First:
Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 29-06-2017
Gestart door hikma (Beheerder) op DESKTOP-9OP5E15 (29-06-2017 13:57:25)
Gestart vanaf C:\Users\hikma\Desktop
Geladen Profielen: hikma (Beschikbare Profielen: hikma)
Platform: Windows 10 Home Versie 1703 (X64) Taal: Dutch (Netherlands)
Internet Explorer Versie 11 (Standaardbrowser: Chrome)
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool:
FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processen (gefilterd) =================
(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe
(Bluestack System Inc. ) C:\Program Files (x86)\BlueStacks\BstkSVC.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Register (gefilterd) ====================
(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1307720 2013-04-24] (Realtek Semiconductor)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{C12EDCD9-A219-4778-A5FC-0D0F1F219F12}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{C12EDCD9-A219-47 (de data item heeft 36 mee tekens).
HKU\S-1-5-21-2934984055-1632560249-2123969850-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [160824 2017-05-24] (BlueStack Systems, Inc.)
GroupPolicy: Restrictie - Chrome <==== AANDACHT
==================== Internet (gefilterd) ====================
(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)
Tcpip\Parameters: [DhcpNameServer] 195.130.131.2 195.130.130.2
Tcpip\..\Interfaces\{1a4286df-61dd-4388-860e-fa1b4acd841f}: [DhcpNameServer] 195.130.131.2 195.130.130.2
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2934984055-1632560249-2123969850-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://
www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
SearchScopes: HKU\S-1-5-21-2934984055-1632560249-2123969850-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://
www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-25] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-25] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-24] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-24] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-24] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-24] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-24] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-24] (Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-28] (Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.google.be/
CHR StartupUrls: Default -> "hxxp://
www.google.be/"
CHR Profile: C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default [2017-06-29]
CHR Extension: (Google Slides) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-28]
CHR Extension: (Google Docs) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-28]
CHR Extension: (Google Drive) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-28]
CHR Extension: (YouTube) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-28]
CHR Extension: (Cookies On-Off) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\dceidjjhomnclmfgflmjaomohekdgdgb [2017-06-28]
CHR Extension: (Gmail Offline) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2017-06-28]
CHR Extension: (Google Calendar) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-06-28]
CHR Extension: (Google Sheets) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-28]
CHR Extension: (Google Docs Offline) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-28]
CHR Extension: (AdBlock) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-06-28]
CHR Extension: (Video Downloader Pro) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilppkoakomgpcblpemgbloapenijdcho [2017-06-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-28]
CHR Extension: (Gmail) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-28]
CHR Extension: (Chrome Media Router) - C:\Users\hikma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-28]
CHR HKLM-x32\...\Chrome\Extension: [iinglghmhcgdgjjlafobajghjamdchik] - hxxps://clients2.google.com/service/update2/crx
==================== Services (gefilterd) ====================
(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [387128 2017-05-24] (BlueStack Systems, Inc.)
R3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-05-24] (BlueStack Systems, Inc.)
R3 BstHdPlusAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe [406584 2017-05-24] (BlueStack Systems, Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4122816 2017-06-10] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corp.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370064 2015-09-30] (Intel Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1254736 2017-04-11] (Bitdefender)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [8515952 2017-05-14] (Reimage®)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10884848 2017-05-23] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
===================== Drivers (gefilterd) ======================
(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
S3 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [152672 2017-05-24] (BlueStack Systems)
R3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-05-22] (Bluestack System Inc. )
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 LeapdroidVMDrv; C:\Program Files\Leapdroid\VM\LeapdroidVMDrv.sys [300952 2017-06-24] (Leapdroid Inc.)
S3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R3 MEIx64; C:\WINDOWS\System32\drivers\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R1 MpKsle42845c5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F85BC33B-79D8-46EF-AFAA-C310293E4416}\MpKsle42845c5.sys [44928 2017-06-29] (Microsoft Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_9d2734742a07f3cf\nvlddmkm.sys [14456920 2017-05-18] (NVIDIA Corporation)
S3 QRDCIO; C:\WINDOWS\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
S3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [751632 2015-05-14] (Realsil Semiconductor Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2016-09-05] (QUALCOMM Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (gefilterd) ===================
(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)
==================== Een Maand Aangemaakt bestanden en mappen ========
(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)
2017-06-29 13:57 - 2017-06-29 13:58 - 00013745 _____ C:\Users\hikma\Desktop\FRST.txt
2017-06-29 13:57 - 2017-06-29 13:57 - 00000000 ____D C:\FRST
2017-06-29 13:56 - 2017-06-29 13:56 - 02440704 _____ (Farbar) C:\Users\hikma\Downloads\FRST64.exe
2017-06-29 13:56 - 2017-06-29 13:56 - 02440704 _____ (Farbar) C:\Users\hikma\Desktop\FRST64.exe
2017-06-29 10:11 - 2017-06-29 10:11 - 00000000 ___HD C:\OneDriveTemp
2017-06-29 01:02 - 2017-06-29 01:02 - 00003548 _____ C:\WINDOWS\System32\Tasks\Reimage Reminder
