Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 03-05-2020 Gestart door Erwin (Beheerder) op LAPTOP-GUG6CUUV (Acer Aspire ES1-523) (07-05-2020 09:09:39) Gestart vanaf C:\Users\Erwin\Downloads Geladen Profielen: Erwin (Beschikbare Profielen: defaultuser0 & Erwin) Platform: Windows 10 Home Versie 1909 18363.778 (X64) Taal: Nederlands (Nederland) Standaardbrowser: Chrome Boot Modus: Normal Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processen (gefilterd) ================= (Als een item is opgenomen in de fixlist, zal het proces worden gesloten. Het bestand zal niet worden verplaatst.) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe (AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <2> (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <22> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\Erwin\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ==================== Register (gefilterd) =================== (Als een item is opgenomen in de fixlist, zal het registeritem worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16419072 2016-02-26] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [108728 2020-05-04] (Avast Software s.r.o. -> AVAST Software) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-07] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== AANDACHT HKU\S-1-5-21-2074649015-76847304-505890287-1001\...\Run: [AvastBrowserAutoLaunch_74989FA8DEBBD6BE3A48653A86DCD6E4] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-08] (Avast Software s.r.o. -> AVAST Software) HKU\S-1-5-21-2074649015-76847304-505890287-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-2074649015-76847304-505890287-1001\...\Run: [ShowBatteryBar] => C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2014-09-19] () [Bestand niet getekend] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\Installer\chrmstp.exe [2020-05-07] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.3970.92\Installer\chrmstp.exe [2020-05-04] (Avast Software s.r.o. -> AVAST Software) FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restrictie <==== AANDACHT CHR HKLM\SOFTWARE\Policies\Google: Restrictie <==== AANDACHT ==================== Geplande Taken (gefilterd) ============ (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) Task: {00ADB035-6258-4E9E-998D-702D74EB5FAA} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software s.r.o. -> AVAST Software) Task: {05A12E31-DDBD-475F-B7C5-05DDC96EB8D2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23772528 2020-04-28] (Microsoft Corporation -> Microsoft Corporation) Task: {0AC56F72-D5B0-4ACE-98BF-CC59E95C5F56} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-05-01] (Piriform Software Ltd -> Piriform Software Ltd) Task: {32688897-5116-4381-9385-C3A1F836B19E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-03-23] (Google Inc -> Google Inc.) Task: {3337B513-CC86-41DF-AB9C-29E6592D618C} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [216296 2014-03-13] (Acer Incorporated -> TODO: ) Task: {3CD07A0D-7DBA-479E-9426-215F79185091} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe Task: {3D4D0719-AA67-4928-A342-8BCE41BC5393} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23772528 2020-04-28] (Microsoft Corporation -> Microsoft Corporation) Task: {3EE92BC3-A8E0-4E59-899F-03257AE3A680} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [422704 2016-09-14] (Acer Incorporated -> Acer Incorporated) Task: {42DAD435-67EA-460E-BF1F-1AF669376D6D} - System32\Tasks\AcerCMUpdateTask2.1.16258 => C:\Program Files (x86)\Acer\Amundsen\2.1.16258\AWC.exe [152880 2016-09-20] (Acer Incorporated -> ) Task: {4466ECAF-CE43-4030-AC26-6C864B9275D9} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1429400 2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Task: {493A2D41-F4A4-48BD-9AA2-372F8859D8A8} - System32\Tasks\DashlaneUpgradeCheck => net [Argument = start "Dashlane Upgrade Service"] Task: {56B425E9-E366-47D9-9B4F-3E0300D33824} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software) Task: {64DA6427-16E5-4E63-A6AB-8909799A81C5} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2437920 2017-10-02] (Acer Incorporated -> Acer) Task: {66AA97B0-B35F-43DF-ADC6-9B353BE53679} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [472992 2016-06-25] (Acer Incorporated -> Acer Incorporated) Task: {6F837A4B-D23F-42C4-82A5-4C162E10157B} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3339472 2020-05-04] (Avast Software s.r.o. -> AVAST Software) Task: {847FCD4B-AAE8-49CF-9761-0D81D1BDBA08} - System32\Tasks\Power Button => C:\Program Files\Acer\Acer Quick Access\ePowerButton_NB.exe [2767152 2016-09-14] (Acer Incorporated -> Acer Incorporated) Task: {87C14139-DF5B-456C-BC44-9DB5FAB16C0F} - System32\Tasks\Oem\AcerJumpstartTask => C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe [64320 2019-07-11] (Acer Incorporated -> Acer) Task: {892CB997-EF04-4FDA-84F2-D88F1E2A248B} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software s.r.o. -> AVAST Software) Task: {8A5A45ED-D77E-43C1-8EAB-A97F6D248F90} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124776 2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Task: {8E118BE1-5B0F-4782-96A0-AB6C0F5149B9} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [124776 2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Task: {9CABA1D2-C3FB-4197-B3B6-43E19C4F8131} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2919840 2016-06-25] (Acer Incorporated -> ) Task: {A62E2694-55F4-4AB2-978A-29AE636E7308} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-08] (Avast Software s.r.o. -> AVAST Software) Task: {AC245E9B-B567-4EC7-866C-E6F22E6F1893} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-08] (Avast Software s.r.o. -> AVAST Software) Task: {B4DB7B56-D983-45FB-B519-A7CFB11E1FEF} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [65752 2017-03-20] (Acer Incorporated -> Acer Incorporated) Task: {B6A2CE9C-CBCA-4E54-AEF2-AB8FAA8373CA} - System32\Tasks\FubToolByPLD => C:\OEM\Preload\FubTool\FubTool.exe [30976 2015-05-14] (Acer Incorporated -> ) Task: {BD031D99-99B5-4F57-8B40-3B08B708318E} - \Microsoft\Windows\UNP\RunCampaignManager -> Geen bestand <==== AANDACHT Task: {CE403525-7340-497C-9A54-F89272FD40C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-03-23] (Google Inc -> Google Inc.) Task: {D577B2DD-BE7B-4468-B1A2-521828E8E885} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems) Task: {D60AD589-246E-488C-9EB2-4842917D5F98} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [23571128 2020-05-01] (Piriform Software Ltd -> Piriform Software Ltd) Task: {DED07CA7-5DCC-463B-AF42-3FE5E772973C} - System32\Tasks\Acer Collection Monitor Application => C:\Program Files (x86)\Acer\Acer Collection\ACEMon.exe [417072 2017-12-13] (Acer Incorporated -> Acer Incorporated) Task: {E4424DFD-F600-488E-B788-900FF0B15907} - System32\Tasks\App Explorer => C:\Users\Erwin\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [6998936 2018-09-17] (SweetLabs Inc. -> SweetLabs, Inc) <==== AANDACHT Task: {E6C649C3-60BB-4375-9D84-3CBF0F483279} - System32\Tasks\Acer Collection Application => C:\Program Files (x86)\Acer\Acer Collection\ACEStd.exe [479024 2017-12-14] (Acer Incorporated -> ) Task: {E81FF0D1-830E-476C-93B0-0DC59D94AAFF} - System32\Tasks\Microsoft\Windows\rempl\shell => C:\Program Files\rempl\sedlauncher.exe Task: {EEC62A28-D122-46BF-87B5-D54C83541992} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [40352 2016-06-25] (Acer Incorporated -> ) Task: {F5760FC2-B18D-4426-9650-8747D5E5260E} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4644256 2016-06-25] (Acer Incorporated -> ) (Als een item is opgenomen in de fixlist, wordt de taak (job) bestand verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.) ==================== Internet (gefilterd) ==================== (Als een item is opgenomen in de fixlist en een registeritem is, wordt het verwijderd of hersteld naar de standaard.) Tcpip\Parameters: [DhcpNameServer] 195.130.130.1 195.130.131.1 Tcpip\..\Interfaces\{1c83dde7-7db1-4d17-a940-8cf87cd37f3b}: [DhcpNameServer] 195.130.130.1 195.130.131.1 Tcpip\..\Interfaces\{f260706f-c139-415b-a7ec-5b7ea001d9da}: [DhcpNameServer] 195.130.130.1 195.130.131.1 Internet Explorer: ================== HKU\S-1-5-21-2074649015-76847304-505890287-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer17win10.msn.com/?pc=ACTE HKU\S-1-5-21-2074649015-76847304-505890287-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer17win10.msn.com/?pc=ACTE SearchScopes: HKU\S-1-5-21-2074649015-76847304-505890287-1001 -> DefaultScope {880FD7D3-F8BF-4BEB-8234-D85787094E2E} URL = SearchScopes: HKU\S-1-5-21-2074649015-76847304-505890287-1001 -> {880FD7D3-F8BF-4BEB-8234-D85787094E2E} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-12] (Microsoft Corporation -> Microsoft Corporation) BHO: Geen Naam -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> Geen bestand BHO-x32: Geen Naam -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> Geen bestand Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-05-04] (Microsoft Corporation -> Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - Geen bestand Edge: ====== DownloadDir: C:\Users\Erwin\Downloads Edge Notifications: HKU\S-1-5-21-2074649015-76847304-505890287-1001 -> hxxps://www.facebook.com FireFox: ======== FF DefaultProfile: u3s3wyp3.default FF ProfilePath: C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\ir0ax6nv.default-release [2020-05-05] FF Extension: (Avast SafePrice | Prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\ir0ax6nv.default-release\Extensions\sp@avast.com.xpi [2019-02-11] FF Extension: (Avast Online Security) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\ir0ax6nv.default-release\Extensions\wrc@avast.com.xpi [2018-06-23] FF ProfilePath: C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default [2020-05-05] FF Extension: (Amazon Assistant for Firefox) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\abb-acer@amazon.com [2017-03-25] [Verouderd] FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\langpack-nl@firefox.mozilla.org.xpi [2020-04-17] FF Extension: (Mozilla Partner Defaults) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\partnerdefaults@mozilla.com [2017-03-25] [Verouderd] FF Extension: (Avast SafePrice | Prijsvergelijking, aanbiedingen, waardebonnen) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\sp@avast.com.xpi [2019-02-11] FF Extension: (uBlock Origin) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\uBlock0@raymondhill.net.xpi [2018-03-25] FF Extension: (Avast Online Security) - C:\Users\Erwin\AppData\Roaming\Mozilla\Firefox\Profiles\u3s3wyp3.default\Extensions\wrc@avast.com.xpi [2020-04-17] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json] FF Extension: (Amazon Assistant for Firefox) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb-acer@amazon.com [2017-01-11] [Verouderd] FF Extension: (Nederlands (NL) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-nl@firefox.mozilla.org [2017-01-11] [Verouderd] FF Extension: (Mozilla Partner Defaults) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\partnerdefaults@mozilla.com [2017-01-11] [Verouderd] FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-12] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default [2020-05-07] CHR Notifications: Default -> hxxps://0.bo8news.biz; hxxps://allevents.in; hxxps://badoo.com; hxxps://be.jobtome.com; hxxps://be.locale.online; hxxps://belgium.joob24.com; hxxps://doorbraak.be; hxxps://en.nametests.com; hxxps://koopjeskrant.os.tc; hxxps://m.hln.be; hxxps://m.nieuwsblad.be; hxxps://nl.metrotime.be; hxxps://nl.nametests.com; hxxps://nl.newsner.com; hxxps://nl.pepper.com; hxxps://nl.softonic.com; hxxps://onlinecasino.os.tc; hxxps://order.dominos.be; hxxps://p-magazine.be; hxxps://sceptr.net; hxxps://vtm.be; hxxps://www.4tube.com; hxxps://www.alibaba.com; hxxps://www.apost.com; hxxps://www.captchaverify.net; hxxps://www.cinenews.be; hxxps://www.demorgen.be; hxxps://www.facebook.com; hxxps://www.fashionnova.com; hxxps://www.google.be; hxxps://www.gratissoftware.nu; hxxps://www.gva.be; hxxps://www.hbvl.be; hxxps://www.hln.be; hxxps://www.huisvlijt.com; hxxps://www.hunkemoller.be; hxxps://www.instagram.com; hxxps://www.jetcost.nl; hxxps://www.kortingvandedag.be; hxxps://www.mydates.com; hxxps://www.nieuwsblad.be; hxxps://www.pc-helpforum.be; hxxps://www.playamo.com; hxxps://www.spydeals.be; hxxps://www.voetbalprimeur.be; hxxps://www.want.nl; hxxps://www.wattedoen.be; hxxps://www.wish.com; hxxps://www.wittybunny.com; hxxps://www.youtube.com; hxxps://www.zita.be CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Extension: (Presentaties) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12] CHR Extension: (Documenten) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12] CHR Extension: (Google Drive) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17] CHR Extension: (YouTube) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-23] CHR Extension: (Adblock Plus - gratis adblocker) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-04-06] CHR Extension: (Spreadsheets) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12] CHR Extension: (Offline Documenten) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-20] CHR Extension: (Save to Facebook) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfikkaogpplgnfjmbjdpalkhclendgd [2019-06-27] CHR Extension: (Jitsi Meetings) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kglhbbefdnlheedjiejgomgmfplipfeb [2020-04-24] CHR Extension: (Officieel Lierse Forum • Forumoverzicht) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\neiolngelljlmindhccjghagabpfifek [2017-05-12] CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03] CHR Extension: (Gmail) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-04] CHR Extension: (Chrome Media Router) - C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-10] CHR Profile: C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-05-05] CHR Profile: C:\Users\Erwin\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-05] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] ==================== Services (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [560536 2017-10-24] (Advanced Micro Devices, Inc. -> AMD) S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6350752 2020-05-04] (Avast Software s.r.o. -> AVAST Software) S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [348968 2020-05-04] (Avast Software s.r.o. -> AVAST Software) S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-23] (AVAST Software s.r.o. -> AVAST Software) S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.3970.92\elevation_service.exe [954600 