867B4ACEED 402432 ----a-w- C:\WINDOWS\Sysnative\FWPUCLNT.DLL 2016-05-22 15:43:21 F6B9E6CB351D86A0C318B37E14B97656 196608 ----a-w- C:\WINDOWS\Sysnative\fwpolicyiomgr.dll 2016-05-22 15:43:21 F374C27099807E99A156953F8416D34A 361472 ----a-w- C:\WINDOWS\Sysnative\bdesvc.dll 2016-05-22 15:43:21 E9B10E704AD5B1BA5E531809C89A085B 93184 ----a-w- C:\WINDOWS\Sysnative\wpninprc.dll 2016-05-22 15:43:21 E34A89A196F45473D61CCDAB193293D1 119808 ----a-w- C:\WINDOWS\Sysnative\BitLockerDeviceEncryption.exe 2016-05-22 15:43:21 E083BE4900FCBB6BC42943438DCF2CAD 176128 ----a-w- C:\WINDOWS\Sysnative\SystemSettings.DeviceEncryptionHandlers.dll 2016-05-22 15:43:21 DCC42EF91745E4AB13602B9A4D86DDC4 115040 ----a-w- C:\WINDOWS\Sysnative\NetSetupApi.dll 2016-05-22 15:43:21 D906EFF6ADB6704071C903E62867AC23 696672 ----a-w- C:\WINDOWS\Sysnative\NetSetupEngine.dll 2016-05-22 15:43:21 CA24B0764C9DFE243D15A8708580673B 107520 ----a-w- C:\WINDOWS\Sysnative\BdeHdCfgLib.dll 2016-05-22 15:43:21 C8B840675B83DC8A257B075BFE5F9357 261376 ----a-w- C:\WINDOWS\Sysnative\LsaIso.exe 2016-05-22 15:43:21 AA97AC06BFA15DA23C7C9C145A226C2D 25600 ----a-w- C:\WINDOWS\Sysnative\wfapigp.dll 2016-05-22 15:43:21 A15D9F32A84660FA62F9D27577B0F105 324608 ----a-w- C:\WINDOWS\Sysnative\fvecpl.dll 2016-05-22 15:43:21 9C6EE1DE9CF7B77FF550A737816EB6DB 207360 ----a-w- C:\WINDOWS\Sysnative\NetSetupSvc.dll 2016-05-22 15:43:21 9AE80C03EA83537F17B286ECBBA13D43 184320 ----a-w- C:\WINDOWS\Sysnative\fwbase.dll 2016-05-22 15:43:21 95A03F67830FDCB950E70261128D540D 957952 ----a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL 2016-05-22 15:43:21 712AE16ED8FC7F2363F7EA1D8F6D546A 821248 ----a-w- C:\WINDOWS\Sysnative\fvewiz.dll 2016-05-22 15:43:21 6A5290128257BC733107E7819648CA76 526336 ----a-w- C:\WINDOWS\Sysnative\FirewallAPI.dll 2016-05-22 15:43:21 6A0745D04DFB6E37A6D0FEE339A0B742 556032 ----a-w- C:\WINDOWS\Sysnative\PsmServiceExtHost.dll 2016-05-22 15:43:21 47323DE2A684895004CE63EC66FB4AB4 401408 ----a-w- C:\WINDOWS\Sysnative\sharemediacpl.dll 2016-05-22 15:43:21 45FA01F8B7971ACB65202038E34D04A3 86528 ----a-w- C:\WINDOWS\Sysnative\wpdbusenum.dll 2016-05-22 15:43:21 37F5E2385CB4D10AB42186974B9C241A 794112 ----a-w- C:\WINDOWS\Sysnative\BFE.DLL 2016-05-22 15:43:21 258BCD1FE978849EDB02D131FD1F7893 989536 ----a-w- C:\WINDOWS\Sysnative\SecConfig.efi 2016-05-22 15:43:21 0B28F2ACE5103586D322AD98FAA01309 870912 ----a-w- C:\WINDOWS\Sysnative\MPSSVC.dll 2016-05-22 15:43:21 091D5AE5E663A66EE73B539AF7C32EC5 69632 ----a-w- C:\WINDOWS\Sysnative\fveskybackup.dll 2016-05-22 15:43:10 C78D43083400B8FAE408FEB1E99F9DA8 1847808 ----a-w- C:\WINDOWS\Sysnative\WMPDMC.exe 2016-05-22 15:43:10 24146738C422814EEB2A98FF1FC5C6E1 338432 ----a-w- C:\WINDOWS\Sysnative\ncbservice.dll 2016-05-22 15:43:09 E0932D924DA7C363F40E5B90DC9D2669 129536 ----a-w- C:\WINDOWS\Sysnative\flvprophandler.dll 2016-05-22 15:43:09 85A676350B7A349B1DFB47654FBF8C71 804352 ----a-w- C:\WINDOWS\Sysnative\jscript.dll 2016-05-22 15:43:09 5EED294E19B8293E4F0845CED31489BA 13383168 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2016-05-22 15:43:09 3E80E2B0C0010154CC504DC51BE21968 14252544 ----a-w- C:\WINDOWS\Sysnative\wmp.dll 2016-05-22 15:43:08 FA05A804701A1BF900577A0F7C14B59E 24604672 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2016-05-22 15:43:08 7E500CCA3EC66C419F2E4BBDE8617647 4894208 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2016-05-22 15:43:08 1D7F891D7ADCE1A6824FCB57D6768E14 689152 ----a-w- C:\WINDOWS\Sysnative\ieproxy.dll 2016-05-22 15:43:07 3602BE2186C15362DF2B5C489AC1B1D1 22379008 ----a-w- C:\WINDOWS\Sysnative\edgehtml.dll 2016-05-22 15:43:06 82E25186617BA6C15010F0D47C705705 65536 ----a-w- C:\WINDOWS\Sysnative\basesrv.dll 2016-05-22 15:43:06 62D33462C8781DA354519488A571A9AD 7832576 ----a-w- C:\WINDOWS\Sysnative\Chakra.dll 2016-05-22 15:43:06 09098FB07B47765865492C53B66E29E5 764928 ----a-w- C:\WINDOWS\Sysnative\Chakradiag.dll 2016-05-22 15:43:05 1997A751EF0FB9889E6642428DC4CAB2 1161120 ----a-w- C:\WINDOWS\Sysnative\rpcrt4.dll 2016-05-22 15:43:05 03DE6DE0019FFC0DE60759A893BD8B3F 1819208 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2016-05-22 15:43:00 DA5108028A00B865BBECB1980EB05EB8 1997328 ----a-w- C:\WINDOWS\Sysnative\KernelBase.dll 2016-05-22 15:42:55 EDF39F56DDF4116DCC8779A65EF8D6C5 58208 ----a-w- C:\WINDOWS\Sysnative\dwminit.dll 2016-05-22 15:42:55 EA30B6E587862DF15E35525C60CCAFA9 838144 ----a-w- C:\WINDOWS\Sysnative\uDWM.dll 2016-05-22 15:42:55 E2B2525EF375D716E0DE6FE8F3ADCEDB 365568 ----a-w- C:\WINDOWS\Sysnative\atmfd.dll 2016-05-22 15:42:55 A74CEC306AB99D74559F7075EDB60A9B 451584 ----a-w- C:\WINDOWS\Sysnative\werui.dll 2016-05-22 15:42:55 A4CA6FE3F02C6299EED8B7296DC902D6 12800 ----a-w- C:\WINDOWS\Sysnative\oleacchooks.dll 2016-05-22 15:42:55 7185B16516478DF0061C2561C1B072CE 228352 ----a-w- C:\WINDOWS\Sysnative\wsqmcons.exe 2016-05-22 15:42:55 68B34C3558BEE0F6B822FA603E9AE441 258280 ----a-w- C:\WINDOWS\Sysnative\sqmapi.dll 2016-05-22 15:42:55 60C04811AC0BB0BFC5E00D293B8F4464 630632 ----a-w- C:\WINDOWS\Sysnative\fontdrvhost.exe 2016-05-22 15:42:55 54D6AEA7933377556BBBEC5F45539922 673280 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.dll 2016-05-22 15:42:55 14D75B31BA6A28F4A46D7432B48C26B3 45568 ----a-w- C:\WINDOWS\Sysnative\atmlib.dll 2016-05-22 15:42:55 0C8955B4BB1E9D588B4B62D0BD2E5E78 411648 ----a-w- C:\WINDOWS\Sysnative\oleacc.dll 2016-05-22 15:42:55 04EDE78320552097AC7EB3CE69A4A0BD 118272 ----a-w- C:\WINDOWS\Sysnative\fontsub.dll 2016-05-22 15:42:54 FF07BE14ED82E218C3EEE7C986118A2E 307712 ----a-w- C:\WINDOWS\Sysnative\usbmon.dll 2016-05-22 15:42:54 FE42F8A07885E518ED1E846C93E4B78C 617984 ----a-w- C:\WINDOWS\Sysnative\StorSvc.dll 2016-05-22 15:42:54 FE3A72E9BC5515509517D9BF41144252 414720 ----a-w- C:\WINDOWS\Sysnative\bcastdvr.exe 2016-05-22 15:42:54 F8FAB3E1281FB937DB1C8109842A9534 3994624 ----a-w- C:\WINDOWS\Sysnative\SettingsHandlers_nt.dll 2016-05-22 15:42:54 F8083C536BEDE61AFB4069D8A8C16DA7 456704 ----a-w- C:\WINDOWS\Sysnative\ipnathlp.dll 2016-05-22 15:42:54 F75A1710366B5C6B02D3C061DAA4C578 529920 ----a-w- C:\WINDOWS\Sysnative\LogonController.dll 2016-05-22 15:42:54 F70CB98E5669D44CBFA6F3EBF534977F 86528 ----a-w- C:\WINDOWS\Sysnative\AppCapture.dll 2016-05-22 15:42:54 F4F6D943E788447DAE29DA217B6743E6 147456 ----a-w- C:\WINDOWS\Sysnative\mtxoci.dll 2016-05-22 15:42:54 F172E5709824756634091047826E7A9F 1319424 ----a-w- C:\WINDOWS\Sysnative\wifinetworkmanager.dll 2016-05-22 15:42:54 F0D97E9816795E1AAA17396ABD2660C4 4827136 ----a-w- C:\WINDOWS\Sysnative\ExplorerFrame.dll 2016-05-22 15:42:54 F07301C282AA222C33F8C28B4F545275 591872 ----a-w- C:\WINDOWS\Sysnative\SmsRouterSvc.dll 2016-05-22 15:42:54 F00A2E895B61858DBB3FE870495E37FA 210432 ----a-w- C:\WINDOWS\Sysnative\wcmcsp.dll 2016-05-22 15:42:54 EF953237B34D1468B81A6AB260A3C524 1317640 ----a-w- C:\WINDOWS\Sysnative\winload.efi 2016-05-22 15:42:54 ECF260CA5837CE3174AAAE450C1888C6 605184 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2016-05-22 15:42:54 EBD07BD20B5E0E92A398566EF8720F79 31232 ----a-w- C:\WINDOWS\Sysnative\seclogon.dll 2016-05-22 15:42:54 E5E09ABD5171EB8622821059D8757F43 239616 ----a-w- C:\WINDOWS\Sysnative\credprovhost.dll 2016-05-22 15:42:54 DBD087566420D945303C278A4FD90E60 440320 ----a-w- C:\WINDOWS\Sysnative\CredProvDataModel.dll 2016-05-22 15:42:54 DAFECF80513C6E6892BBEBB48D555A31 