2017-06-29 01:01 - 2017-06-29 01:02 - 00000000 ____D C:\rei
2017-06-29 01:01 - 2017-06-29 01:02 - 00000000 ____D C:\ProgramData\Reimage Protector
2017-06-29 01:01 - 2017-06-29 01:01 - 00004352 _____ C:\WINDOWS\System32\Tasks\ReimageUpdater
2017-06-29 01:01 - 2017-06-29 01:01 - 00001988 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2017-06-29 01:01 - 2017-06-29 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2017-06-29 01:01 - 2017-06-29 01:01 - 00000000 ____D C:\Program Files\Reimage
2017-06-29 01:00 - 2017-06-29 01:02 - 00000140 _____ C:\WINDOWS\Reimage.ini
2017-06-29 01:00 - 2017-06-29 01:00 - 00604928 _____ (Reimage) C:\Users\hikma\Downloads\ReimageRepair.exe
2017-06-29 00:25 - 2017-06-29 00:25 - 00216696 _____ C:\ProgramData\cl.uninstall.1498688601.bdinstall.bin
2017-06-29 00:23 - 2017-06-29 00:23 - 00035978 _____ C:\ProgramData\dm.uninstall.1498688612.bdinstall.bin
2017-06-29 00:20 - 2017-06-29 00:20 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Macromedia
2017-06-28 23:50 - 2017-06-28 23:50 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Bandicam Company
2017-06-28 23:49 - 2017-06-29 00:07 - 00000000 ____D C:\Users\hikma\Documents\Bandicam
2017-06-28 23:49 - 2017-06-28 23:49 - 00001065 _____ C:\Users\Public\Desktop\Bandicam.lnk
2017-06-28 23:49 - 2017-06-28 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2017-06-28 23:49 - 2017-06-28 23:49 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
2017-06-28 23:49 - 2017-06-28 23:49 - 00000000 ____D C:\Program Files (x86)\Bandicam
2017-06-28 23:48 - 2017-06-28 23:48 - 17122224 _____ (Bandicam Company) C:\Users\hikma\Downloads\bdcamsetup.exe
2017-06-28 23:20 - 2017-06-28 23:20 - 00002352 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-28 23:20 - 2017-06-28 23:20 - 00002340 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-28 23:18 - 2017-06-28 23:18 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-06-28 23:18 - 2017-06-28 23:18 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-06-28 17:48 - 2017-06-28 18:24 - 00008728 _____ C:\Users\hikma\Documents\inkomsten en uitgaven.xlsx
2017-06-28 17:48 - 2017-06-28 17:48 - 00000000 ____D C:\Users\hikma\Documents\Aangepaste Office-sjablonen
2017-06-28 11:10 - 2017-06-28 11:10 - 00000000 ____D C:\Users\hikma\.Origin
2017-06-28 11:09 - 2017-06-28 11:10 - 54864456 _____ (Electronic Arts) C:\Users\hikma\Downloads\OriginThinSetup.exe
2017-06-27 20:33 - 2017-06-27 20:39 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Notepad++
2017-06-27 20:33 - 2017-06-27 20:33 - 03051288 _____ C:\Users\hikma\Downloads\npp.7.4.2.Installer.exe
2017-06-27 20:33 - 2017-06-27 20:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2017-06-27 20:33 - 2017-06-27 20:33 - 00000000 ____D C:\Program Files (x86)\Notepad++
2017-06-26 08:41 - 2017-06-26 08:41 - 00000385 _____ C:\WINDOWS\system32\user_gensett.xml
2017-06-26 08:32 - 2017-06-29 00:24 - 00002367 _____ C:\bdlog.txt
2017-06-25 21:34 - 2017-06-25 21:34 - 00000262 __RSH C:\ProgramData\ntuser.pol
2017-06-25 21:33 - 2017-06-25 21:33 - 00491994 _____ ( ) C:\Users\hikma\Downloads\Bitdefender_Total_Security_2017_Key_With_Activation_Code_Till_2045.exe
2017-06-25 21:31 - 2017-06-25 21:31 - 00056456 _____ C:\ProgramData\dm.1498419035.bdinstall.bin
2017-06-25 21:30 - 2017-06-25 21:30 - 00466165 _____ C:\ProgramData\cl.1498418602.bdinstall.bin
2017-06-25 21:30 - 2017-06-25 21:30 - 00000000 ____D C:\ProgramData\Bitdefender Device Management
2017-06-25 21:28 - 2017-06-25 21:28 - 00000000 ____D C:\ProgramData\BDLogging
2017-06-25 21:28 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\capicom.dll
2017-06-25 21:27 - 2017-06-29 00:25 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Bitdefender
2017-06-25 21:23 - 2017-06-29 00:25 - 00000000 ____D C:\ProgramData\Bitdefender
2017-06-25 21:23 - 2017-06-25 21:23 - 00000000 ____D C:\Users\hikma\AppData\Roaming\QuickScan
2017-06-25 21:21 - 2017-06-25 21:21 - 00003798 _____ C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2017-06-25 21:19 - 2017-06-29 13:53 - 00000000 ____D C:\Program Files\Bitdefender Agent
2017-06-25 21:19 - 2017-06-25 21:19 - 09915560 _____ C:\Users\hikma\Downloads\bitdefender_windows_9ec4059b-5f63-4313-ad09-1b2badd34674.exe
2017-06-25 21:19 - 2017-06-25 21:19 - 00049472 _____ C:\ProgramData\agent.1498418359.bdinstall.bin
2017-06-25 21:19 - 2017-06-25 21:19 - 00000000 ____D C:\ProgramData\Bitdefender Agent
2017-06-25 17:43 - 2017-06-28 11:13 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-25 17:43 - 2017-06-25 17:43 - 00001942 _____ C:\Users\hikma\Desktop\BitLord.lnk
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\Documents\BitLord
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\AppData\Roaming\BitLord
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\AppData\Local\BitLord
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\.QtWebEngineProcess
2017-06-25 17:43 - 2017-06-25 17:43 - 00000000 ____D C:\Users\hikma\.BitLord
2017-06-25 17:42 - 2017-06-25 17:43 - 00000000 ____D C:\Program Files (x86)\BitLord
2017-06-25 17:41 - 2017-06-25 17:41 - 01638344 _____ (Temibosafo ) C:\Users\hikma\Downloads\BitlordSetup_V9aL1L.exe
2017-06-25 12:50 - 2017-06-25 12:50 - 00001144 _____ C:\Users\Public\Desktop\Macro Recorder.lnk
2017-06-25 12:50 - 2017-06-25 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macro Recorder
2017-06-25 12:50 - 2017-06-25 12:50 - 00000000 ____D C:\Program Files (x86)\MacroRecorder
2017-06-25 12:43 - 2017-06-28 16:08 - 00130146 _____ C:\Users\hikma\Desktop\For my Belgish friend.mcr
2017-06-25 11:35 - 2017-06-25 11:35 - 00000000 ____D C:\Users\hikma\AppData\Local\DBG
2017-06-25 11:21 - 2017-06-25 11:21 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-06-25 11:21 - 2017-03-10 23:17 - 00536864 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-06-25 11:21 - 2017-03-10 23:17 - 00525600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-06-25 11:21 - 2017-03-10 23:17 - 00254240 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-06-25 11:21 - 2017-03-10 23:17 - 00233760 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-06-25 11:20 - 2017-06-29 02:17 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-25 11:20 - 2017-05-01 22:52 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-06-25 10:25 - 2017-06-25 10:25 - 01208320 _____ C:\Users\hikma\Desktop\Fifa 17 (Ver 3.3) refresh.exe
2017-06-24 22:38 - 2017-06-24 23:07 - 00000000 ____D C:\Users\hikma\Documents\Leapdroid
2017-06-24 22:38 - 2017-06-24 22:38 - 00001876 _____ C:\Users\Public\Desktop\Leapdroid VM2.lnk
2017-06-24 22:38 - 2017-06-24 22:38 - 00001876 _____ C:\Users\Public\Desktop\Leapdroid VM1.lnk
2017-06-24 22:38 - 2017-06-24 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LeapdroidVM
2017-06-24 22:37 - 2017-06-24 22:38 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Leapdroid
2017-06-24 22:37 - 2017-06-24 22:37 - 00000000 ____D C:\Program Files\Leapdroid
2017-06-24 22:36 - 2017-06-24 22:36 - 00000000 ____D C:\Users\hikma\AppData\Roaming\WinRAR
2017-06-24 22:36 - 2017-06-24 22:36 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-06-24 22:36 - 2017-06-24 22:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-06-24 22:36 - 2017-06-24 22:36 - 00000000 ____D C:\Program Files (x86)\WinRAR
2017-06-24 22:35 - 2017-06-24 22:35 - 01972424 _____ C:\Users\hikma\Downloads\wrar540.exe
2017-06-24 22:34 - 2017-06-24 22:36 - 284115957 _____ C:\Users\hikma\Downloads\[
www.gigapurbalingga.com]_LdVMIF180.rar
2017-06-24 19:47 - 2017-06-24 19:10 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-06-24 19:43 - 2017-06-24 19:47 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-24 19:43 - 2017-06-24 19:43 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-24 19:32 - 2017-06-24 19:32 - 00000000 ____D C:\Users\hikma\AppData\Local\TeamViewer
2017-06-24 18:47 - 2017-06-28 15:32 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-24 18:47 - 2017-06-24 18:47 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-06-24 18:47 - 2017-06-24 18:47 - 00001108 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-06-24 18:47 - 2017-06-24 18:47 - 00000000 ____D C:\Users\hikma\AppData\Roaming\TeamViewer
2017-06-24 18:46 - 2017-06-24 18:46 - 15507008 _____ (TeamViewer GmbH) C:\Users\hikma\Downloads\TeamViewer_Setup.exe
2017-06-24 18:37 - 2017-06-24 18:37 - 00000000 ____D C:\users1
2017-06-24 18:05 - 2017-06-24 18:05 - 00000000 ____D C:\Users\hikma\AppData\Local\Geckofx
2017-06-24 18:04 - 2017-06-24 18:04 - 00000168 _____ C:\Users\hikma\Desktop\safe.ini
2017-06-24 17:55 - 2017-06-24 17:55 - 00000000 ____D C:\Users\hikma\.android
2017-06-24 17:49 - 2017-06-24 17:49 - 07136794 _____ C:\Users\hikma\Documents\GameGuardian.8_26.5.apk
2017-06-24 17:46 - 2017-06-24 17:46 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Mozilla
2017-06-24 17:41 - 2017-06-28 22:45 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2017-06-24 17:41 - 2017-06-24 17:41 - 00001648 _____ C:\Users\Public\Desktop\BlueStacks.lnk
2017-06-24 17:41 - 2017-06-24 17:41 - 00001648 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-06-24 17:40 - 2017-06-24 17:40 - 00107216 _____ C:\Users\hikma\Downloads\gauhar.zip
2017-06-24 17:40 - 2017-06-24 17:40 - 00000000 ____D C:\Users\hikma\AppData\Local\Bluestacks
2017-06-24 17:39 - 2017-06-24 17:41 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2017-06-24 17:39 - 2017-05-24 08:58 - 00000000 ____D C:\ProgramData\BlueStacks
2017-06-24 17:36 - 2017-06-24 17:38 - 339047640 _____ (BlueStack Systems Inc.) C:\Users\hikma\Downloads\BlueStacks2_native_fa8c12cef084437061f07176c64d9c6f.exe
2017-06-24 17:36 - 2017-06-24 17:36 - 00000000 ____D C:\Users\hikma\Documents\iPhone gegevens
2017-06-24 17:36 - 2017-06-24 17:36 - 00000000 ____D C:\Users\hikma\Documents\Codes
2017-06-24 17:32 - 2017-06-24 17:34 - 00000000 ____D C:\Users\hikma\AppData\Local\MSfree Inc
2017-06-24 17:23 - 2017-06-24 17:23 - 00002546 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive voor Bedrijven.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype voor Bedrijven 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002525 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002518 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002476 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2017-06-24 17:23 - 2017-06-24 17:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-hulpprogramma's
2017-06-24 17:20 - 2017-06-25 10:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-24 17:20 - 2017-06-24 17:20 - 00000000 ____D C:\Program Files\Microsoft Office 15
2017-06-24 17:18 - 2017-06-24 17:19 - 00000000 ___RD C:\Users\hikma\Documents\School
2017-06-24 17:18 - 2017-06-24 17:18 - 00000000 ____D C:\Users\hikma\Desktop\Root Bluestacks
2017-06-24 17:18 - 2017-05-19 22:28 - 00000081 _____ C:\Users\hikma\Documents\fifa mobile acc.txt
2017-06-24 17:18 - 2017-05-17 19:52 - 00000084 _____ C:\Users\hikma\Documents\keyloggerv.txt
2017-06-24 17:18 - 2017-05-16 21:18 - 00000156 _____ C:\Users\hikma\Documents\gmail.txt
2017-06-24 17:18 - 2017-05-12 16:07 - 00000113 _____ C:\Users\hikma\Documents\elhajhikmat codes.txt
2017-06-24 17:18 - 2017-05-11 16:01 - 00000153 _____ C:\Users\hikma\Documents\links roblox.txt
2017-06-24 17:18 - 2017-05-07 12:18 - 00000020 _____ C:\Users\hikma\Documents\code website.txt
2017-06-24 17:18 - 2017-05-01 13:09 - 00000350 _____ C:\Users\hikma\Documents\Keylogger hacks.txt
2017-06-24 17:18 - 2017-04-28 19:16 - 00000753 _____ C:\Users\hikma\Documents\filter.txt
2017-06-24 17:18 - 2017-04-07 23:31 - 00000216 _____ C:\Users\hikma\Documents\5 euro.txt
2017-06-24 17:18 - 2017-03-04 14:19 - 00000101 _____ C:\Users\hikma\Documents\fifamobile.txt
2017-06-24 17:17 - 2017-06-24 17:17 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-06-24 17:17 - 2017-06-24 17:17 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Google
2017-06-24 17:11 - 2017-06-29 10:11 - 00000000 ___RD C:\Users\hikma\OneDrive
2017-06-24 17:11 - 2017-06-29 00:58 - 00000000 ____D C:\Users\hikma\AppData\Local\Google
2017-06-24 17:11 - 2017-06-28 23:20 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-24 17:11 - 2017-06-24 17:12 - 00003290 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-24 17:11 - 2017-06-24 17:12 - 00002391 _____ C:\Users\hikma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-24 17:11 - 2017-06-24 17:11 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-06-24 17:11 - 2017-06-24 17:11 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Skype
2017-06-24 17:10 - 2017-06-24 17:10 - 00000000 ____D C:\Users\hikma\AppData\Local\MicrosoftEdge
2017-06-24 17:10 - 2017-06-24 17:10 - 00000000 ____D C:\Users\hikma\AppData\Local\Comms
2017-06-24 17:09 - 2017-06-24 17:09 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-06-24 17:07 - 2017-06-29 10:10 - 00000000 __SHD C:\Users\hikma\IntelGraphicsProfiles
2017-06-24 17:07 - 2017-06-25 18:02 - 00000000 ____D C:\Users\hikma\AppData\Local\Packages
2017-06-24 17:07 - 2017-06-25 17:12 - 00000000 ____D C:\Users\hikma\AppData\Local\Publishers
2017-06-24 17:07 - 2017-06-24 22:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-24 17:07 - 2017-06-24 17:08 - 00000000 ____D C:\Users\hikma\AppData\Local\ConnectedDevicesPlatform
2017-06-24 17:07 - 2017-06-24 17:07 - 00000000 ____D C:\Users\hikma\AppData\Roaming\Adobe
2017-06-24 17:07 - 2017-06-24 17:07 - 00000000 ____D C:\Users\hikma\AppData\Local\VirtualStore