2020-04-08] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [58048 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2278616 2017-03-20] (Acer Incorporated -> Acer Incorporated) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10610544 2020-04-28] (Microsoft Corporation -> Microsoft Corporation) S2 Dashlane Upgrade Service; C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe [83992 2017-08-23] (Dashlane -> Dashlane, Inc.) S3 GoogleChromeElevationService1d510e85524787a; C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\elevation_service.exe [1095664 2020-05-02] (Google LLC -> Google LLC) S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-03-15] (Malwarebytes Inc -> Malwarebytes) S3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [441136 2016-09-14] (Acer Incorporated -> Acer Incorporated) S3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [482608 2016-09-14] (Acer Incorporated -> Acer Incorporated) S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [295840 2016-05-28] (Acer Incorporated -> acer) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2001.10-0\NisSrv.exe [3285864 2020-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2001.10-0\MsMpEng.exe [103168 2020-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. ) R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0319312.inf_amd64_1bd7dae294b3987b\atikmdag.sys [36566432 2017-10-24] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0319312.inf_amd64_1bd7dae294b3987b\atikmpag.sys [537504 2017-10-24] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [82704 2016-06-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R0 amdpsp; C:\WINDOWS\System32\DRIVERS\amdpsp.sys [243048 2017-06-16] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. ) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37136 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [205880 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [234560 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [178760 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [60480 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2020-02-25] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42784 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [175704 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [501472 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [109272 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84856 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [851592 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460992 2020-05-04] (Avast Software s.r.o. -> AVAST Software) S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [235488 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [319120 2020-05-04] (Avast Software s.r.o. -> AVAST Software) R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-22] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices) R3 Kb9xI2c; C:\WINDOWS\System32\drivers\Kb9xI2c.sys [37888 2015-05-19] (Microsoft Windows Hardware Compatibility Publisher -> ENE TECHNOLOGY INC.) R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1010648 2017-11-07] (Realtek Semiconductor Corp. -> Realtek ) S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [416472 2016-05-17] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation) S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [25608 2019-01-06] (AVG Technologies CZ, s.r.o. -> SlimWare Utilities, Inc.) R3 SynRMIHID; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [57448 2015-10-26] (Synaptics Incorporated -> Synaptics Incorporated) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-03-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [376544 2020-03-14] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2020-03-14] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (gefilterd) =================== (Als een item is opgenomen in de fixlist, wordt het uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.) ==================== Een maand (aangemaakt) =================== (Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.) 2020-05-07 09:09 - 2020-05-07 09:12 - 000029483 _____ C:\Users\Erwin\Downloads\FRST.txt 2020-05-07 09:09 - 2020-05-07 09:11 - 000000000 ____D C:\FRST 2020-05-07 09:08 - 2020-05-07 09:08 - 002283520 _____ (Farbar) C:\Users\Erwin\Downloads\FRST64 (2).exe 2020-05-07 09:06 - 2020-05-07 09:06 - 002283520 _____ (Farbar) C:\Users\Erwin\Downloads\FRST64 (1).exe 2020-05-07 09:05 - 2020-05-07 09:05 - 002283520 _____ (Farbar) C:\Users\Erwin\Downloads\FRST64.exe 2020-05-07 08:54 - 2020-05-07 08:54 - 000000000 ___HD C:\OneDriveTemp 2020-05-05 21:45 - 2020-05-05 21:46 - 006889184 _____ (Piriform Ltd) C:\Users\Erwin\Downloads\spsetup132.exe 2020-05-04 21:07 - 2020-05-04 21:06 - 000337560 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2020-05-04 21:07 - 2020-05-04 21:06 - 000235488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2020-05-04 21:07 - 2020-05-04 21:06 - 000175704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2020-05-04 18:33 - 2020-05-04 18:33 - 000001960 _____ C:\Users\Erwin\Downloads\startup.txt 2020-05-04 18:29 - 2020-05-04 18:29 - 000004886 _____ C:\Users\Erwin\Documents\startup4.txt 2020-05-04 18:29 - 2020-05-04 18:29 - 000001332 _____ C:\Users\Erwin\Documents\startup3.txt 2020-05-04 18:28 - 2020-05-04 18:28 - 000001960 _____ C:\Users\Erwin\Documents\startup.txt 2020-05-04 18:28 - 2020-05-04 18:28 - 000001948 _____ C:\Users\Erwin\Documents\STARTUP2.txt 2020-05-04 09:26 - 2020-05-04 09:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\Taken voor Logboeken 2020-05-04 09:15 - 2020-05-04 09:15 - 000000000 ___HD C:\$SysReset 2020-05-04 01:26 - 2020-05-04 01:26 - 000000460 _____ C:\Users\Erwin\Documents\cc_20200504_012649.reg 2020-05-04 01:24 - 2020-05-04 01:24 - 000000017 _____ C:\Users\Erwin\AppData\Local\resmon.resmoncfg 2020-05-03 20:16 - 2020-05-04 10:16 - 000000000 ____D C:\WINDOWS\Minidump 2020-05-03 16:23 - 2020-05-03 16:23 - 000001656 _____ C:\Users\Erwin\Documents\cc_20200503_162344.reg 2020-04-24 16:17 - 2020-04-24 16:17 - 000531568 _____ C:\Users\Erwin\Downloads\zenderlijst-082019.pdf 2020-04-23 21:22 - 2020-04-23 21:22 - 000000500 _____ C:\Users\Erwin\Documents\cc_20200423_212206.reg 2020-04-18 10:10 - 2020-04-18 10:10 - 000000435 _____ C:\Users\Erwin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlock.lnk 2020-04-18 09:37 - 2020-04-18 09:37 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe 2020-04-18 09:37 - 2020-04-18 09:37 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll 2020-04-18 09:37 - 2020-04-18 09:37 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 022636544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 007756800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 004611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 002951832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001545216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001077064 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 000775696 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2020-04-18 09:36 - 2020-04-18 09:36 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2020-04-18 09:36 - 2020-04-18 09:36 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe 2020-04-18 09:36 - 2020-04-18 09:36 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2020-04-18 09:36 - 2020-04-18 09:36 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2020-04-18 09:36 - 2020-04-18 09:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2020-04-18 09:35 - 2020-04-18 09:36 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 004563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 003802624 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 003753472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 003547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 002767928 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 002086656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2020-04-18 09:35 - 2020-04-18 09:35 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001665216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001646048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 001261808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001243648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000759272 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000618296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000515600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000513576 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2020-04-18 09:35 - 2020-04-18 09:35 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000277864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000259776 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000251704 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000147696 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000089336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000066624 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000033080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys 2020-04-18 09:35 - 2020-04-18 09:35 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2020-04-18 09:35 - 2020-04-18 09:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2020-04-18 09:35 - 2020-04-18 09:35 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2020-04-18 09:34 - 2020-04-18 09:35 - 001512832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2020-04-18 09:34 - 2020-04-18 09:34 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001656904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001603584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 001427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001378528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 001011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000915192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000811320 