115712 ----a-w- C:\WINDOWS\Sysnative\srpapi.dll 2016-05-22 15:42:54 D5D0D1345DEAC9D08A6A5B146A29ADBE 1390080 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Shell.dll 2016-05-22 15:42:54 D3406F98BD98633780820C5EDBA9A5B4 166400 ----a-w- C:\WINDOWS\Sysnative\AboveLockAppHost.dll 2016-05-22 15:42:54 D20C52607024BD08A88CF1CA6B339C9B 517632 ----a-w- C:\WINDOWS\Sysnative\winspool.drv 2016-05-22 15:42:54 D1241DFC397FA8CCFB4BB4B63AAD31AC 755712 ----a-w- C:\WINDOWS\Sysnative\spoolsv.exe 2016-05-22 15:42:54 CFF943806EBAD5CFAC26FD3DF304E79F 1073152 ----a-w- C:\WINDOWS\Sysnative\RDXService.dll 2016-05-22 15:42:54 CFF6A3799F83060D3FF538564E4264CA 374008 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsAdminFlows.exe 2016-05-22 15:42:54 CFF415024C353DA284731CB72FE3F8FF 770640 ----a-w- C:\WINDOWS\Sysnative\iuilp.dll 2016-05-22 15:42:54 CD885F960066DDD538CD1BBD509A0EC0 69632 ----a-w- C:\WINDOWS\Sysnative\wininetlui.dll 2016-05-22 15:42:54 C991F0E48492D1550279F901AB2332B0 390496 ----a-w- C:\WINDOWS\Sysnative\wlanapi.dll 2016-05-22 15:42:54 C49BB15138D9A7AE2901692CA30E11D1 181248 ----a-w- C:\WINDOWS\Sysnative\shacct.dll 2016-05-22 15:42:54 C3BB5D3E3DD24AC0BFA9223F2877F136 76800 ----a-w- C:\WINDOWS\Sysnative\NetCfgNotifyObjectHost.exe 2016-05-22 15:42:54 C1D51970E74AB5FFE46FE624BFE900C6 1731072 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2016-05-22 15:42:54 C1C169EFA8E5E30A0A521C0409CAC153 874968 ----a-w- C:\WINDOWS\Sysnative\winresume.exe 2016-05-22 15:42:54 BE7D6EA3650F1C25076335A9C1F3D59B 1098240 ----a-w- C:\WINDOWS\Sysnative\dosvc.dll 2016-05-22 15:42:54 BD3F339FE542C30BB4A88F34A597728C 134656 ----a-w- C:\WINDOWS\Sysnative\wificonnapi.dll 2016-05-22 15:42:54 B985F4CC9D63594D8D3DCADAC07F257E 130560 ----a-w- C:\WINDOWS\Sysnative\CloudDomainJoinDataModelServer.dll 2016-05-22 15:42:54 B471A4DA6F8DFF957B6F109FA182C366 3575296 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsThresholdAdminFlowUI.dll 2016-05-22 15:42:54 B37F21B4C25BF10605A196791F93E324 360448 ----a-w- C:\WINDOWS\Sysnative\vaultsvc.dll 2016-05-22 15:42:54 B0236F0FB7402381A50F2EBF031C49CF 1030416 ----a-w- C:\WINDOWS\Sysnative\winresume.efi 2016-05-22 15:42:54 AEBD5FCFBFF0294A2D87048D4F5417CB 74424 ----a-w- C:\WINDOWS\Sysnative\easinvoker.exe 2016-05-22 15:42:54 AE6A68A065D4C26AF4BEFAA53623B266 2755584 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2016-05-22 15:42:54 ACC6B16066D073AA0E20B044BFEF9CD1 471552 ----a-w- C:\WINDOWS\Sysnative\NetSetupShim.dll 2016-05-22 15:42:54 A78E76034D230AFE6B74B57BAF8C8BF2 27648 ----a-w- C:\WINDOWS\Sysnative\WiFiConfigSP.dll 2016-05-22 15:42:54 A2953084546B1F46B5CCC7FC57A72C1B 314880 ----a-w- C:\WINDOWS\Sysnative\RDXTaskFactory.dll 2016-05-22 15:42:54 A2902A998C3A8A049D26235A75DBE300 174592 ----a-w- C:\WINDOWS\Sysnative\easwrt.dll 2016-05-22 15:42:54 A1BFD44C6343BDF582828EAB6B4CBDE5 630784 ----a-w- C:\WINDOWS\Sysnative\PhoneProviders.dll 2016-05-22 15:42:54 9BE5ECE2F17B3BEDE6FDE1175BD23266 376536 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.MediaControl.dll 2016-05-22 15:42:54 9822B613AEB1CF24E05EFEE748160637 25088 ----a-w- C:\WINDOWS\Sysnative\irmon.dll 2016-05-22 15:42:54 96BAB1499995B85B91C312BA5114CA03 1322248 ----a-w- C:\WINDOWS\Sysnative\ole32.dll 2016-05-22 15:42:54 92291BFE95AD37CF486BD3E4B31F746B 1141504 ----a-w- C:\WINDOWS\Sysnative\winload.exe 2016-05-22 15:42:54 8AF0CBE3FC6129C42D7A2A73B681F226 1118208 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2016-05-22 15:42:54 89FE1A65D15DE2AA9CBF86AA6A731557 7474528 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2016-05-22 15:42:54 84ADBF35DAF6404148AE85973BE26D59 48640 ----a-w- C:\WINDOWS\Sysnative\wfdprov.dll 2016-05-22 15:42:54 7F0318ECC1E6E566D02F218DD59CEA84 484352 ----a-w- C:\WINDOWS\Sysnative\DataSenseHandlers.dll 2016-05-22 15:42:54 7A0E065E46156F9288AE32B1E0399247 52224 ----a-w- C:\WINDOWS\Sysnative\jsproxy.dll 2016-05-22 15:42:54 77B2F9C522467B1FC8770028D09534DB 91648 ----a-w- C:\WINDOWS\Sysnative\asycfilt.dll 2016-05-22 15:42:54 75A22EF6AC813D4FE63E30C3C292F871 11545088 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2016-05-22 15:42:54 717FDDACE38C314CA5A517E12162CC6D 216576 ----a-w- C:\WINDOWS\Sysnative\QuickActionsDataModel.dll 2016-05-22 15:42:54 70C5D325E1BBD9C771542375F9DE5711 303216 ----a-w- C:\WINDOWS\Sysnative\LockAppHost.exe 2016-05-22 15:42:54 703430E9FFF072334B247B5E88428331 288768 ----a-w- C:\WINDOWS\Sysnative\vaultcli.dll 2016-05-22 15:42:54 6EA247B3631FE0181583566B9D828B22 413536 ----a-w- C:\WINDOWS\Sysnative\wifitask.exe 2016-05-22 15:42:54 6E04BBE242E2889B37300C4DF5CE1126 3449168 ----a-w- C:\WINDOWS\Sysnative\WSService.dll 2016-05-22 15:42:54 6870232D80480DA4FF1FBE3373FCA06E 965632 ----a-w- C:\WINDOWS\Sysnative\SRH.dll 2016-05-22 15:42:54 6758ABE6A73AE709A6C74F121C666CC1 841216 ----a-w- C:\WINDOWS\Sysnative\win32spl.dll 2016-05-22 15:42:54 610D0502400BDAFD4BB8EA10713234C7 74240 ----a-w- C:\WINDOWS\Sysnative\SMSRouter.dll 2016-05-22 15:42:54 6072C7DB85FD3FE8D308EE44865C04DE 305664 ----a-w- C:\WINDOWS\Sysnative\wifiprofilessettinghandler.dll 2016-05-22 15:42:54 5DA95027DF2317174E8C39B4A8D1FCD8 1213440 ----a-w- C:\WINDOWS\Sysnative\wwansvc.dll 2016-05-22 15:42:54 5D88798FC34BB61C74256CDD66BDD205 318976 ----a-w- C:\WINDOWS\Sysnative\domgmt.dll 2016-05-22 15:42:54 5C156EC4E44E30331BCC865A3B61D839 585728 ----a-w- C:\WINDOWS\Sysnative\winlogon.exe 2016-05-22 15:42:54 5BDA53E18911DEAB35F03AA1C3213A78 3673424 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2016-05-22 15:42:54 53AC4B2658807691D2A485EE0F8A50E9 463360 ----a-w- C:\WINDOWS\Sysnative\wlansec.dll 2016-05-22 15:42:54 52C95CFC459242ECBD8A557A197F6FF6 725776 ----a-w- C:\WINDOWS\Sysnative\SHCore.dll 2016-05-22 15:42:54 50E41D3203DA334DBBD2B3B6C7EA64CD 988672 ----a-w- C:\WINDOWS\Sysnative\SharedStartModel.dll 2016-05-22 15:42:54 453740989239803FE363FF8B40EA2E08 2295808 ----a-w- C:\WINDOWS\Sysnative\wlansvc.dll 2016-05-22 15:42:54 3F8466CC13D1F614C8FAC24B1C030D59 214528 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Scanners.dll 2016-05-22 15:42:54 335995302980B83CA6B1974A84AC6009 730344 ----a-w- C:\WINDOWS\Sysnative\Windows.Internal.Shell.Broker.dll 2016-05-22 15:42:54 2989A5B700D1C706ED496CCA75DCFA67 7533568 ----a-w- C:\WINDOWS\Sysnative\mstscax.dll 2016-05-22 15:42:54 290D24F50396B379338790B8E8D1C503 1714688 ----a-w- C:\WINDOWS\Sysnative\SRHInproc.dll 2016-05-22 15:42:54 28CFFDB411375B2BBB0EBF295ABAEF29 382464 ----a-w- C:\WINDOWS\Sysnative\wuuhext.dll 2016-05-22 15:42:54 1BF000CFA56FD272B4ECAC167CDF6A8F 1211904 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Cred.dll 2016-05-22 15:42:54 167176E3A8B095C2E807D27CBE6AB0D3 1902592 ----a-w- C:\WINDOWS\Sysnative\msxml3.dll 2016-05-22 15:42:54 12D83590FEF1C8C28DBF3323C61E831A 31232 ----a-w- C:\WINDOWS\Sysnative\wsdchngr.dll 2016-05-22 15:42:54 0ED8556CB47EC7689D0046791F3427AE 26112 ----a-w- C:\WINDOWS\Sysnative\wlansvcpal.dll 2016-05-22 15:42:54 0D7BB44BFFFA4E153F4EA1E05522D2C3 37376 ----a-w- C:\WINDOWS\Sysnative\LaunchWinApp.exe 2016-05-22 15:42:54 0CFE0F27EC828D9659FD8BF3A529F7B1 166400 ----a-w- C:\WINDOWS\Sysnative\SubscriptionMgr.dll 2016-05-22 15:42:54 0C8655AAC4EA262F62B00DCDA4639819 2598912 ----a-w- C:\WINDOWS\Sysnative\NetworkMobileSettings.dll 2016-05-22 15:42:54 0BF8D8C7EC9FB15D6480A12101E88B71 606720 ----a-w- C:\WINDOWS\Sysnative\wcmsvc.dll 2016-05-22 