2017-06-24 17:07 - 2017-06-24 17:07 - 00000000 ____D C:\Users\hikma\AppData\Local\TileDataLayer
2017-06-24 17:06 - 2017-06-28 11:10 - 00000000 ____D C:\Users\hikma
2017-06-24 17:06 - 2017-06-24 17:06 - 00000020 ___SH C:\Users\hikma\ntuser.ini
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Sjablonen
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Netwerkprinteromgeving
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Mijn documenten
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Menu Start
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Documents\Mijn video's
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Documents\Mijn muziek
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\Documents\Mijn afbeeldingen
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2017-06-24 17:06 - 2017-06-24 17:06 - 00000000 _SHDL C:\Users\hikma\AppData\Local\Geschiedenis
2017-06-24 14:08 - 2017-06-29 00:52 - 02209188 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-24 14:06 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Public\Documents\Mijn video's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Public\Documents\Mijn muziek
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Public\Documents\Mijn afbeeldingen
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Sjablonen
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Netwerkprinteromgeving
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Mijn documenten
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Menu Start
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Documents\Mijn video's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Documents\Mijn muziek
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\Documents\Mijn afbeeldingen
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default\AppData\Local\Geschiedenis
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User\Documents\Mijn video's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User\Documents\Mijn muziek
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User\Documents\Mijn afbeeldingen
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Geschiedenis
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\Default User
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Users\All Users
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\ProgramData\Sjablonen
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programma's
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\ProgramData\Menu Start
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\ProgramData\Documenten
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\ProgramData\Bureaublad
2017-06-24 14:03 - 2017-06-24 14:03 - 00000000 _SHDL C:\Documents and Settings
2017-06-24 14:01 - 2017-06-24 14:01 - 00000000 ____D C:\ProgramData\USOShared
2017-06-24 13:56 - 2017-06-24 13:56 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-06-24 13:56 - 2017-05-01 22:51 - 06437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 02479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 00548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 00392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-06-24 13:56 - 2017-05-01 22:51 - 00069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-06-24 13:56 - 2017-04-25 23:11 - 07944687 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-06-24 13:55 - 2017-06-29 10:10 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-06-24 13:55 - 2017-06-25 11:21 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-06-24 13:55 - 2017-06-25 11:20 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-06-24 13:55 - 2017-06-24 14:06 - 00000000 ____D C:\Intel
2017-06-24 13:55 - 2017-06-24 13:55 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2017-06-24 13:55 - 2017-06-24 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-06-24 13:55 - 2017-06-24 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-06-24 13:55 - 2017-06-24 13:55 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-06-24 13:55 - 2017-06-24 13:55 - 00000000 ____D C:\Program Files\Realtek
2017-06-24 13:55 - 2017-06-24 13:55 - 00000000 ____D C:\Program Files\Intel
2017-06-24 13:55 - 2017-05-18 07:56 - 00521816 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2017-06-24 13:55 - 2017-05-18 07:56 - 00427608 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2017-06-24 13:54 - 2017-06-24 13:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2017-06-24 13:50 - 2017-06-29 00:46 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-24 13:49 - 2017-06-29 13:25 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-24 13:49 - 2017-06-24 22:53 - 00384216 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-24 13:49 - 2017-06-24 13:50 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-06-24 13:01 - 2017-06-24 13:01 - 00000000 ____D C:\WINDOWS\InfusedApps
2017-06-24 13:00 - 2017-06-24 13:00 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-06-24 12:59 - 2017-06-24 12:59 - 00000000 ____D C:\Program Files\Elantech
2017-06-24 12:58 - 2017-06-24 12:58 - 00000000 ____D C:\WINDOWS\Setup
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\OCR
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\Program Files\MSBuild
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-06-24 12:56 - 2017-06-24 12:56 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-06-24 12:55 - 2017-06-29 00:52 - 01005492 _____ C:\WINDOWS\system32\perfh013.dat
2017-06-24 12:55 - 2017-06-29 00:52 - 00214188 _____ C:\WINDOWS\system32\perfc013.dat
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\winrm
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\WCN
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\slmgr
2017-06-24 12:55 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\nl
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\system32\nl
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\system32\0409
2017-06-24 12:55 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\DigitalLocker
2017-06-24 12:55 - 2017-06-24 12:54 - 00347800 _____ C:\WINDOWS\system32\perfi013.dat
2017-06-24 12:55 - 2017-06-24 12:54 - 00045450 _____ C:\WINDOWS\system32\perfd013.dat
