Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 03-05-2020 Gestart door Bettina (Beheerder) op BETTINA-PC (Hewlett-Packard HP Compaq dx2300 Microtower) (05-05-2020 19:32:56) Gestart vanaf C:\Users\Bettina\Desktop Geladen Profielen: Bettina (Beschikbare Profielen: Bettina) Platform: Windows 10 Home Versie 1909 18363.778 (X64) Taal: Nederlands (Nederland) Standaardbrowser: Edge Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, zal het proces worden gesloten. Het bestand zal niet worden verplaatst.) (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Facebook, Inc. -> Facebook) C:\Users\Bettina\AppData\Local\Facebook\Games\FacebookGameroom.exe (Gadwin, Ltd. -> Gadwin Systems, Inc) C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <16> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2004.6-0\NisSrv.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe ==================== Register (gefilterd) =================== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKU\S-1-5-21-3029372247-2320051476-2110462517-1000\...\Run: [Gadwin PrintScreen] => C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe [1842384 2012-05-30] (Gadwin, Ltd. -> Gadwin Systems, Inc) HKU\S-1-5-21-3029372247-2320051476-2110462517-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22256824 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.129\Installer\chrmstp.exe [2020-05-01] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> Startup: C:\Users\Bettina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2020-04-23] ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Bettina\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) ==================== Geplande Taken (gefilterd) ============ (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {2A22EFDF-D15B-4A4C-9F8B-DBB093EE4BF6} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3029372247-2320051476-2110462517-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} Task: {2B4CF73A-55F5-46C5-B8ED-9F8348C29658} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2018-01-31] (Google Inc -> Google Inc.) Task: {3583E4AC-D645-4EE5-98F1-C9EB3D458322} - System32\Tasks\{1084A7D9-8F5D-4A25-A2F6-FB30C821249A} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (12).exe" -d C:\Users\Bettina\Downloads Task: {3FE38A9B-93A8-4259-8A8D-A2FC44D3F824} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {41C91D86-77A0-4D1F-9AE4-9BBD962A42CD} - System32\Tasks\{017700BA-820C-4269-A0E2-5761C1BBE904} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12EDJYIX\FacebookGameroom.exe" -d C:\Users\Bettina\Desktop Task: {43485D74-D25B-4E7D-B956-B9DFC8DA7637} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [485944 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47c2-B62A-B7C4CED925CB} Task: {5226C2FE-7ECC-44FC-920A-FE0B1A3991A1} - System32\Tasks\{3B57D1E1-151D-4483-A119-9A2CECA93814} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEITLXJU\FacebookGameroom.exe" -d C:\Users\Bettina\Desktop Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A} Task: {75C31ED9-C17E-4EFD-8016-9C755F3CE924} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [485944 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {78B78AE3-623B-4E5F-A488-347C8FCF1358} - System32\Tasks\{5A109A6C-D19C-4D47-ACD4-3A3B337CB3C9} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (15).exe" -d C:\Users\Bettina\Downloads Task: {78E655E6-F2BC-4C96-9006-971CF4077C10} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-04-15] (Adobe Inc. -> Adobe) Task: {7D21F9E8-84C2-499C-B386-F714B21394A2} - System32\Tasks\{BB605778-3A0E-4707-8B90-6B0CE9FCD2EC} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (31).exe" -d C:\Users\Bettina\Downloads Task: {7E927C11-9DCF-4EE0-8731-C4F876496A11} - System32\Tasks\{FEAA44AA-4820-421D-B228-765ECBA95A78} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (9).exe" -d C:\Users\Bettina\Downloads Task: {8561F5E5-E370-4833-B77F-17294DD7803E} - System32\Tasks\{FB16F034-82DF-4549-B498-2C28D014A449} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe [82232 2018-01-30] (Panda Security S.L. -> Panda Security, S.L.) Task: {86CF6D7E-A18E-4D31-8EA2-3C763373E0F3} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43da-BFD7-FBEEA2180A1E} Task: {8B313E9A-3D2A-45E7-B93E-5BA303C18750} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_363_pepper.exe [1454136 2020-04-15] (Adobe Inc. -> Adobe) Task: {8F26841F-64EE-4B98-B3A1-DEF7D1D07F92} - System32\Tasks\{549792D0-8877-4B2E-BA92-77DCE5CEC051} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (20).exe" -d C:\Users\Bettina\Downloads Task: {92FCCF94-C119-4104-8C24-32BC5C613099} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18233016 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe Task: {A5C07C3F-7549-4C00-B51C-2BC8BD35F3DB} - System32\Tasks\{C50F966C-3C8B-43D5-B9A7-25F55C3737EB} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZLT9HX7Y\FacebookGameroom.exe" -d C:\Users\Bettina\Desktop Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371} Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe Task: {CF1AFDA5-2671-4FE0-9624-62A58AEBB991} - System32\Tasks\{2BCA9490-19E4-4FA1-AD7B-268156B21A15} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (13).exe" -d C:\Users\Bettina\Downloads Task: {D3CF4747-4BA5-42C6-8B25-07C8D98D1390} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [126152 2020-04-27] (Mozilla Corporation -> Mozilla Foundation) Task: {D89D5606-54FB-4BF2-A82B-27A0580ED5F2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2018-01-31] (Google Inc -> Google Inc.) Task: {DECDAC23-6A4C-48D6-A7FB-61F1BE032D1B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [485944 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E1FE0CE5-8061-41B2-8101-00A3C38CDFAD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems) Task: {F43D479C-0130-43D6-8E77-AFDA092ABCFE} - System32\Tasks\{E5552598-76F9-4C3D-9169-447F24109B99} => C:\Windows\system32\pcalua.exe -a "C:\Users\Bettina\Downloads\FacebookGameroom (33).exe" -d C:\Users\Bettina\Downloads Task: {FC65DFEC-978D-41BD-A8EB-A3A92A781BAC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MpCmdRun.exe [485944 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) (Als een item is opgenomen in de fixlist, wordt de taak (job) bestand verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) Task: C:\WINDOWS\Tasks\{FB16F034-82DF-4549-B498-2C28D014A449}.job => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist en een registeritem is, wordt het verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 62.179.104.196 213.46.228.196 Tcpip\..\Interfaces\{580A5421-C682-466D-81EC-94AD6D0FB9D3}: [DhcpNameServer] 62.179.104.196 213.46.228.196 Internet Explorer: ================== HKU\S-1-5-21-3029372247-2320051476-2110462517-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.msn.com/?OCID=IE11FREDHP&PC=UF01 SearchScopes: HKU\S-1-5-21-3029372247-2320051476-2110462517-1000 -> {4D05569D-511D-4B93-B06B-FBA21E31A78E} URL = hxxp://www.google.com/search?q={searchTerms} BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-01-31] (Google Inc -> Google Inc.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-01-31] (Google Inc -> Google Inc.) BHO-x32: Geen Naam -> {C0E8AE32-0758-4C8D-AB71-23B361FE8964} -> Geen bestand Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2018-01-31] (Google Inc -> Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2018-01-31] (Google Inc -> Google Inc.) DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab Edge: ====== Edge Profile: C:\Users\Bettina\AppData\Local\Microsoft\Edge\User Data\Default [2020-05-01] FireFox: ======== FF DefaultProfile: xmuctk1g.default FF ProfilePath: C:\Users\Bettina\AppData\Roaming\Mozilla\Firefox\Profiles\xmuctk1g.default [2020-05-05] FF Notifications: Mozilla\Firefox\Profiles\xmuctk1g.default -> hxxps://www.facebook.com FF HKLM\...\Firefox\Extensions: [@sandblast] - => niet gevonden FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1231201.dll [2017-11-02] (Adobe Systems, Inc.) [Bestand niet getekend] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default [2020-05-05] CHR Notifications: Default -> hxxps://creativecosmetics.pushcrew.com; hxxps://fr.wearetests.com; hxxps://nl.softonic.com; hxxps://www.autowereld.nl; hxxps://www.bestekrabbels.nl; hxxps://www.bewegenzonderpijn.com; hxxps://www.rotterdammersvoorelkaar.nl CHR HomePage: Default -> hxxp://www.google.nl/ CHR NewTab: Default -> Not-active:"chrome-extension://maajolkefbigbiaekfgmkiehhkeaodpk/newtabpage.html", Not-active:"chrome-extension://dmieilohcciojgiclflbcgnkacbbgden/newtabproduct.html", Not-active:"chrome-extension://lgbfeddflgjmcjkinakpbljigfgdgekj/newtabproduct.html" CHR DefaultSearchURL: Default -> hxxps://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&enableSearch=true&rdrct=no&redirect=CPC CHR DefaultSearchKeyword: Default -> ask CHR DefaultSuggestURL: Default -> hxxps://ss.search.ask.com/ss?li=ff&sstype=prefix&limit=10&hl=en&q={searchTerms}&enableSearch=true&rdrct=no CHR Extension: (DirectionsBuilder) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmieilohcciojgiclflbcgnkacbbgden [2020-03-26] CHR Extension: (Adobe Acrobat) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-03-03] CHR Extension: (Landleven Flash Helper) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmglheppjkpgkfaggfjegmdjkekjfejl [2019-09-07] CHR Extension: (FileShareFanatic) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgbfeddflgjmcjkinakpbljigfgdgekj [2019-12-18] CHR Extension: (Ask Web Search) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2020-03-31] CHR