15:42:54 0BECECA1B6DA7B022FC9502D22B9E9B3 22561256 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2016-05-22 15:42:54 09918925526BC0B5B823CF1A2473D909 412672 ----a-w- C:\WINDOWS\Sysnative\wlanmsm.dll 2016-05-22 15:42:49 F83E3BAEF5931399978A31753B22D0BE 713920 ----a-w- C:\WINDOWS\Sysnative\generaltel.dll 2016-05-22 15:42:49 F7391A45172C10D8B79A239CDD8BA88B 209408 ----a-w- C:\WINDOWS\Sysnative\storewuauth.dll 2016-05-22 15:42:49 F5B8CC586CE9D6187F412B5DFE932468 33280 ----a-w- C:\WINDOWS\Sysnative\wuautoappupdate.dll 2016-05-22 15:42:49 F432ACF44EABBE3EB98F613E1573DA6F 334736 ----a-w- C:\WINDOWS\Sysnative\policymanager.dll 2016-05-22 15:42:49 F40C5151476B066A4061E67DFA641657 128512 ----a-w- C:\WINDOWS\Sysnative\dmcsps.dll 2016-05-22 15:42:49 F1DF87BCF5429D48484E78FB1933326B 848896 ----a-w- C:\WINDOWS\Sysnative\wuapi.dll 2016-05-22 15:42:49 EEA1E99FBC7D91A1A271012F2B4567BB 60416 ----a-w- C:\WINDOWS\Sysnative\PimIndexMaintenanceClient.dll 2016-05-22 15:42:49 EA195B8BC11C1CDB313CFD456EFFA0E9 997376 ----a-w- C:\WINDOWS\Sysnative\schedsvc.dll 2016-05-22 15:42:49 E706406D61508D207F6B41CA4AD30891 127488 ----a-w- C:\WINDOWS\Sysnative\VEDataLayerHelpers.dll 2016-05-22 15:42:49 E432FCF8572682126C3362AA856DC4AE 221184 ----a-w- C:\WINDOWS\Sysnative\PhoneCallHistoryApis.dll 2016-05-22 15:42:49 E1D8055043DF089DB8ADB67C21DF2CC4 70656 ----a-w- C:\WINDOWS\Sysnative\POSyncServices.dll 2016-05-22 15:42:49 DEFF4C7B937F60923980D4BB7D1724B8 274944 ----a-w- C:\WINDOWS\Sysnative\ExSMime.dll 2016-05-22 15:42:49 DD877B48C28AB34197AD88902971B81D 45056 ----a-w- C:\WINDOWS\Sysnative\UserDataLanguageUtil.dll 2016-05-22 15:42:49 DD57E9F1482E1A9BD2514F6D017DF58A 258560 ----a-w- C:\WINDOWS\Sysnative\UserDataAccountApis.dll 2016-05-22 15:42:49 DA4F2FBA02ADB65797953219ABEF0C44 58400 ----a-w- C:\WINDOWS\Sysnative\SensorsNativeApi.dll 2016-05-22 15:42:49 D8F3E820C39808C00A687AED554D23C0 859136 ----a-w- C:\WINDOWS\Sysnative\Windows.ApplicationModel.Store.dll 2016-05-22 15:42:49 D842C2B65E77C13273B626317A5BC5C4 555520 ----a-w- C:\WINDOWS\Sysnative\SyncController.dll 2016-05-22 15:42:49 D169A4C1EDA2F63545628420014F2FE3 808800 ----a-w- C:\WINDOWS\Sysnative\WWAHost.exe 2016-05-22 15:42:49 D0F9C288251907FD44B96837DBDF0A50 320000 ----a-w- C:\WINDOWS\Sysnative\cryptngc.dll 2016-05-22 15:42:49 D0CCDC8D0D00DA363F9D87C2E9A803EF 1297752 ----a-w- C:\WINDOWS\Sysnative\LicenseManager.dll 2016-05-22 15:42:49 CD8C4364BC6040C0226638EF37E13CBB 161280 ----a-w- C:\WINDOWS\Sysnative\CallHistoryClient.dll 2016-05-22 15:42:49 CB902A15DD21B363FECA5DCCF34F5C57 1224704 ----a-w- C:\WINDOWS\Sysnative\Unistore.dll 2016-05-22 15:42:49 C6856D20BE1DB90407C9154B0EC319B9 77824 ----a-w- C:\WINDOWS\Sysnative\provpackageapidll.dll 2016-05-22 15:42:49 C59CF7385D070450643D61C8ADEFFE3C 958976 ----a-w- C:\WINDOWS\Sysnative\RemoteNaturalLanguage.dll 2016-05-22 15:42:49 C57CBD3D0A4B832F3DC18250FC02C3DE 46784 ----a-w- C:\WINDOWS\Sysnative\CompatTelRunner.exe 2016-05-22 15:42:49 BE8C62B0B7BBA8F1152A6A7FCF248404 915456 ----a-w- C:\WINDOWS\Sysnative\configurationclient.dll 2016-05-22 15:42:49 B82C04128A96A05139F9F58ED07D0DB2 3351040 ----a-w- C:\WINDOWS\Sysnative\msi.dll 2016-05-22 15:42:49 B6877446C93D3110E56C90CF13CBEC89 45568 ----a-w- C:\WINDOWS\Sysnative\UserDataTypeHelperUtil.dll 2016-05-22 15:42:49 B3B3BF36976D72C06C2D3524AC040643 81144 ----a-w- C:\WINDOWS\Sysnative\netapi32.dll 2016-05-22 15:42:49 B232CE503C6666873E7B9E4BA769C524 92160 ----a-w- C:\WINDOWS\Sysnative\policymanagerprecheck.dll 2016-05-22 15:42:49 AC71C0A77ED618382D5422C6AB1747E4 169472 ----a-w- C:\WINDOWS\Sysnative\mdmmigrator.dll 2016-05-22 15:42:49 AB416599057FFDC84E28BBB6DA69EADC 235008 ----a-w- C:\WINDOWS\Sysnative\MTF.dll 2016-05-22 15:42:49 AB17E08B47FECDAF0E1349797A6C41A4 1184960 ----a-w- C:\WINDOWS\Sysnative\aeinv.dll 2016-05-22 15:42:49 AB1738C51C1C1F41A885467E7BB0D37B 285696 ----a-w- C:\WINDOWS\Sysnative\VEEventDispatcher.dll 2016-05-22 15:42:49 A617BE5E429A035A1CA8217C1B16F0BB 134656 ----a-w- C:\WINDOWS\Sysnative\browser.dll 2016-05-22 15:42:49 A34D9229F8D3A7164247213C9A283DB0 189952 ----a-w- C:\WINDOWS\Sysnative\WiFiDisplay.dll 2016-05-22 15:42:49 A29004CC4FE3A06B5C71969F6411FD41 287232 ----a-w- C:\WINDOWS\Sysnative\provhandlers.dll 2016-05-22 15:42:49 A249C98D869623F1AF0DB4BCFFF6D2A8 68096 ----a-w- C:\WINDOWS\Sysnative\UserDataPlatformHelperUtil.dll 2016-05-22 15:42:49 9FDAC1F65E074C1CF12C3E80BD5195E4 176640 ----a-w- C:\WINDOWS\Sysnative\mdmregistration.dll 2016-05-22 15:42:49 9B034D049D1C6EC9BED55D2F27D86ED9 2186 ----a-w- C:\WINDOWS\Sysnative\AppxProvisioning.xml 2016-05-22 15:42:49 981F6C7FB2338CC7889BA4D37C1A9DCE 69632 ----a-w- C:\WINDOWS\Sysnative\EnterpriseDesktopAppMgmtCSP.dll 2016-05-22 15:42:49 95D2BD6AC94FB337AF69F8AFE056BEBE 147808 ----a-w- C:\WINDOWS\Sysnative\wermgr.exe 2016-05-22 15:42:49 94612B9F7FC2B1A5C6D337C649B346F1 278528 ----a-w- C:\WINDOWS\Sysnative\NotificationObjFactory.dll 2016-05-22 15:42:49 93E597D2B5C653E94680E8B8E1C59B36 641536 ----a-w- C:\WINDOWS\Sysnative\enterprisecsps.dll 2016-05-22 15:42:49 91F08041D932816D0D9607F68578A87E 34816 ----a-w- C:\WINDOWS\Sysnative\dmenterprisediagnostics.dll 2016-05-22 15:42:49 90A52EBAC043CFCA92E5F3DEAD4BBB4C 48128 ----a-w- C:\WINDOWS\Sysnative\wups.dll 2016-05-22 15:42:49 907B65AD953EA159B573A0BCC82F6DB0 243712 ----a-w- C:\WINDOWS\Sysnative\cemapi.dll 2016-05-22 15:42:49 8EC4F381818F8A073DEC52C6D1ED9C76 86016 ----a-w- C:\WINDOWS\Sysnative\DeviceEnroller.exe 2016-05-22 15:42:49 8A88DBA247BFF23BD284C2189F41FDA5 2280960 ----a-w- C:\WINDOWS\Sysnative\wuaueng.dll 2016-05-22 15:42:49 8790833B243AB6DD22A1F86FFB26B689 1052160 ----a-w- C:\WINDOWS\Sysnative\MsSpellCheckingFacility.dll 2016-05-22 15:42:49 85EE46E85C3E76809BC454A50564ECD6 418304 ----a-w- C:\WINDOWS\Sysnative\dmenrollengine.dll 2016-05-22 15:42:49 82BC3D304654F8EBEFABDDC2AD70AFE3 497152 ----a-w- C:\WINDOWS\Sysnative\tileobjserver.dll 2016-05-22 15:42:49 81B78E1782DB1BA758FDA7B993C9FEB5 91136 ----a-w- C:\WINDOWS\Sysnative\browserbroker.dll 2016-05-22 15:42:49 810B7BA7636930BD6A21A93296FBCA51 292864 ----a-w- C:\WINDOWS\Sysnative\provengine.dll 2016-05-22 15:42:49 7E81E3E0D7F83BFE3C3975020B6C7F12 163840 ----a-w- C:\WINDOWS\Sysnative\TimeBrokerServer.dll 2016-05-22 15:42:49 7DDC2D8133CC1CA646134CC450C02C15 28672 ----a-w- C:\WINDOWS\Sysnative\mapsupdatetask.dll 2016-05-22 15:42:49 7C20F3EC0BA5ACB8ED40CDEF41B0AC56 779384 ----a-w- C:\WINDOWS\Sysnative\taskschd.dll 2016-05-22 15:42:49 7AAA9916AA10F4B0E9743798A5BA6549 649216 ----a-w- C:\WINDOWS\Sysnative\ngcsvc.dll 2016-05-22 15:42:49 70BA4CAAC5D621DCE88082DA0B1FF014 23552 ----a-w- C:\WINDOWS\Sysnative\ExtrasXmlParser.dll 2016-05-22 15:42:49 6D8365722FBB3E58FC2B10FEA00BE840 514752 ----a-w- C:\WINDOWS\Sysnative\devinv.dll 2016-05-22 15:42:49 6855984AA46D2452A7C518787E1F2643 1996288 ----a-w- C:\WINDOWS\Sysnative\ActiveSyncProvider.dll 2016-05-22 15:42:49 679DD4763AA8028B2F26651D3D02A2E1 582656 ----a-w- C:\WINDOWS\Sysnative\ngccredprov.dll 2016-05-22 15:42:49 61C99C1A4BB5EE14563ED321A859ACB6 726528 ----a-w- C:\WINDOWS\Sysnative\ChatApis.dll 2016-05-22 15:42:49 5E903356FCDC2C7011E5341A1C2D48E9 192000 ----a-w- C:\WINDOWS\Sysnative\provisioningcsp.dll 2016-05-22 15:42:49 5CB565C1A0A30D76D7B099EEF9654297 256000 ----a-w- C:\WINDOWS\Sysnative\accountaccessor.dll 2016-05-22 15:42:49 5907323899BCEFA32BF6B002F2493C09 76288 ----a-w- C:\WINDOWS\Sysnative\ngcpopkeysrv.dll 2016-05-22 15:42:49 4C5D035670EB045123DCF87EE2FDB33B 162816 ----a-w- C:\WINDOWS\Sysnative\enrollmentapi.dll 2016-05-22 15:42:49 4C3A93515CA70A7017CBA3A6A95CF080 121856 ----a-w- C:\WINDOWS\Sysnative\AppointmentActivation.dll 2016-05-22 15:42:49 4BE54893EC2A3B26140DF44E7B6D4E99 230400 ----a-w- C:\WINDOWS\Sysnative\DAFWSD.dll 2016-05-22 15:42:49 492FB85E61768950CDD27C87AED6E8FA 587776 ----a-w- C:\WINDOWS\Sysnative\bisrv.dll 2016-05-22 15:42:49 4766A523BD8265F3082662A49C382680 26408 ----a-w- C:\WINDOWS\Sysnative\wuauclt.exe 2016-05-22 15:42:49 45D26646E3AD737E5DE3DB91CCCE7DBA 339968 ----a-w- C:\WINDOWS\Sysnative\SensorService.dll 2016-05-22 15:42:49 453EEF8F903DE266D9CB16313B5FA796 215040 ----a-w- C:\WINDOWS\Sysnative\aepic.dll 2016-05-22 15:42:49 3F943A9A21814C6A394FBB8F1D4E622D 1401024 ----a-w- C:\WINDOWS\Sysnative\appraiser.dll 2016-05-22 15:42:49 3F4461644840A3C5572DDC726C36BDF7 92160 ----a-w- C:\WINDOWS\Sysnative\SensorsNativeApi.V2.dll 2016-05-22 15:42:49 3932940E0DB7A31B00A415F6B3D3E242 700416 ----a-w- C:\WINDOWS\Sysnative\AppointmentApis.dll 2016-05-22 15:42:49 38C87ECB57CB973AA5DA633B91778670 676352 ----a-w- C:\WINDOWS\Sysnative\WSDApi.dll 2016-05-22 15:42:49 37E893F5A0BB0DCF89D8464F4D5E0C3D 217440 ----a-w- C:\WINDOWS\Sysnative\AppxAllUserStore.dll 2016-05-22 15:42:49 3655A59A1E16307F2F6475AC037C1EE4 87040 ----a-w- C:\WINDOWS\Sysnative\MDMAppInstaller.exe 2016-05-22 15:42:49 33C215D1F36A184FB0C0F83ECBE12B5B 351232 ----a-w- C:\WINDOWS\Sysnative\NgcCtnr.dll 2016-05-22 15:42:49 333F190DFAE2E1EE500234B78ADDA297 640472 ----a-w- C:\WINDOWS\Sysnative\wer.dll 2016-05-22 15:42:49 315CFB6974B5111E3E62E9A512C92B25 151040 ----a-w- C:\WINDOWS\Sysnative\VEStoreEventHandlers.dll 2016-05-22 15:42:49 2E165E1CF278FC2B4959B825642A595B 558080 ----a-w- C:\WINDOWS\Sysnative\MBMediaManager.dll 2016-05-22 15:42:49 2DDEA2BEDD3169F483C9BE610ADFE8B1 8705672 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Protection.PlayReady.dll 2016-05-22 15:42:49 2BCCAEB08EAF8C5D6BD024B3F020D0EA 790528 ----a-w- C:\WINDOWS\Sysnative\EmailApis.dll 2016-05-22 15:42:49 2771EBB565F5C121E66060B173991D4D 1490432 ----a-w- C:\WINDOWS\Sysnative\UserDataService.dll 2016-05-22 15:42:49 2453622FF2CCB1BA1DFA588207E9C7A4 294592 ----a-w- C:\WINDOWS\Sysnative\invagent.dll 2016-05-22 15:42:49 242DA5F2A6D9C5DFE2F99127BD2077A4 92352 ----a-w- C:\WINDOWS\Sysnative\acmigration.dll 2016-05-22 15:42:49 2362BCA98EAF8CE0487664467F720861 178176 ----a-w- C:\WINDOWS\Sysnative\psmsrv.dll 2016-05-22 15:42:49 21098276051C6BEBBA7C8EB79AAF4E22 938496 ----a-w- C:\WINDOWS\Sysnative\ContactApis.dll 2016-05-22 15:42:49 1F3D69B0AE210874DDC300C3EF1C9CCD 438784 ----a-w- C:\WINDOWS\Sysnative\AccountsRt.dll 2016-05-22 15:42:49 1D00BBEEE33FA7F64A8CBFF471968CB0 195072 ----a-w- C:\WINDOWS\Sysnative\VCardParser.dll 2016-05-22 15:42:49 1AF7E0BA5D1AEA3DEF1CF05B070803FA 89600 ----a-w- C:\WINDOWS\Sysnative\NFCProvisioningPlugin.dll 2016-05-22 15:42:49 1AE232355968BBCA3787B5B35DCA0FD0 550912 ----a-w- C:\WINDOWS\Sysnative\StoreAgent.dll 2016-05-22 15:42:49 1A0945D67F0499600E7B43A69210EC5B 41984 ----a-w- C:\WINDOWS\Sysnative\TimeBrokerClient.dll 2016-05-22 15:42:49 11C782F631D915895E56FC1CD8214E51 100232 ----a-w- C:\WINDOWS\Sysnative\omadmapi.dll 2016-05-22 15:42:49 0FB83658FBB2C5A18AB98C5C94DB9FAF 289792 ----a-w- C:\WINDOWS\Sysnative\NgcCtnrSvc.dll 2016-05-22 15:42:49 0BFEB4862FC2422DAC67EE95C278ECE0 111616 ----a-w- C:\WINDOWS\Sysnative\updatepolicy.dll 2016-05-22 15:42:49 087FF4F0D29833949962F8EE60DA345E 199168 ----a-w- C:\WINDOWS\Sysnative\InstallAgent.exe 2016-05-22 15:42:49 087FBBC026DCC0F693E91079B9901B7E 2166784 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentServer.dll 2016-05-22 15:42:49 082DC7D3704A17FF022D70C577785254 2066432 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentExtensions.dll 2016-05-22 15:42:49 04F7878E7017105AB782353231561749 252928 ----a-w- C:\WINDOWS\Sysnative\PimIndexMaintenance.dll 2016-05-22 15:42:49 04BB77409644685810DBD63D86F5720E 99328 ----a-w- C:\WINDOWS\Sysnative\ngckeyenum.dll 2016-05-22 15:42:49 03416DA86664FF2141A5820868B0B9B1 88576 ----a-w- C:\WINDOWS\Sysnative\AppxSysprep.dll 2016-05-22 15:42:49 0271B5C23A375E008C34024088D0F396 1575936 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Speech.dll 2016-05-22 15:42:49 023338E1DA5B6E5C2EFC7E5ADA7929C5 685568 ----a-w- C:\WINDOWS\Sysnative\scapi.dll 2016-05-22 15:42:49 020AD2DA67F206DC160053F88454A0D4 111616 ----a-w- C:\WINDOWS\Sysnative\UserDataTimeUtil.dll 2016-05-22 15:42:48 FD60606E2E7F74D7104A5DA1210D38E6 460800 ----a-w- C:\WINDOWS\Sysnative\MapConfiguration.dll 2016-05-22 15:42:48 F6718A9F2B5BFA1A42618F63BC890713 5502976 ----a-w- C:\WINDOWS\Sysnative\d2d1.dll 2016-05-22 15:42:48 F5F7CE3E32536F1A37FB3972F27A814F 1399224 ----a-w- C:\WINDOWS\Sysnative\user32.dll 2016-05-22 15:42:48 F1CC271FBAD94FBD3D69BC6BE443C33B 1056256 ----a-w- C:\WINDOWS\Sysnative\JpMapControl.dll 2016-05-22 15:42:48 F0BBBF8807D5725102A9EB06AEB9C1C5 58368 ----a-w- C:\WINDOWS\Sysnative\browcli.dll 2016-05-22 15:42:48 E650C69B5CA9B786AD91E3E7F962A0EE 848896 ----a-w- C:\WINDOWS\Sysnative\samsrv.dll 2016-05-22 15:42:48 DE1C434F0F89C37687D34FB8A8E77B46 120320 ----a-w- C:\WINDOWS\Sysnative\MapsBtSvc.dll 2016-05-22 15:42:48 D9A795240A84C9E3DA78BC1B9E239FCF 95744 ----a-w- C:\WINDOWS\Sysnative\samlib.dll 2016-05-22 15:42:48 C1C81AAF533552B3C4D9F11A5FF97700 291360 ----a-w- C:\WINDOWS\Sysnative\wininit.exe 2016-05-22 15:42:48 BEF109D45139E2646C116DD9B6E53E3C 847360 ----a-w- C:\WINDOWS\Sysnative\netlogon.dll 2016-05-22 15:42:48 B7C13F4BE0263F3A8303404A96F4246D 358752 ----a-w- C:\WINDOWS\Sysnative\msv1_0.dll 2016-05-22 15:42:48 B28EA19205448B34303D006D50E9E65A 74752 ----a-w- C:\WINDOWS\Sysnative\MosStorage.dll 2016-05-22 15:42:48 ABF13620065E258771320165E0759761 1776768 ----a-w- C:\WINDOWS\Sysnative\WindowsCodecs.dll 2016-05-22 15:42:48 A5C14F8FE076B41778C56F2414F5D246 650304 ----a-w- C:\WINDOWS\Sysnative\dxgi.dll 2016-05-22 15:42:48 9A3E17CDB177913C2A111C80F3D0DBB4 686976 ----a-w- C:\WINDOWS\Sysnative\dnsapi.dll 2016-05-22 15:42:48 99DDB4A100F6013E6B6B269880F0C936 988160 ----a-w- C:\WINDOWS\Sysnative\NMAA.dll 2016-05-22 15:42:48 99D5C132D5085DACBFF909C3AAF832AC 2624512 ----a-w- C:\WINDOWS\Sysnative\InputService.dll 2016-05-22 15:42:48 998015F786B2B9EE029FB556393CF848 78040 ----a-w- C:\WINDOWS\Sysnative\wkscli.dll 2016-05-22 15:42:48 93C28A95FC5CA7F420343AC9693E05E6 1594920 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2016-05-22 15:42:48 92FB4032354D2074DA0DC9E70D8305B1 1388032 ----a-w- C:\WINDOWS\Sysnative\lsasrv.dll 2016-05-22 15:42:48 8FFFDB163436D790369E39700B8A7DC1 27648 ----a-w- C:\WINDOWS\Sysnative\LicenseManagerShellext.exe 2016-05-22 15:42:48 7E0078F1EFEB6F8F47CF85C1D73C7EBC 328192 ----a-w- C:\WINDOWS\Sysnative\profsvc.dll 2016-05-22 15:42:48 78A9EBBAC348ACD9AF5B72ECF90944A7 853504 ----a-w- C:\WINDOWS\Sysnative\MapsStore.dll 2016-05-22 15:42:48 77DE2FC672F423C2DFCF2A12DB74197C 89088 ----a-w- C:\WINDOWS\Sysnative\MapsCSP.dll 2016-05-22 15:42:48 77981E6F98F4A8743D3AEB1A8AF4DE09 108544 ----a-w- C:\WINDOWS\Sysnative\InputLocaleManager.dll 2016-05-22 15:42:48 72229D3836EA9697F5E13AAEA85F8688 204048 ----a-w- C:\WINDOWS\Sysnative\rsaenh.dll 2016-05-22 15:42:48 7118498F6E48758A2EF5A7D1982E2B62 1139712 ----a-w- C:\WINDOWS\Sysnative\XblGameSave.dll 