2017-06-24 12:52 - 2017-04-29 03:05 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-24 12:52 - 2017-04-29 03:05 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-24 12:50 - 2017-06-24 13:00 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-06-24 12:50 - 2017-06-24 12:47 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-06-24 12:50 - 2017-06-24 12:47 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-06-24 12:50 - 2017-06-24 12:47 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2017-06-24 12:50 - 2017-06-24 12:47 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-06-24 12:50 - 2017-06-24 12:47 - 00017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-06-24 12:50 - 2017-06-24 12:47 - 00015940 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-06-24 12:50 - 2017-06-24 12:47 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-06-24 12:50 - 2017-06-24 12:47 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-06-24 12:50 - 2017-06-24 12:47 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-06-24 12:50 - 2017-06-24 12:47 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-06-24 12:50 - 2017-06-24 12:47 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-06-24 12:50 - 2017-06-24 12:47 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-06-24 12:50 - 2017-06-24 12:47 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-06-24 12:49 - 2017-06-29 11:39 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-06-24 12:49 - 2017-06-29 10:14 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-24 12:49 - 2017-06-29 10:14 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-24 12:49 - 2017-06-29 00:26 - 00000000 ____D C:\WINDOWS\ELAMBKUP
2017-06-24 12:49 - 2017-06-28 16:15 - 00000000 ____D C:\WINDOWS\rescache
2017-06-24 12:49 - 2017-06-28 11:15 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-06-24 12:49 - 2017-06-26 18:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-06-24 12:49 - 2017-06-26 04:43 - 00000000 ____D C:\WINDOWS\appcompat
2017-06-24 12:49 - 2017-06-25 21:34 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-06-24 12:49 - 2017-06-25 21:34 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ___RD C:\Program Files\Windows Defender
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-06-24 12:49 - 2017-06-25 11:17 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-06-24 12:49 - 2017-06-25 10:31 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-24 12:49 - 2017-06-24 22:49 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-06-24 12:49 - 2017-06-24 22:49 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-06-24 12:49 - 2017-06-24 22:49 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-06-24 12:49 - 2017-06-24 22:49 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-06-24 12:49 - 2017-06-24 22:49 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-24 12:49 - 2017-06-24 22:48 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-06-24 12:49 - 2017-06-24 22:48 - 00000000 ____D C:\WINDOWS\Provisioning
2017-06-24 12:49 - 2017-06-24 17:41 - 00000000 __RHD C:\Users\Public\Libraries
2017-06-24 12:49 - 2017-06-24 17:06 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-06-24 12:49 - 2017-06-24 14:06 - 00000000 ____D C:\WINDOWS\system32\spool
2017-06-24 12:49 - 2017-06-24 14:06 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-06-24 12:49 - 2017-06-24 14:03 - 00000000 ____D C:\Program Files\Windows NT
2017-06-24 12:49 - 2017-06-24 14:01 - 00000000 ____D C:\ProgramData\USOPrivate
2017-06-24 12:49 - 2017-06-24 14:00 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-06-24 12:49 - 2017-06-24 13:57 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-06-24 12:49 - 2017-06-24 13:57 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-06-24 12:49 - 2017-06-24 13:57 - 00000000 ____D C:\WINDOWS\HoloShell
2017-06-24 12:49 - 2017-06-24 13:56 - 00000000 ____D C:\WINDOWS\Help
2017-06-24 12:49 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-06-24 12:49 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\SystemApps
2017-06-24 12:49 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-06-24 12:49 - 2017-06-24 12:56 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ___SD C:\WINDOWS\system32\dsc
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\system32\setup
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\system32\Com
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\WINDOWS\IME
2017-06-24 12:49 - 2017-06-24 12:55 - 00000000 ____D C:\Program Files\Common Files\System
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 __RSD C:\WINDOWS\Media
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ___SD C:\WINDOWS\system32\Nui
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\icsxml
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\ias
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\downlevel
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\DDFs
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\Registration
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\L2Schemas
2017-06-24 12:49 - 2017-06-24 12:50 - 00000000 ____D C:\WINDOWS\Cursors
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Web
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Vss
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\tracing
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\TAPI
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SystemResources
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\winevt
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\ras
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\IME
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\Hydrogen
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\System
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SKB
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\security
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\schemas
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\SchCache
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Resources
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\PLA
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Performance
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\InputMethod
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Globalization
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\Branding
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\addins
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\ProgramData\WindowsHolographicDevices
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files\Windows Security
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files\Windows Portable Devices
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files\Common Files\Services
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files (x86)\Windows NT
2017-06-24 12:49 - 2017-06-24 12:49 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-06-24 12:49 - 2017-06-24 12:47 - 00000219 _____ C:\WINDOWS\system.ini
2017-06-24 12:49 - 2017-06-24 12:47 - 00000092 _____ C:\WINDOWS\win.ini
2017-06-24 12:48 - 2017-06-29 00:25 - 00000000 ____D C:\WINDOWS\INF
2017-06-24 12:41 - 2017-06-25 23:09 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-24 12:36 - 2017-06-29 00:45 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-06-24 12:36 - 2017-06-25 11:17 - 00000000 ____D C:\WINDOWS\servicing