Extension: (GetFormsFree) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\maajolkefbigbiaekfgmkiehhkeaodpk [2019-12-20] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04] CHR Extension: (Landleven Flash Helper) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\omldfnjkkomljkdoipakddglciohipoc [2019-09-28] CHR Extension: (Zoom in op afbeeldin) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbfffoifiebmakblbndlomkkilcdoham [2018-12-15] CHR Extension: (Chrome Media Router) - C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-23] CHR Profile: C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-04-29] CHR Profile: C:\Users\Bettina\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-29] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Services (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [109024 2017-11-08] (Panda Security S.L. -> Panda Security, S.L.) S3 Panda VPN Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\Hydra.Sdk.Windows.Service.exe [320848 2017-11-20] (AnchorFree Inc -> ) R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [84176 2019-02-19] (Panda Security S.L. -> Panda Security, S.L.) R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [48784 2017-10-18] (Panda Security S.L. -> Panda Security, S.L.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13252624 2020-04-23] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\NisSrv.exe [3304992 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MsMpEng.exe [103376 2020-05-01] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) S3 b06diag; C:\WINDOWS\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation -> Broadcom Corporation) S3 BFN7x64; C:\WINDOWS\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc. -> Bigfoot Networks, Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [231936 2019-10-07] (Microsoft Corporation) [Bestand niet getekend] S3 bxfcoe; C:\WINDOWS\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation -> Broadcom Corporation) S3 bxois; C:\WINDOWS\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation -> Broadcom Corporation) R3 E100B; C:\WINDOWS\System32\drivers\efe5b32e.sys [182656 2019-03-19] (Microsoft Windows -> Intel Corporation) R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [108000 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [211936 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [121312 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [126432 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [99512 2017-09-26] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [118240 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPIHSW; C:\WINDOWS\System32\DRIVERS\NNSPIHSW.sys [91616 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [135648 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [336352 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [249312 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [123360 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [281056 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [125920 2017-11-06] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [191448 2017-11-09] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [153992 2018-01-23] (Panda Security S.L. -> Panda Security, S.L.) R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [207248 2018-01-30] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [146912 2017-10-17] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [159200 2017-10-17] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [129504 2017-10-17] (Panda Security S.L. -> Panda Security, S.L.) S3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72280 2017-05-22] (Panda Security S.L. -> Panda Security, S.L.) R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> ) S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> ) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-05-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [394680 2020-05-01] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64944 2020-05-01] (Microsoft Windows -> Microsoft Corporation) U3 idsvc; geen ImagePath ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een maand (aangemaakt) =================== (Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.) 