2016-05-22 15:42:48 703F15FBAEA94F88FD5E12EFA94A0F7E 2656952 ----a-w- C:\WINDOWS\Sysnative\CoreUIComponents.dll 2016-05-22 15:42:48 614EF7EFFE6896791CC8E4D045F37579 7977472 ----a-w- C:\WINDOWS\Sysnative\mos.dll 2016-05-22 15:42:48 5FD7FDCE260C2ADE6CFFBC141657E8C0 939520 ----a-w- C:\WINDOWS\Sysnative\MapControlCore.dll 2016-05-22 15:42:48 5839A317C25F70979433E0905DFABB1B 284672 ----a-w- C:\WINDOWS\Sysnative\dnsrslvr.dll 2016-05-22 15:42:48 56B24B359838BE86B013C2CFD38BDFC4 72704 ----a-w- C:\WINDOWS\Sysnative\moshost.dll 2016-05-22 15:42:48 5470B002C5E5D4DC8C4C330EAE8A685D 619296 ----a-w- C:\WINDOWS\Sysnative\d3d10level9.dll 2016-05-22 15:42:48 5066575F39AEECAA7A9E03C0FA007A90 881664 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Input.Inking.dll 2016-05-22 15:42:48 50007CDB0F9801A7186F3E81D3377D12 2773096 ----a-w- C:\WINDOWS\Sysnative\d3d11.dll 2016-05-22 15:42:48 489EDA0C433F5B0AA54033F523F2C80E 269824 ----a-w- C:\WINDOWS\Sysnative\moshostcore.dll 2016-05-22 15:42:48 46E51F35566F8B73540D56EAA0A97E46 175616 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Core.TextInput.dll 2016-05-22 15:42:48 3CFA0EA6ABC10436D998F7958912387C 1848072 ----a-w- C:\WINDOWS\Sysnative\crypt32.dll 2016-05-22 15:42:48 3C52661045548D78EC0EB76495CB978F 66560 ----a-w- C:\WINDOWS\Sysnative\MosHostClient.dll 2016-05-22 15:42:48 2804ACDD73835F051CE71DA4DB25337D 110584 ----a-w- C:\WINDOWS\Sysnative\srvcli.dll 2016-05-22 15:42:48 1B8A57EC632457E909A06957CB216806 7200256 ----a-w- C:\WINDOWS\Sysnative\BingMaps.dll 2016-05-22 15:42:48 1A944DC7982279E73C4181DD5D50E021 3591168 ----a-w- C:\WINDOWS\Sysnative\win32kfull.sys 2016-05-22 15:42:48 0D9E0BDCCCE10F07A7B66A61B27C1F71 116224 ----a-w- C:\WINDOWS\Sysnative\FontProvider.dll 2016-05-22 15:42:48 0676A6C9A6EECA48E14B9AE13B0E3508 1387520 ----a-w- C:\WINDOWS\Sysnative\win32kbase.sys 2016-05-22 15:42:44 ED309332DA910BE791F40F09F6FC50B5 38400 ----a-w- C:\WINDOWS\Sysnative\ByteCodeGenerator.exe 2016-05-22 15:42:44 DB0C2721BE0E21EAA0C4C70B07F481DE 3078144 ----a-w- C:\WINDOWS\Sysnative\esent.dll 2016-05-22 15:42:44 C417C35D0B714320708A1C18673ACE6C 104448 ----a-w- C:\WINDOWS\Sysnative\BluetoothApis.dll 2016-05-22 15:42:44 C3534256AF526A16AADBA335AA99D58F 63488 ----a-w- C:\WINDOWS\Sysnative\wshbth.dll 2016-05-22 15:42:44 AFAF7063071A1124985A63382B2BC34C 161792 ----a-w- C:\WINDOWS\Sysnative\AppxSip.dll 2016-05-22 15:42:44 A1144CA95D4C30449331D3DF39F295F9 970752 ----a-w- C:\WINDOWS\Sysnative\kerberos.dll 2016-05-22 15:42:44 82C4028BABC9BADCD89600F5084E4543 479232 ----a-w- C:\WINDOWS\Sysnative\schannel.dll 2016-05-22 15:42:44 6D31FB3E4263749BD994B3895322D799 982016 ----a-w- C:\WINDOWS\Sysnative\AppxPackaging.dll 2016-05-22 15:42:44 33931A5F8E8B4446C547B020409D66C4 436736 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentClient.dll 2016-05-22 15:42:44 2F0FA6F60BC9A971BFBF31D1D2C8AF08 167936 ----a-w- C:\WINDOWS\Sysnative\dafBth.dll 2016-05-22 15:42:44 24F2141493C1A2F6FDEC8C3FA5A95CDE 6605504 ----a-w- C:\WINDOWS\Sysnative\windows.storage.dll 2016-05-22 15:42:43 FBC8C56814642A7CA88ACBCA8DD1121F 145408 ----a-w- C:\WINDOWS\Sysnative\dssvc.dll 2016-05-22 15:42:43 F66EEB5365413D4B968C5B51D25F88B8 141560 ----a-w- C:\WINDOWS\Sysnative\AuthHost.exe 2016-05-22 15:42:43 EED30CDEAB6E4B45CBF1BD5298952049 550656 ----a-w- C:\WINDOWS\Sysnative\directmanipulation.dll 2016-05-22 15:42:43 E8A201E7ACF39359D99EEDD3D059E5AC 1395712 ----a-w- C:\WINDOWS\Sysnative\UIAutomationCore.dll 2016-05-22 15:42:43 DB2911201B4AAC79AF712C5551F0C41D 688640 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.Connectivity.dll 2016-05-22 15:42:43 D2EF3FDF915BBA7C9832FA890DD4D85A 16984576 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2016-05-22 15:42:43 D22A2DEC01300ECEB41D22AB60B1E4B3 66048 ----a-w- C:\WINDOWS\Sysnative\OnDemandConnRouteHelper.dll 2016-05-22 15:42:43 B9B902C12D6872DE9135B0A7C1ACA5A8 565600 ----a-w- C:\WINDOWS\Sysnative\SettingSyncHost.exe 2016-05-22 15:42:43 B8CBDF64077D764D26E6E0255270B7BF 224256 ----a-w- C:\WINDOWS\Sysnative\PackageStateRoaming.dll 2016-05-22 15:42:43 A8ECAFE7C58ABABA7CB1C377B7A7E309 984576 ----a-w- C:\WINDOWS\Sysnative\SettingSyncCore.dll 2016-05-22 15:42:43 A6969BAD3166EDA1C79988DD782A87CF 888320 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.dll 2016-05-22 15:42:43 A55AB67676D0E90C279E36AF78EECCFA 515072 ----a-w- C:\WINDOWS\Sysnative\OneDriveSettingSyncProvider.dll 2016-05-22 15:42:43 A407435633C74CB1D6911DC05A90D939 2912256 ----a-w- C:\WINDOWS\Sysnative\CertEnroll.dll 2016-05-22 15:42:43 8F225A78F60DB08D4691C1C27CF644F2 6974464 ----a-w- C:\WINDOWS\Sysnative\Windows.Data.Pdf.dll 2016-05-22 15:42:43 87F0EA669FB37C03207A8870C3B91174 1410560 ----a-w- C:\WINDOWS\Sysnative\Windows.Web.Http.dll 2016-05-22 15:42:43 79BF53E386256057C30EF606DC3CFDFB 870400 ----a-w- C:\WINDOWS\Sysnative\modernexecserver.dll 2016-05-22 15:42:43 7890990143812A452858058BBD52149F 297472 ----a-w- C:\WINDOWS\Sysnative\thumbcache.dll 2016-05-22 15:42:43 63939B50C5C103FA71A419BCEA5B1CF0 26112 ----a-w- C:\WINDOWS\Sysnative\TokenBrokerCookies.exe 2016-05-22 15:42:43 5DFAF8BE5A3CABAABF6795BC09EB7876 948736 ----a-w- C:\WINDOWS\Sysnative\XblAuthManager.dll 2016-05-22 15:42:43 594FDF2DB7568C73C282B282845E30CF 36352 ----a-w- C:\WINDOWS\Sysnative\tbauth.dll 2016-05-22 15:42:43 56C238ACFE4CB020D3E38508249039EA 87040 ----a-w- C:\WINDOWS\Sysnative\tzautoupdate.dll 2016-05-22 15:42:43 51449675B00C62F970B497A2FBF1BC46 787456 ----a-w- C:\WINDOWS\Sysnative\Windows.Web.dll 2016-05-22 15:42:43 497EB340D13433E8FE53625103E0C2D0 146432 ----a-w- C:\WINDOWS\Sysnative\AuthBroker.dll 2016-05-22 15:42:43 3EEB5260D4321F7F124955E1D228FDF2 274944 ----a-w- C:\WINDOWS\Sysnative\DisplayManager.dll 2016-05-22 15:42:43 2A643E48326E427C6A43005EC29F314D 2444288 ----a-w- C:\WINDOWS\Sysnative\twinui.appcore.dll 2016-05-22 15:42:43 191A50C760243B5B8E08E0A1CA0B1F7C 821760 ----a-w- C:\WINDOWS\Sysnative\TokenBroker.dll 2016-05-22 15:42:42 F7DD01F464ED3ADB8477CD5FD1DE6CF4 356864 ----a-w- C:\WINDOWS\Sysnative\ActivationManager.dll 2016-05-22 15:42:42 F7526C133AC265F283012E9CD751F873 625000 ----a-w- C:\WINDOWS\Sysnative\ClipSVC.dll 2016-05-22 15:42:42 AB3F697651DDAE1C424C9B2412EFBB59 1239552 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Bluetooth.dll 2016-05-22 15:42:42 9CB84B6398F10BCF0CE357F2C7B6056D 286720 ----a-w- C:\WINDOWS\Sysnative\deviceaccess.dll 2016-05-22 15:42:42 86BE19C6A177AEB93302EA5C4FBE2D11 754664 ----a-w- C:\WINDOWS\Sysnative\CoreMessaging.dll 2016-05-22 15:42:42 7539A3BF1DC12C53D6DDE078BE888951 190144 ----a-w- C:\WINDOWS\Sysnative\DeviceCensus.exe 2016-05-22 15:42:42 734B3E9E4DA94DD093C6759CA0C2AA1E 4775424 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2016-05-22 15:42:42 728146F5877FD08DE65B21817ABB19A8 765952 ----a-w- C:\WINDOWS\Sysnative\fveapi.dll 2016-05-22 15:42:42 5DBA65D48CB7B17E241BB7430745C2E0 59392 ----a-w- C:\WINDOWS\Sysnative\hmkd.dll 2016-05-22 15:42:42 5B5F518D6487FDCC9C40A74D3C72B8EE 828928 ----a-w- C:\WINDOWS\Sysnative\Windows.AccountsControl.dll 2016-05-22 15:42:42 5118193C56A2F8D07554395B78A6FDCC 223232 ----a-w- C:\WINDOWS\Sysnative\fveapibase.dll 2016-05-22 15:42:42 4098813724BDAC23A74DD6E75CA360CC 450560 ----a-w- C:\WINDOWS\Sysnative\Windows.Internal.Bluetooth.dll 2016-05-22 15:42:42 3C994D13A234D0E33D592CDF55F09B01 628736 ----a-w- C:\WINDOWS\Sysnative\MessagingDataModel2.dll 