2017-06-24 12:36 - 2017-06-24 14:05 - 00000000 ____D C:\WINDOWS\Panther
2017-06-24 12:36 - 2017-06-24 13:51 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-06-24 12:36 - 2017-06-24 12:49 - 00000000 ____D C:\WINDOWS\system32\SMI
2017-06-24 11:20 - 2017-06-24 13:04 - 00000000 ___HD C:\$SysReset
2017-06-14 13:38 - 2017-06-03 12:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-06-14 13:38 - 2017-06-03 12:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-06-14 13:38 - 2017-06-03 11:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-14 13:38 - 2017-06-03 11:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-14 13:38 - 2017-06-03 11:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-14 13:38 - 2017-06-03 11:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-06-14 13:38 - 2017-06-03 11:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-14 13:38 - 2017-06-03 11:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-06-14 13:38 - 2017-06-03 11:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-14 13:38 - 2017-06-03 11:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-06-14 13:38 - 2017-06-03 11:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2017-06-14 13:38 - 2017-06-03 11:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-14 13:38 - 2017-06-03 11:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-06-14 13:38 - 2017-06-03 11:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-14 13:38 - 2017-06-03 11:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-14 13:38 - 2017-06-03 11:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-14 13:38 - 2017-06-03 11:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-14 13:38 - 2017-06-03 11:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-14 13:38 - 2017-06-03 11:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-14 13:38 - 2017-06-03 11:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-14 13:38 - 2017-06-03 11:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-06-14 13:38 - 2017-06-03 11:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-06-14 13:38 - 2017-06-03 11:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-06-14 13:38 - 2017-06-03 11:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-14 13:38 - 2017-06-03 11:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-14 13:38 - 2017-06-03 10:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-14 13:38 - 2017-06-03 10:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-14 13:38 - 2017-06-03 10:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-06-14 13:38 - 2017-06-03 10:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-14 13:38 - 2017-06-03 10:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-06-14 13:38 - 2017-06-03 10:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-06-14 13:38 - 2017-06-03 10:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-06-14 13:38 - 2017-06-03 10:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-14 13:38 - 2017-06-03 10:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-14 13:38 - 2017-06-03 10:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-14 13:38 - 2017-06-03 10:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-14 13:38 - 2017-06-03 10:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-06-14 13:38 - 2017-06-03 10:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-06-14 13:38 - 2017-05-20 11:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-06-14 13:38 - 2017-05-20 10:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-06-14 13:38 - 2017-05-20 10:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-06-14 13:38 - 2017-05-20 10:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-06-14 13:38 - 2017-05-20 10:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-06-14 13:38 - 2017-05-20 10:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-06-14 13:38 - 2017-05-20 10:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-06-14 13:38 - 2017-05-20 10:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-06-14 13:38 - 2017-05-20 10:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-06-14 13:38 - 2017-05-20 10:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-06-14 13:38 - 2017-05-20 10:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2017-06-14 13:38 - 2017-05-20 10:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-06-14 13:38 - 2017-05-20 10:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-06-14 13:38 - 2017-05-20 10:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2017-06-14 13:38 - 2017-05-20 10:26 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll
2017-06-14 13:38 - 2017-05-20 10:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-06-14 13:38 - 2017-05-20 10:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2017-06-14 13:38 - 2017-05-20 10:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-06-14 13:38 - 2017-05-20 10:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-06-14 13:38 - 2017-05-20 10:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-06-14 13:38 - 2017-05-20 10:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-06-14 13:38 - 2017-05-20 10:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-06-14 13:38 - 2017-05-20 10:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2017-06-14 13:38 - 2017-05-20 10:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-06-14 13:38 - 2017-05-20 10:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-06-14 13:38 - 2017-05-20 10:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2017-06-14 13:38 - 2017-05-20 10:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-06-14 13:38 - 2017-05-20 10:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-06-14 13:38 - 2017-05-20 10:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-06-14 13:38 - 2017-05-20 10:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-06-14 13:38 - 2017-05-20 10:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-06-14 13:38 - 2017-05-20 10:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-06-14 13:38 - 2017-05-20 10:17 - 04544000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2017-06-14 13:38 - 2017-05-20 10:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-06-14 13:38 - 2017-05-20 10:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-06-14 13:38 - 2017-05-20 10:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-06-14 13:38 - 2017-05-20 10:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-06-14 13:38 - 2017-05-20 10:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-06-14 13:38 - 2017-05-20 10:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-06-14 13:38 - 2017-05-20 10:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-06-14 