2020-05-05 19:29 - 2020-05-05 19:36 - 000021398 _____ C:\Users\Bettina\Desktop\Addition.txt 2020-05-05 19:23 - 2020-05-05 19:35 - 000022647 _____ C:\Users\Bettina\Desktop\FRST.txt 2020-05-05 19:23 - 2020-05-05 19:34 - 000000000 ____D C:\FRST 2020-05-05 15:23 - 2020-05-05 15:23 - 002283520 _____ (Farbar) C:\Users\Bettina\Desktop\FRST64.exe 2020-05-05 15:22 - 2020-05-05 15:22 - 002283520 _____ (Farbar) C:\Users\Bettina\Downloads\FRST64.exe 2020-05-04 22:38 - 2020-05-04 22:38 - 000034608 _____ C:\urls.set 2020-05-04 22:18 - 2020-05-05 02:05 - 000000000 ____D C:\Program Files\Restoro 2020-05-04 22:17 - 2020-05-05 02:04 - 000000150 _____ C:\WINDOWS\restoro.ini 2020-05-04 22:17 - 2020-05-04 22:17 - 000931056 _____ (Restoro) C:\Users\Bettina\Downloads\Restoro (1).exe 2020-05-04 22:16 - 2020-05-04 22:17 - 000931056 _____ (Restoro) C:\Users\Bettina\Downloads\Restoro.exe 2020-05-01 14:09 - 2020-05-01 22:22 - 000002397 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-05-01 14:09 - 2020-05-01 22:22 - 000002356 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-05-01 13:38 - 2020-05-01 13:38 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup (4).exe 2020-05-01 13:38 - 2020-05-01 13:38 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup (3).exe 2020-05-01 13:34 - 2020-05-01 13:34 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup (2).exe 2020-05-01 13:19 - 2020-05-01 13:20 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup(4).exe 2020-05-01 13:19 - 2020-05-01 13:19 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup(3).exe 2020-05-01 13:18 - 2020-05-01 13:18 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup(2).exe 2020-05-01 13:17 - 2020-05-01 13:17 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup(1).exe 2020-04-30 11:29 - 2020-04-30 11:29 - 000099883 _____ C:\Users\Bettina\Downloads\NL83INGB0691722307_20-04-2020_29-04-2020.pdf 2020-04-27 01:12 - 2020-04-27 11:25 - 000000000 ____D C:\ProgramData\Fighters 2020-04-27 01:12 - 2020-04-27 01:13 - 000000000 ____D C:\Users\Bettina\AppData\Roaming\Fighters 2020-04-27 01:04 - 2020-04-27 01:05 - 004280488 _____ (SPAMfighter ApS.) C:\Users\Bettina\Downloads\SLOW-PCfighter_web.exe 2020-04-27 00:23 - 2020-04-27 00:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2020-04-27 00:04 - 2020-04-29 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2020-04-25 21:13 - 2020-04-25 21:13 - 000000000 ____D C:\Users\Bettina\AppData\Local\TeamViewer 2020-04-25 21:12 - 2020-05-04 22:40 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2020-04-25 21:12 - 2020-04-25 21:12 - 000001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk 2020-04-25 21:12 - 2020-04-25 21:12 - 000001104 _____ C:\Users\Public\Desktop\TeamViewer.lnk 2020-04-25 21:12 - 2020-04-25 21:12 - 000000000 ____D C:\Users\Bettina\AppData\Roaming\TeamViewer 2020-04-25 21:10 - 2020-04-25 21:10 - 027347176 _____ (TeamViewer Germany GmbH) C:\Users\Bettina\Downloads\TeamViewer_Setup (2).exe 2020-04-25 21:01 - 2020-04-25 21:01 - 027347176 _____ (TeamViewer Germany GmbH) C:\Users\Bettina\Downloads\TeamViewer_Setup.exe 2020-04-25 21:01 - 2020-04-25 21:01 - 027347176 _____ (TeamViewer Germany GmbH) C:\Users\Bettina\Downloads\TeamViewer_Setup (1).exe 2020-04-25 15:57 - 2020-05-05 02:10 - 000001630 _____ C:\Users\Bettina\Desktop\ScreenShot406 - Snelkoppeling.lnk 2020-04-25 01:08 - 2020-04-25 01:09 - 016921304 _____ (Corel Corporation) C:\Users\Bettina\Downloads\SimpleDriverUpdaterSetup_ppc3.exe 2020-04-24 09:56 - 2020-04-24 09:56 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup (1).exe 2020-04-24 09:55 - 2020-04-24 09:55 - 001295576 _____ (Google LLC) C:\Users\Bettina\Downloads\ChromeSetup.exe 2020-04-23 22:42 - 2020-04-23 22:42 - 000001285 _____ C:\Users\Bettina\Desktop\Facebook Gameroom.lnk 2020-04-23 22:42 - 2020-04-23 22:42 - 000000000 ____D C:\Users\Bettina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook 2020-04-23 22:40 - 2020-04-23 22:40 - 000419800 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (48).exe 2020-04-23 22:37 - 2020-04-23 22:37 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (47).exe 2020-04-23 22:11 - 2020-04-23 22:11 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (46).exe 2020-04-23 21:35 - 2020-04-23 21:35 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (45).exe 2020-04-23 21:31 - 2020-04-23 21:31 - 000001661 _____ C:\Users\Bettina\Downloads\FacebookGameroom (2) - Snelkoppeling.lnk 2020-04-23 21:30 - 2020-04-23 21:30 - 000001661 _____ C:\Users\Bettina\Downloads\FacebookGameroom (44) - Snelkoppeling.lnk 2020-04-23 21:29 - 2020-04-23 21:29 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (44).exe 2020-04-23 11:22 - 2020-04-23 11:23 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (43).exe 2020-04-23 11:06 - 2020-04-23 11:06 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (42).exe 2020-04-23 11:05 - 2020-04-23 11:04 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Documents\FacebookGameroom (41).exe 2020-04-23 11:04 - 2020-04-23 11:04 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (41).exe 2020-04-23 11:02 - 2020-04-23 11:02 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (40).exe 2020-04-23 02:18 - 2020-04-23 02:18 - 000000926 _____ C:\Users\Bettina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FacebookGameroom (39).lnk 2020-04-23 02:16 - 2020-04-23 02:16 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (39).exe 2020-04-23 02:08 - 2020-04-23 02:08 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (38).exe 2020-04-23 01:48 - 2020-04-23 01:48 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (37).exe 2020-04-23 01:30 - 2020-04-23 01:30 - 000419888 _____ (Facebook Technologies, LLC) C:\Users\Bettina\Downloads\FacebookGameroom (55).exe 2020-04-20 10:23 - 2020-04-20 10:23 - 000112670 _____ C:\Users\Bettina\Downloads\5306457_467277327.pdf 2020-04-15 15:51 - 2020-04-15 15:51 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 004611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 002951832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 001545216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2020-04-15 15:51 - 2020-04-15 15:51 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe 2020-04-15 15:51 - 2020-04-15 15:51 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll 2020-04-15 15:51 - 2020-04-15 15:51 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 022636544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 007756800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 003753472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 002767928 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 002086656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001665216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001646048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001077064 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000775696 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000618296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2020-04-15 15:50 - 2020-04-15 15:50 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2020-04-15 15:50 - 2020-04-15 15:50 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000277864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000147696 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000089336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000066624 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000033080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys 2020-04-15 15:50 - 2020-04-15 15:50 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe 2020-04-15 15:50 - 2020-04-15 15:50 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2020-04-15 15:50 - 2020-04-15 15:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2020-04-15 15:49 - 2020-04-15 15:50 - 003802624 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 017790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 007849216 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 004563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 003587384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 003547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 003109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 002114560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001960448 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2020-04-15 15:49 - 2020-04-15 15:49 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001656904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001603584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001512832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 001497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 001427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001378528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 001261808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001243648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 001011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000915192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000811320 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000759272 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000684560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000515600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000513576 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2020-04-15 15:49 - 2020-04-15 15:49 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000339304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000259776 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000251704 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000231912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2020-04-15 15:49 - 2020-04-15 15:49 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll 2020-04-15 15:49 - 2020-04-15 15:49 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 002131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 