2016-05-22 15:42:42 19D88BF131158F4286294C372B4410B3 1946112 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2016-05-22 15:42:42 15D174719872A30F2FDD6B5B1B8BA5D9 1613664 ----a-w- C:\WINDOWS\Sysnative\diagtrack.dll 2016-05-22 15:42:42 0FEE16BB03B1A97A70121165E7414903 67584 ----a-w- C:\WINDOWS\Sysnative\profext.dll 2016-05-22 15:34:11 E91942A0D00C6AA014B2EA33EE0ED0A3 35480 ----a-w- C:\WINDOWS\Sysnative\TsWpfWrp.exe 2016-05-22 15:34:11 E2296A6174894682DF8F0FF29FDDCC82 1166520 ----a-w- C:\WINDOWS\Sysnative\PresentationNative_v0300.dll 2016-05-22 15:34:11 C5FEF4B4A7FB961ECDB0AB07DBCF379E 124624 ----a-w- C:\WINDOWS\Sysnative\PresentationCFFRasterizerNative_v0300.dll 2016-05-22 15:34:00 48E7F01CD9246CAF86702F5CB9100C9F 1087488 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2016-05-22 15:34:00 20B48DC4AF4492B31A756528444BDA8C 304752 ----a-w- C:\WINDOWS\Sysnative\systemreset.exe 2016-05-22 14:50:54 5C5A797761421CF9B72087F3BC8A5259 180 ----a-w- C:\WINDOWS\Sysnative\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-05-22 14:50:54 1373F6562D5E4C715D5D3583E350093E 200 ----a-w- C:\WINDOWS\Sysnative\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2016-05-22 14:50:51 E7806F4DF276CFBF72C72F8CF1F3626B 99848 ----a-w- C:\WINDOWS\Sysnative\OpenCL.DLL 2016-05-21 11:58:05 82446D358A9FB51CB9DA32A5C901D7A0 21040 ----a-w- C:\WINDOWS\Sysnative\sdnclean64.exe ====== C:\WINDOWS\Sysnative\drivers ===== 2016-05-28 17:52:34 786E8BCDFF674068F3C950615FC2E71C 37144 ----a-w- C:\WINDOWS\Sysnative\drivers\aswKbd.sys 2016-05-28 17:51:14 DF190688D993A3DB227BFB0BB40BD7D4 103064 ----a-w- C:\WINDOWS\Sysnative\drivers\aswRdr2.sys 2016-05-28 17:51:14 D873455DFA27680585AE238503917DF5 74544 ----a-w- C:\WINDOWS\Sysnative\drivers\aswRvrt.sys 2016-05-28 17:51:14 BA4CDCD8C0395E91C38CD2C5CE3E7FA2 287528 ----a-w- C:\WINDOWS\Sysnative\drivers\aswVmm.sys 2016-05-28 17:51:14 A371A06EC8F4830C263D3F5CA5A11B65 1070904 ----a-w- C:\WINDOWS\Sysnative\drivers\aswSnx.sys 2016-05-28 17:51:14 6B7F6CE19A16240EE9DE2C528897ED9C 465792 ----a-w- C:\WINDOWS\Sysnative\drivers\aswSP.sys 2016-05-28 17:51:14 3575F9226251DE48E065ED5C384A21EF 166432 ----a-w- C:\WINDOWS\Sysnative\drivers\aswStm.sys 2016-05-28 17:51:14 33D0DD0471FDF449C81338863FC63978 107792 ----a-w- C:\WINDOWS\Sysnative\drivers\aswMonFlt.sys 2016-05-28 17:51:14 1694434F5B9AB16772C7A8E2EF9134CA 37656 ----a-w- C:\WINDOWS\Sysnative\drivers\aswHwid.sys 2016-05-28 10:19:08 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\WINDOWS\Sysnative\drivers\MBAMSwissArmy.sys 2016-05-28 10:18:49 898415AC0B5F1D2A9A48ABCB68A6DC4B 65408 ----a-w- C:\WINDOWS\Sysnative\drivers\mwac.sys 2016-05-28 10:18:49 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\WINDOWS\Sysnative\drivers\mbam.sys 2016-05-28 10:18:49 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\WINDOWS\Sysnative\drivers\mbamchameleon.sys 2016-05-22 18:48:26 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\WINDOWS\Sysnative\drivers\EsgScanner.sys 2016-05-22 15:43:23 1A490555FD330CA2764D89191177C867 285696 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb10.sys 2016-05-22 15:43:21 083A727D784009F9CCFB120C7841B7AF 2403680 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2016-05-22 15:43:06 19BD8A88AAC580592668B070AC0727D9 2152280 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2016-05-22 15:43:00 E582DA849A58524E645545FB68B6625D 1152864 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2016-05-22 15:42:57 935823F79CBEDB91637B63D37E3A5A36 148480 ----a-w- C:\WINDOWS\Sysnative\drivers\dfsc.sys 2016-05-22 15:42:57 0B3B0C1D86050355676640488FA897D3 430944 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2016-05-22 15:42:54 EDDB0D726DBECDFC1DBCC6DB464E5A13 146272 ----a-w- C:\WINDOWS\Sysnative\drivers\appid.sys 2016-05-22 15:42:54 E3C82823B22463BC38AA4F8ADA852624 104960 ----a-w- C:\WINDOWS\Sysnative\drivers\rasl2tp.sys 2016-05-22 15:42:54 AA4CD20708B7E0412A5316D7E2875103 530432 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2016-05-22 15:42:54 A4411C522D41707D5BCA817A5BB9E30B 114688 ----a-w- C:\WINDOWS\Sysnative\drivers\bridge.sys 2016-05-22 15:42:54 2BC2E99623119521EEF7910A11D0FDE0 694784 ----a-w- C:\WINDOWS\Sysnative\drivers\WdiWiFi.sys 2016-05-22 15:42:49 B880BE37452AB1D4AA93845F58EF7960 95072 ----a-w- C:\WINDOWS\Sysnative\drivers\sdport.sys 2016-05-22 15:42:49 8F2523C9D8F1448FF2156452AF60FA00 87552 ----a-w- C:\WINDOWS\Sysnative\drivers\filecrypt.sys 2016-05-22 15:42:49 63C3F74DC398A1C1A77E39DFB9C312CA 1089888 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2016-05-22 15:42:48 48D8729FACC784900B831212AE56F824 1996640 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2016-05-22 15:42:48 3B866F8CB10719A5AF9E410B1B149714 605440 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2016-05-22 15:42:48 357910142E9285B978689B1DB4EFA00A 393568 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys 2016-05-22 15:42:48 01C01ED15ED56B98088CE1D5A0965E6A 577368 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys 2016-05-22 15:42:44 82D3B1F4D80057826AA649D78147DE36 63488 ----a-w- C:\WINDOWS\Sysnative\drivers\UcmCx.sys 2016-05-22 15:42:44 28B8E1C6CBCF9FFE2FABFF3160C26ADF 258912 ----a-w- C:\WINDOWS\Sysnative\drivers\ufx01000.sys 2016-05-22 15:42:43 67B9684B8272D5EBD1CCBB1DBD425EC8 99680 ----a-w- C:\WINDOWS\Sysnative\drivers\pdc.sys 2016-05-22 15:42:42 F279536122B83FD0D8E158AA753E1B7C 238592 ----a-w- C:\WINDOWS\Sysnative\drivers\xboxgip.sys 2016-05-22 15:42:42 E7463CE8579A0418A98BE9BE42C647D7 534872 ----a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2016-05-22 15:42:42 DA0807D87A62D076C29C4E30F1E84F46 26112 ----a-w- C:\WINDOWS\Sysnative\drivers\xinputhid.sys 2016-05-22 15:42:42 CFFE69B6C276A3418687109EA8AC9E7D 330072 ----a-w- C:\WINDOWS\Sysnative\drivers\pci.sys 2016-05-22 15:42:42 C330883C06E2D4CE4F6982F048265D37 335712 ----a-w- C:\WINDOWS\Sysnative\drivers\fastfat.sys 2016-05-22 15:42:42 C0752D58193603B6ED762B4027C65E1B 155136 ----a-w- C:\WINDOWS\Sysnative\drivers\hidclass.sys 2016-05-22 15:42:42 B24408471C1BCB17FC44F5B47EA8DEA3 277856 ----a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2016-05-22 15:42:42 9E9D58F5E1702955B2F4D62996F80E8E 378208 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2016-05-22 15:42:42 8949F77132A4F8F3BA17C6727099F002 127840 ----a-w- C:\WINDOWS\Sysnative\drivers\USBSTOR.SYS 2016-05-22 15:42:42 8359F776CA899E761852F2293B724EAE 185184 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2016-05-22 15:42:42 50DFE05C698E9B0A63D95E3D669A105C 638816 ----a-w- C:\WINDOWS\Sysnative\drivers\fvevol.sys 2016-05-22 15:42:42 4AAD6547953D373A1EB5B2DF583D868B 67072 ----a-w- C:\WINDOWS\Sysnative\drivers\usbser.sys 2016-05-22 15:42:42 469441BAE3FF8A16826FC62C51EF5E18 563552 ----a-w- C:\WINDOWS\Sysnative\drivers\acpi.sys 2016-05-22 15:42:42 2A87EA182EA333D79AA0B03833EA67F2 131424 ----a-w- C:\WINDOWS\Sysnative\drivers\ufxsynopsys.sys 2016-05-22 15:42:42 249A563C48DFD9E42A37587653E003BB 83968 ----a-w- C:\WINDOWS\Sysnative\drivers\serial.sys 2016-05-22 15:42:42 0731E8F4D8D3B8D3FD98A46A8ABFE0A0 333824 ----a-w- C:\WINDOWS\Sysnative\drivers\portcls.sys 2016-05-22 14:51:03 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_ASMBSW_01_11_00.Wdf 2016-05-22 14:49:38 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2016-05-13 07:49:38 34E103A5EFF7EADA5ADE6D61294FAA7F 