13:38 - 2017-05-20 10:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-06-14 13:38 - 2017-05-20 10:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-06-14 13:38 - 2017-05-20 10:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-06-14 13:38 - 2017-05-20 10:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-06-14 13:38 - 2017-05-20 10:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2017-06-14 13:38 - 2017-05-20 10:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-06-14 13:38 - 2017-05-20 10:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-06-14 13:38 - 2017-05-20 10:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-06-14 13:38 - 2017-05-20 10:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-06-14 13:38 - 2017-05-20 10:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-06-14 13:38 - 2017-05-20 10:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-06-14 13:38 - 2017-05-20 10:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2017-06-14 13:38 - 2017-05-20 09:07 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-14 13:38 - 2017-05-20 08:58 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-14 13:38 - 2017-05-20 08:55 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-06-14 13:38 - 2017-05-20 08:54 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-06-14 13:38 - 2017-05-20 08:54 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-06-14 13:38 - 2017-05-20 08:53 - 00335808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2017-06-14 13:38 - 2017-05-20 08:10 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2017-06-14 13:38 - 2017-05-20 08:07 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-06-14 13:38 - 2017-05-20 08:07 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-06-14 13:37 - 2017-06-03 12:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-14 13:37 - 2017-06-03 12:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-14 13:37 - 2017-06-03 12:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-14 13:37 - 2017-06-03 11:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-06-14 13:37 - 2017-06-03 11:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-06-14 13:37 - 2017-06-03 11:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-14 13:37 - 2017-06-03 11:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-14 13:37 - 2017-06-03 11:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-14 13:37 - 2017-06-03 11:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-14 13:37 - 2017-06-03 11:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-14 13:37 - 2017-06-03 11:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-06-14 13:37 - 2017-06-03 11:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-06-14 13:37 - 2017-06-03 11:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-14 13:37 - 2017-06-03 11:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-14 13:37 - 2017-06-03 11:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-14 13:37 - 2017-06-03 11:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-14 13:37 - 2017-06-03 11:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-14 13:37 - 2017-06-03 11:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-14 13:37 - 2017-06-03 11:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-06-14 13:37 - 2017-06-03 11:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-14 13:37 - 2017-06-03 11:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-14 13:37 - 2017-06-03 10:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-14 13:37 - 2017-06-03 10:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-14 13:37 - 2017-06-03 10:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-14 13:37 - 2017-06-03 10:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-06-14 13:37 - 2017-06-03 10:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-14 13:37 - 2017-06-03 10:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-14 13:37 - 2017-06-03 10:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-06-14 13:37 - 2017-06-03 10:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-06-14 13:37 - 2017-06-03 10:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-14 13:37 - 2017-06-03 10:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-14 13:37 - 2017-05-20 09:03 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-06-14 13:37 - 2017-05-20 08:55 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-06-14 13:37 - 2017-05-20 08:55 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-06-14 13:37 - 2017-05-20 08:54 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-14 13:37 - 2017-05-20 08:53 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-14 13:37 - 2017-05-20 08:53 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-06-14 13:37 - 2017-05-20 08:52 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-06-14 13:37 - 2017-05-20 08:52 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-06-14 13:37 - 2017-05-20 08:51 - 06551856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-06-14 13:37 - 2017-05-20 08:51 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-06-14 13:37 - 2017-05-20 08:51 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-06-14 13:37 - 2017-05-20 08:51 - 01219560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-06-14 13:37 - 2017-05-20 08:48 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-06-14 13:37 - 2017-05-20 08:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-06-14 13:37 - 2017-05-20 08:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2017-06-14 13:37 - 2017-05-20 08:07 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2017-06-14 13:37 - 2017-05-20 08:06 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-06-14 13:37 - 2017-05-20 08:03 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-06-14 13:37 - 2017-05-20 08:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-06-14 13:37 - 2017-05-20 08:00 - 05776384 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2017-06-14 13:37 - 2017-05-20 08:00 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-06-14 13:37 - 2017-05-20 08:00 - 00846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-06-14 13:37 - 2017-05-20 08:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-06-14 13:37 - 2017-05-20 07:59 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-06-14 13:37 - 2017-05-20 07:58 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-06-14 13:37 - 2017-05-20 07:58 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-06-14 13:37 - 2017-05-20 07:58 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-06-14 13:37 - 2017-05-20 07:58 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-06-14 13:37 - 2017-05-20 07:55 