002126144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000879616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 000437560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000297272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000151352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe 2020-04-15 15:48 - 2020-04-15 15:48 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll 2020-04-15 15:48 - 2020-04-15 15:48 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys 2020-04-15 15:48 - 2020-04-15 15:48 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys 2020-04-15 15:22 - 2020-03-17 05:57 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2020-04-15 15:22 - 2020-03-17 05:56 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe ==================== Een maand (gewijzigd) ================== (Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.) 2020-05-05 19:25 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-05-05 19:23 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF 2020-05-05 19:06 - 2019-11-30 12:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-05-05 02:11 - 2017-01-11 23:38 - 000001375 _____ C:\Users\Bettina\Desktop\Internet Explorer.lnk 2020-05-05 01:52 - 2016-12-16 19:43 - 000000000 ____D C:\Users\Bettina\AppData\LocalLow\Mozilla 2020-05-04 22:39 - 2019-11-30 13:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-05-04 22:39 - 2019-03-19 06:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2020-05-04 02:12 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2020-05-04 02:12 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Macromed 2020-05-02 15:23 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-05-02 15:23 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-05-01 14:09 - 2017-04-26 01:32 - 000000000 ____D C:\Program Files (x86)\Google 2020-05-01 13:33 - 2019-11-30 13:09 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2020-04-30 00:53 - 2019-07-04 21:52 - 000002146 _____ C:\Users\Bettina\Desktop\Cookie Jam.lnk 2020-04-30 00:41 - 2017-01-14 17:10 - 000001220 _____ C:\Users\Bettina\Desktop\Gadwin PrintScreen.lnk 2020-04-29 20:54 - 2016-12-16 19:42 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-04-28 21:28 - 2019-11-30 11:06 - 000000000 ___DC C:\WINDOWS\Panther 2020-04-27 01:28 - 2019-11-29 16:30 - 000000913 _____ C:\Users\Bettina\Desktop\Speccy.lnk 2020-04-27 00:23 - 2016-12-16 19:42 - 000001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-04-26 12:31 - 2019-11-30 12:43 - 000317920 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2020-04-25 23:56 - 2016-12-16 23:31 - 000000000 ____D C:\Users\Bettina\AppData\Local\ElevatedDiagnostics 2020-04-25 23:21 - 2017-12-15 21:19 - 000000262 _____ C:\Users\Bettina\Desktop\Run.lnk 2020-04-24 01:37 - 2019-11-30 22:20 - 000001375 _____ C:\Users\Bettina\Desktop\Internet Explorer (2).lnk 2020-04-23 22:42 - 2017-07-16 12:54 - 000000000 ____D C:\Users\Bettina\AppData\Local\Facebook 2020-04-23 21:40 - 2019-11-30 13:22 - 000000000 ____D C:\Users\Bettina\AppData\Local\PlaceholderTileLogoFolder 2020-04-23 21:40 - 2019-11-30 13:13 - 000000000 ____D C:\Users\Bettina\AppData\Local\Publishers 2020-04-23 21:40 - 2019-11-30 13:12 - 000000000 ____D C:\Users\Bettina\AppData\Local\Packages 2020-04-21 21:41 - 2019-11-30 13:46 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3029372247-2320051476-2110462517-1000 2020-04-21 21:40 - 2019-11-30 13:46 - 000000000 ___RD C:\Users\Bettina\OneDrive 2020-04-21 21:40 - 2019-11-30 12:57 - 000002415 _____ C:\Users\Bettina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-04-18 02:14 - 2019-11-30 12:57 - 000000000 ____D C:\Users\Bettina 2020-04-15 18:31 - 2019-11-30 12:56 - 001977780 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-04-15 18:31 - 2019-03-19 14:33 - 000861714 _____ C:\WINDOWS\system32\perfh013.dat 2020-04-15 18:31 - 2019-03-19 14:33 - 000188528 _____ C:\WINDOWS\system32\perfc013.dat 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\Provisioning 2020-04-15 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2020-04-15 15:59 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2020-04-15 11:56 - 2019-11-30 13:09 - 000004704 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier ==================== Bestanden in de root van sommige mappen ======== 2017-01-01 04:28 - 2017-01-01 04:28 - 000000036 _____ () C:\Users\Bettina\AppData\Local\housecall.guid.cache 2018-11-01 15:26 - 2018-11-01 15:26 - 000000017 _____ () C:\Users\Bettina\AppData\Local\resmon.resmoncfg 2019-05-09 01:15 - 2019-05-09 01:15 - 000000000 _____ () C:\Users\Bettina\AppData\Local\{922033FD-8AC1-4840-85B4-F76EC5385EF6} ==================== SigCheck ============================ (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) ==================== Einde van FRST.txt ========================