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000684560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2020-04-18 09:34 - 2020-04-18 09:34 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2020-04-18 09:34 - 2020-04-18 09:34 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll 2020-04-18 09:34 - 2020-04-18 09:34 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll 2020-04-18 09:33 - 2020-04-18 09:34 - 003109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 017790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 007849216 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 003587384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 002131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 002126144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 002114560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001960448 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000879616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000437560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000339304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000297272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000231912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000151352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2020-04-18 09:33 - 2020-04-18 09:33 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys 2020-04-18 09:33 - 2020-04-18 09:33 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll 2020-04-18 09:33 - 2020-04-18 09:33 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys 2020-04-18 08:46 - 2020-04-18 08:46 - 000000080 ___SH C:\bootTel.dat 2020-04-18 07:59 - 2020-03-17 05:57 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2020-04-18 07:59 - 2020-03-17 05:56 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2020-04-17 17:43 - 2020-04-17 17:43 - 022267336 _____ (Piriform Software Ltd) C:\Users\Erwin\Downloads\ccsetup565.exe 2020-04-17 10:44 - 2020-04-17 10:44 - 000000874 _____ C:\Users\Erwin\Documents\cc_20200417_104426.reg 2020-04-17 08:07 - 2020-04-17 08:07 - 000000896 _____ C:\Users\Erwin\Documents\cc_20200417_080721.reg 2020-04-15 05:43 - 2020-05-04 21:06 - 000501472 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetHub.sys 2020-04-08 18:36 - 2020-04-08 18:47 - 000000000 ____D C:\Users\Erwin\AppData\Roaming\BatteryBar 2020-04-08 18:36 - 2020-04-08 18:36 - 000000000 ____D C:\Program Files\BatteryBar 2020-04-08 18:34 - 2020-04-08 18:34 - 001318648 _____ C:\Users\Erwin\Downloads\BatteryBarSetup-3.6.6.exe 2020-04-08 18:26 - 2020-04-08 18:26 - 000154492 _____ C:\Users\Erwin\Downloads\Luminus_002007000631.pdf 2020-04-07 06:48 - 2020-05-04 21:19 - 000000000 ____D C:\Program Files\Mozilla Firefox ==================== Een maand (gewijzigd) ================== (Als een item is opgenomen in de fixlist, wordt de map of het bestand verplaatst.) 2020-05-07 09:07 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-05-07 08:55 - 2017-09-27 13:52 - 000000000 ____D C:\Users\Erwin\AppData\Local\AVAST Software 2020-05-07 08:55 - 2017-04-19 19:17 - 000000000 ____D C:\ProgramData\AVAST Software 2020-05-07 08:54 - 2017-04-07 17:20 - 000000000 ____D C:\Users\Erwin\AppData\Local\CrashDumps 2020-05-07 08:54 - 2017-03-23 22:11 - 000000000 ___RD C:\Users\Erwin\OneDrive 2020-05-07 04:34 - 2020-03-30 09:26 - 000003506 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2020-05-07 04:34 - 2020-03-30 09:26 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2020-05-07 04:34 - 2020-03-30 09:26 - 000003282 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2020-05-07 04:34 - 2020-03-30 09:26 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2020-05-07 04:34 - 2020-03-30 09:26 - 000002850 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2074649015-76847304-505890287-1001 2020-05-07 04:34 - 2020-03-30 09:26 - 000002214 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC 2020-05-07 04:34 - 2020-03-30 09:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software 2020-05-07 04:28 - 2017-03-23 22:25 - 000002325 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-05-07 04:27 - 2017-03-23 22:25 - 000002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-05-07 04:27 - 2017-03-23 22:25 - 000002284 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-05-07 04:23 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-05-07 04:23 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-05-06 22:08 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF 2020-05-06 20:41 - 2020-03-30 09:26 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2020-05-05 23:28 - 2017-04-19 21:27 - 000000000 ____D C:\Program Files\CCleaner 2020-05-05 23:18 - 2020-03-30 09:26 - 000003510 _____ C:\WINDOWS\system32\Tasks\DashlaneUpgradeCheck 2020-05-05 23:15 - 2020-03-30 09:26 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-05-05 