7858088 ----a-w- C:\WINDOWS\Sysnative\drivers\igdkmd64.sys ====== C:\WINDOWS\Tasks ====== 2016-05-28 17:53:00 EA52029813D45B54D560179DAC88BED8 4000 ----a-w- C:\WINDOWS\Sysnative\Tasks\SafeZone scheduled Autoupdate 1464457972 2016-05-28 17:51:22 FE2344AB47DFF3C45540CC38EFE06451 4006 ----a-w- C:\WINDOWS\Sysnative\Tasks\avast! Emergency Update 2016-05-21 11:58:11 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\Safer-Networking ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2016-05-25 16:49:39 -------- d-----w- C:\Program Files\trend micro 2016-05-22 15:35:01 -------- d-----w- C:\Program Files\Reference Assemblies 2016-05-22 15:35:01 -------- d-----w- C:\Program Files\MSBuild 2016-05-22 14:51:06 -------- d-----w- C:\Program Files\Realtek 2016-05-22 14:50:54 -------- d-----w- C:\Program Files\ASUS 2016-05-22 14:50:12 -------- d-----w- C:\Program Files\Intel 2016-05-21 11:59:15 -------- d-----w- C:\Program Files\Common Files\AV 2016-05-17 21:47:42 -------- d-----w- C:\Program Files\iPod 2016-05-17 21:47:40 -------- d---a-w- C:\Program Files\iTunes ======= C:\PROGRA~2 ===== 2016-05-28 17:25:58 -------- d---a-w- C:\PROGRA~2\ZHPFix 2016-05-22 18:29:14 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2016-05-22 15:35:01 -------- d-----w- C:\PROGRA~2\Reference Assemblies 2016-05-22 15:35:01 -------- d-----w- C:\PROGRA~2\MSBuild 2016-05-22 14:50:57 -------- d-----w- C:\PROGRA~2\ASUS 2016-05-22 14:49:52 -------- d-----w- C:\PROGRA~2\COMMON~1\Intel 2016-05-17 21:47:42 -------- d-----w- C:\PROGRA~2\iTunes 2016-05-02 20:30:48 -------- d---a-w- C:\PROGRA~2\Blurry Video Clearer Free 2016-04-30 17:38:30 -------- d-----w- C:\PROGRA~2\PhotoScape ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2016-05-29 14:29:30 BC6A3500D447CCCC49C0F0C11B399CF3 57339 ----a-w- C:\Users\Gebruiker\AppData\Local\recently-used.xbel 2016-05-28 17:40:17 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Temp 2016-05-22 19:48:07 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\DataSharing 2016-05-22 15:21:30 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Avg 2016-05-22 15:12:47 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Packages 2016-05-22 15:06:18 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg 2016-05-22 14:53:55 -------- d-s---r- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 2016-05-22 14:53:55 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2016-05-22 14:53:55 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming 2016-05-22 14:53:55 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Microsoft 2016-05-22 14:53:55 -------- d-----w- C:\Users\Gebruiker\AppData\Local 2016-05-22 14:53:55 -------- d-----r- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2016-05-22 14:53:55 -------- d-----r- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2016-05-22 14:53:55 -------- d-----r- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2016-05-22 14:53:55 -------- d-----r- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs 2016-05-22 14:50:58 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft 2016-05-20 14:11:23 -------- d-----w- C:\Users\Gebruiker\AppData\Local\GetGo 2016-05-20 13:31:32 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Sony ====== C:\Users\Gebruiker ====== 2016-05-28 20:50:05 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Gebruiker\Downloads\mbam-setup-2.2.1.1043 (1).exe 2016-05-28 17:25:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2016-05-28 17:24:26 78546FB86AC0BDA85879BE7BBAF36FDB 3521617 ----a-w- C:\Users\Gebruiker\Desktop\ZHPFix.exe 2016-05-28 14:45:14 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2016-05-28 13:57:07 95DAE48CF9EB22F0A1C6FD196C75654B 2210304 ----a-w- C:\Users\Gebruiker\Downloads\ZHPDiag3.exe 2016-05-28 10:16:02 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Gebruiker\Downloads\mbam-setup-2.2.1.1043(1).exe 2016-05-28 08:09:00 FF1A65ED208854A4679FDB92838843B1 2383360 ----a-w- C:\Users\Gebruiker\Desktop\FRST64.exe 2016-05-26 14:35:34 -------- d-----w- C:\ProgramData\HitmanPro 2016-05-26 13:06:49 A55203B3BEA501A9E8FBF2B66B838E62 3678272 ----a-w- C:\Users\Gebruiker\Downloads\adwcleaner_5.118.exe 2016-05-25 16:49:19 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gebruiker\Downloads\RSITx64 (1).exe 2016-05-25 16:49:01 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gebruiker\Downloads\RSITx64.exe 2016-05-22 18:49:01 -------- d-----w- C:\Users\Gebruiker\Start Menu 2016-05-22 18:35:40 7DDD0BE2B01CE21B11B8F782CEADE10F 987728 ----a-w- C:\Users\Gebruiker\Downloads\ChromeSetup.exe 2016-05-22 18:17:23 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\.oracle_jre_usage 2016-05-22 18:14:46 AB51109EDB08CE704DAA3913A25782A0 5066104 ----a-w- C:\Users\Gebruiker\Downloads\avast_free_antivirus_setup_online.exe 2016-05-22 16:34:39 -------- d-----w- C:\ProgramData\Unchecky 2016-05-22 16:33:34 C5046BCC434B3985A107172E6B99CBD2 1443600 ----a-w- C:\Users\Gebruiker\Downloads\unchecky_setup.exe 2016-05-22 15:52:40 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Gebruiker\Downloads\mbam-setup-2.2.1.1043.exe 2016-05-22 15:27:03 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Gebruiker\ntuser.ini 2016-05-22 14:53:55 -------- d--h--w- C:\Users\Gebruiker\AppData 2016-05-22 14:51:16 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\ProgramData\DP45977C.lfl 2016-05-20 21:32:04 1F14A3768CB568E4AA89C568903F5CC4 242200 ----a-w- C:\Users\Gebruiker\Downloads\Firefox Setup Stub 46.0.1.exe 2016-05-20 14:17:28 -------- d--h--w- C:\ProgramData\Common Files 2016-05-20 14:10:32 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free VPN 2016-05-20 13:58:39 79EBF8011EA2F6669CAE221EC7FDBA83 2181680 ----a-w- C:\Users\Gebruiker\Downloads\winrar-x64-54b1.exe 2016-05-20 13:20:16 5610F50DF4BFE31CFE4CBDC72262E1A4 411005560 ----a-w- C:\Users\Gebruiker\Downloads\vegaspro13.0.453.exe 2016-05-17 21:47:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-05-10 21:44:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2016-05-02 20:30:51 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blurry Video Clearer Free 2016-04-30 17:38:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape ====== C: exe-files == 2016-05-29 18:55:09 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\A1E0E559-FDB1-4F06-AB10-93A19E0A4AD9\DismHost.exe 2016-05-29 18:12:08 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\5B774AC0-63F1-4EF1-A39A-91CC3D54E0F2\DismHost.exe 2016-05-29 17:08:26 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\F3A96B50-D7CA-42DC-906A-4308BE3CCBF4\DismHost.exe 2016-05-29 17:03:17 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\3F9EBAA7-3627-4385-882D-FF9C420D88B0\DismHost.exe 2016-05-29 15:29:48 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\E3106B2E-2AC1-40B3-BC70-516590F3AE38\DismHost.exe 2016-05-29 15:21:58 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\9D20D00C-8533-46E0-B886-2A23984F830A\DismHost.exe 2016-05-29 14:48:43 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\34246C09-EDCF-43FD-BEB4-F0D22F14A6C9\DismHost.exe 2016-05-28 20:50:05 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Gebruiker\Downloads\mbam-setup-2.2.1.1043 (1).exe 2016-05-28 17:25:58 F3A37421DBD1AAA36558C97572C91C5A 147456 ----a-w- C:\Program Files (x86)\ZHPFix\catchme.exe 2016-05-28 17:25:58 