23:14 - 2019-03-19 06:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2020-05-05 23:14 - 2017-05-24 18:19 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2020-05-05 21:47 - 2018-02-12 23:25 - 000000841 _____ C:\Users\Public\Desktop\Speccy.lnk 2020-05-05 21:47 - 2018-02-12 23:25 - 000000841 _____ C:\ProgramData\Desktop\Speccy.lnk 2020-05-05 08:41 - 2018-07-12 05:48 - 000000000 ____D C:\ProgramData\Packages 2020-05-04 21:19 - 2017-01-11 02:50 - 000001009 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-05-04 21:18 - 2017-01-11 02:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2020-05-04 21:07 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2020-05-04 21:06 - 2019-01-14 17:36 - 000234560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys 2020-05-04 21:06 - 2019-01-06 15:19 - 000178760 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys 2020-05-04 21:06 - 2019-01-06 15:19 - 000060480 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys 2020-05-04 21:06 - 2019-01-06 15:19 - 000037136 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys 2020-05-04 21:06 - 2018-10-11 05:43 - 000042784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000851592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000460992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000319120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000205880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000109272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2020-05-04 21:06 - 2017-11-20 12:54 - 000084856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2020-05-04 17:57 - 2020-03-30 09:26 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) 2020-05-04 17:57 - 2020-03-30 09:26 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon) 2020-05-04 17:57 - 2018-03-23 19:45 - 000002522 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk 2020-05-04 17:57 - 2018-03-23 19:45 - 000002487 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk 2020-05-04 17:57 - 2018-03-23 19:45 - 000002487 _____ C:\ProgramData\Desktop\Avast Secure Browser.lnk 2020-05-04 10:16 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2020-05-04 08:09 - 2020-03-30 08:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-05-04 07:18 - 2017-01-11 01:56 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2020-05-03 23:05 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2020-05-03 21:53 - 2020-03-30 08:48 - 000000000 ____D C:\Users\Erwin 2020-04-28 18:25 - 2017-04-05 04:37 - 000000000 ____D C:\Users\Erwin\Documents\Outlook-bestanden 2020-04-28 15:10 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\NDF 2020-04-24 13:24 - 2019-07-08 19:04 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2020-04-18 11:46 - 2020-03-30 09:04 - 001771832 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-04-18 11:46 - 2019-03-19 14:33 - 000787394 _____ C:\WINDOWS\system32\perfh013.dat 2020-04-18 11:46 - 2019-03-19 14:33 - 000154388 _____ C:\WINDOWS\system32\perfc013.dat 2020-04-18 11:37 - 2020-03-30 08:37 - 000432056 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\Provisioning 2020-04-18 11:34 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2020-04-18 10:45 - 2017-11-20 14:08 - 000000000 ____D C:\Users\Erwin\AppData\Local\Packages 2020-04-18 09:45 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\servicing 2020-04-17 17:48 - 2020-03-24 20:01 - 000000000 ___DC C:\WINDOWS\Panther 2020-04-17 17:44 - 2017-04-19 21:27 - 000000867 _____ C:\Users\Public\Desktop\CCleaner.lnk 2020-04-17 17:44 - 2017-04-19 21:27 - 000000867 _____ C:\ProgramData\Desktop\CCleaner.lnk 2020-04-17 08:33 - 2017-04-02 17:17 - 000000000 ____D C:\Users\Erwin\AppData\LocalLow\Mozilla 2020-04-17 08:00 - 2020-03-30 08:48 - 000002410 _____ C:\Users\Erwin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-04-16 20:21 - 2017-06-01 06:44 - 000002092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2020-04-16 20:21 - 2017-06-01 06:44 - 000002080 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2020-04-16 20:21 - 2017-06-01 06:44 - 000002080 _____ C:\ProgramData\Desktop\Avast Free Antivirus.lnk 2020-04-16 20:17 - 2017-01-11 02:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-04-07 09:33 - 2017-03-23 22:23 - 000001417 _____ C:\Users\Erwin\Desktop\Microsoft Edge.lnk ==================== Bestanden in de root van sommige mappen ======== 2020-05-04 01:24 - 2020-05-04 01:24 - 000000017 _____ () C:\Users\Erwin\AppData\Local\resmon.resmoncfg 2019-02-14 20:33 - 2019-02-14 20:33 - 000000000 _____ () C:\Users\Erwin\AppData\Local\{379C1DB1-06A9-4F8A-A0A1-FAA653E0A2A4} 2019-02-14 20:33 - 2019-02-14 20:33 - 000000000 _____ () C:\Users\Erwin\AppData\Local\{C7CA95A7-4603-48EA-A3DD-8D3A81BED2B3} ==================== SigCheck ============================ (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.) ==================== Einde van FRST.txt ========================