C573A6CB885554F9B162AC4709A78407 3061760 ----a-w- C:\Program Files (x86)\ZHPFix\ZHPFix.exe 2016-05-28 17:25:58 C155A13687144076286989EF078112C2 1917440 ----a-w- C:\Program Files (x86)\ZHPFix\ZHPhep.exe 2016-05-28 17:25:58 9DAA7218961710008D7385B01BD3F386 89088 ----a-w- C:\Program Files (x86)\ZHPFix\mbr.exe 2016-05-28 17:25:58 9658565C1728E9B7F9F45C907E2028D9 694736 ----a-w- C:\Program Files (x86)\ZHPFix\unins000.exe 2016-05-28 17:25:58 53CDBB093B0AEE9FD6CF1CBD25A95077 290304 ----a-w- C:\Program Files (x86)\ZHPFix\subinacl.exe 2016-05-28 17:25:58 451AE03D3C92777F09840CA56F08AB62 454056 ----a-w- C:\Program Files (x86)\ZHPFix\setacl32.exe 2016-05-28 17:25:58 3E350EB5DF15C06DEC400A39DD1C6F29 559528 ----a-w- C:\Program Files (x86)\ZHPFix\setacl64.exe 2016-05-28 17:24:26 78546FB86AC0BDA85879BE7BBAF36FDB 3521617 ----a-w- C:\Users\Gebruiker\Desktop\ZHPFix.exe 2016-05-28 13:58:17 95DAE48CF9EB22F0A1C6FD196C75654B 2210304 ----a-w- C:\Users\Gebruiker\AppData\Roaming\ZHP\ZHPDiag3.exe 2016-05-28 13:57:07 95DAE48CF9EB22F0A1C6FD196C75654B 2210304 ----a-w- C:\Users\Gebruiker\Downloads\ZHPDiag3.exe 2016-05-28 10:16:02 52F4695C53B02ADA7D648F95F2E2F8B4 22851472 ----a-w- C:\Users\Gebruiker\Downloads\mbam-setup-2.2.1.1043(1).exe 2016-05-28 08:09:00 FF1A65ED208854A4679FDB92838843B1 2383360 ----a-w- C:\Users\Gebruiker\Desktop\FRST64.exe 2016-05-26 13:06:49 A55203B3BEA501A9E8FBF2B66B838E62 3678272 ----a-w- C:\Users\Gebruiker\Downloads\adwcleaner_5.118.exe 2016-05-25 16:49:40 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruiker.exe 2016-05-25 16:49:19 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gebruiker\Downloads\RSITx64 (1).exe 2016-05-25 16:49:01 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gebruiker\Downloads\RSITx64.exe 2016-05-24 13:35:47 08F835066C531779237C2CBD67AC7991 147456 ----a-w- C:\Users\Gebruiker\AppData\Local\Packages\34908JigsawPuzzlephotosud.MahjongDeluxeHD-Shanghai_2ty3rvq1c6b9m\AC\Microsoft\CLR_v4.0_32\NativeImages\mahjong\f92c8a4574c0c36cf8d1f64570e58116\mahjong.ni.exe === C: other files == 2016-05-28 17:52:34 786E8BCDFF674068F3C950615FC2E71C 37144 ----a-w- C:\Windows\System32\drivers\aswKbd.sys 2016-05-28 17:51:14 DF190688D993A3DB227BFB0BB40BD7D4 103064 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys 2016-05-28 17:51:14 D873455DFA27680585AE238503917DF5 74544 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys 2016-05-28 17:51:14 BA4CDCD8C0395E91C38CD2C5CE3E7FA2 287528 ----a-w- C:\Windows\System32\drivers\aswVmm.sys 2016-05-28 17:51:14 A371A06EC8F4830C263D3F5CA5A11B65 1070904 ----a-w- C:\Windows\System32\drivers\aswSnx.sys 2016-05-28 17:51:14 6B7F6CE19A16240EE9DE2C528897ED9C 465792 ----a-w- C:\Windows\System32\drivers\aswSP.sys 2016-05-28 17:51:14 3575F9226251DE48E065ED5C384A21EF 166432 ----a-w- C:\Windows\System32\drivers\aswStm.sys 2016-05-28 17:51:14 33D0DD0471FDF449C81338863FC63978 107792 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2016-05-28 17:51:14 1694434F5B9AB16772C7A8E2EF9134CA 37656 ----a-w- C:\Windows\System32\drivers\aswHwid.sys 2016-05-28 17:40:17 2D9A27911C7209D31767D912FBF253EC 150281 ----a-w- C:\Users\Gebruiker\Downloads\ProxyFix.zip 2016-05-28 10:19:08 78488AF2AB2111D67B3C4044707A519B 192216 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys 2016-05-28 10:18:49 898415AC0B5F1D2A9A48ABCB68A6DC4B 65408 ----a-w- C:\Windows\System32\drivers\mwac.sys 2016-05-28 10:18:49 78BFF5425E044086E74E78650A359FBB 27008 ----a-w- C:\Windows\System32\drivers\mbam.sys 2016-05-28 10:18:49 1239597BAB7EED2BB16D035AF87E65D9 140672 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys 2016-05-23 16:22:45 5818311C3B9DAEF629B6D1480D6D6BE0 17416 ----a-w- C:\Users\Gebruiker\Desktop\Oude Firefox-gegevens\x68rv29s.default-1419717149148\extensions\bingsearch.full@microsoft.com.xpi ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-2083432871-1646923358-3950239412-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Google Update"="C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe /c" "OneDrive"="C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "BingSvc"="C:\Users\Gebruiker\AppData\Local\Microsoft\BingSvc\BingSvc.exe" "SpybotPostWindows10UpgradeReInstall"="C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe" "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" "ArcSoft Connection Service"="C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "SDTray"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Google Update"="C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe /c" "OneDrive"="C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "BingSvc"="C:\Users\Gebruiker\AppData\Local\Microsoft\BingSvc\BingSvc.exe" "SpybotPostWindows10UpgradeReInstall"="C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "CanonSolutionMenu"="C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon" "CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [13-05-2016 14:20] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12-09-2015 11:39] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12-09-2015 11:39] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2083432871-1646923358-3950239412-1001Core.job --a-------- C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe [27-08-2015 20:15] C:\WINDOWS\tasks\WebReg HP Deskjet F300 series.job --a-------- C:\Program Files (x86)\HP\Digital Imaging\bin\hpqwrg.exe [29-04-2011 09:03] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\Apple Diagnostics" [C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2083432871-1646923358-3950239412-1001Core" [C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\SafeZone scheduled Autoupdate 1464457972" [C:\Program Files\AVAST Software\SZBrowser\launcher.exe] "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2016-02-13 13:29:13 -------- d-----w- C:\PROGRA~3\USOShared 2016-02-13 13:34:23 -------- d-----w- C:\PROGRA~3\Microsoft OneDrive 2016-03-28 14:44:21 -------- d-----w- C:\PROGRA~3\Avnex 2016-03-28 17:31:02 -------- d-----w- C:\PROGRA~3\AVS4YOU 2016-03-29 15:06:04 -------- d-----w- C:\PROGRA~3\Apowersoft 2016-03-30 13:57:15 -------- d-----w- C:\PROGRA~3\Movavi Video Editor 11 2016-03-30 19:04:16 -------- d-----w- C:\PROGRA~3\Real 2016-04-22 11:51:49 -------- d-----w- C:\PROGRA~3\Movavi Video Converter 16 2016-04-22 11:52:15 -------- d-----w- C:\PROGRA~3\Movavi 2016-05-20 14:17:28 -------- d--h--w- C:\PROGRA~3\Common Files 2016-05-21 11:58:04 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy 2016-05-22 15:26:08 -------- d-sh--we C:\PROGRA~3\Application Data 2016-05-22 16:34:39 -------- d-----w- C:\PROGRA~3\Unchecky 2016-05-22 18:15:16 -------- d-----w- C:\PROGRA~3\AVAST Software 2016-05-26 14:35:34 -------- d-----w- C:\PROGRA~3\HitmanPro ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\p6xulgba.default-1464020546821 user_pref("browser.startup.homepage", "http://www.google.nl/"); user_pref("browser.newtab.url", "about:newtab"); ProfilePath: C:\Users\GEBRUI~1\AppData\Roaming\Thunderbird\Profiles\gvxios7q.default user_pref("browser.startup.homepage", "http://www.google.nl/"); user_pref("browser.newtab.url", "about:newtab"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28-05-2016 19:51] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28-05-2016 19:51] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "MFVersion"="MF41.0.2 (x86 nl)" []