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-06-14 13:37 - 2017-05-20 07:54 - 04537344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-06-14 13:37 - 2017-05-20 07:54 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-06-14 13:37 - 2017-05-20 07:52 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-06-14 13:37 - 2017-05-20 07:52 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-06-14 13:37 - 2017-05-20 07:51 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-06-14 13:37 - 2017-05-20 07:50 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-06-14 13:36 - 2017-06-03 12:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-14 13:36 - 2017-06-03 12:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-14 13:36 - 2017-06-03 12:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-14 13:36 - 2017-06-03 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-14 13:36 - 2017-06-03 12:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-14 13:36 - 2017-06-03 12:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-14 13:36 - 2017-06-03 12:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-14 13:36 - 2017-06-03 12:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-14 13:36 - 2017-06-03 12:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-06-14 13:36 - 2017-06-03 12:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-06-14 13:36 - 2017-06-03 12:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-06-14 13:36 - 2017-06-03 11:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-14 13:36 - 2017-06-03 11:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-06-14 13:36 - 2017-06-03 11:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-06-14 13:36 - 2017-06-03 11:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-06-14 13:36 - 2017-06-03 11:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-14 13:36 - 2017-06-03 11:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-06-14 13:36 - 2017-06-03 11:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-06-14 13:36 - 2017-06-03 11:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-14 13:36 - 2017-06-03 11:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-14 13:36 - 2017-06-03 11:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-06-14 13:36 - 2017-06-03 11:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-14 13:36 - 2017-06-03 11:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-06-14 13:36 - 2017-06-03 11:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-06-14 13:36 - 2017-06-03 11:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-06-14 13:36 - 2017-06-03 11:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-14 13:36 - 2017-06-03 11:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-06-14 13:36 - 2017-06-03 11:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-06-14 13:36 - 2017-06-03 11:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-06-14 13:36 - 2017-06-03 11:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-06-14 13:36 - 2017-06-03 10:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-14 13:36 - 2017-06-03 10:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-14 13:36 - 2017-06-03 10:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-14 13:36 - 2017-06-03 10:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-06-14 13:36 - 2017-06-03 10:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-14 13:36 - 2017-06-03 10:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-14 13:36 - 2017-06-03 10:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-06-14 13:36 - 2017-05-20 10:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-06-14 13:36 - 2017-05-20 09:08 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-06-14 13:36 - 2017-05-20 09:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-06-14 13:36 - 2017-05-20 08:59 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-06-14 13:36 - 2017-05-20 08:56 - 04847928 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-06-14 13:36 - 2017-05-20 08:56 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-06-14 13:36 - 2017-05-20 08:56 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-06-14 13:36 - 2017-05-20 08:55 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-06-14 13:36 - 2017-05-20 08:55 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-14 13:36 - 2017-05-20 08:55 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-06-14 13:36 - 2017-05-20 08:53 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-06-14 13:36 - 2017-05-20 08:53 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-06-14 13:36 - 2017-05-20 08:51 - 00406064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-06-14 13:36 - 2017-05-20 08:10 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-06-14 13:36 - 2017-05-20 08:10 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-06-14 13:36 - 2017-05-20 08:10 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll
2017-06-14 13:36 - 2017-05-20 08:10 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys
2017-06-14 13:36 - 2017-05-20 08:09 - 17365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-06-14 13:36 - 2017-05-20 08:09 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-06-14 13:36 - 2017-05-20 08:09 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-06-14 13:36 - 2017-05-20 08:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll
2017-06-14 13:36 - 2017-05-20 08:06 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-06-14 13:36 - 2017-05-20 08:06 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2017-06-14 13:36 - 2017-05-20 08:05 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-06-14 13:36 - 2017-05-20 08:05 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-06-14 13:36 - 2017-05-20 08:03 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-06-14 13:36 - 2017-05-20 08:03 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-06-14 13:36 - 2017-05-20 08:03 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-06-14 13:36 - 2017-05-20 08:03 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-06-14 13:36 - 2017-05-20 08:03 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-06-14 13:36 - 2017-05-20 08:02 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-06-14 13:36 - 2017-05-20 08:02 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-06-14 13:36 - 2017-05-20 08:01 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll
2017-06-14 13:36 - 2017-05-20 08:00 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-06-14 13:36 - 2017-05-20 08:00 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-06-14 13:36 - 2017-05-20 07:59 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-06-14 13:36 - 2017-05-20 07:58 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-06-14 13:36 - 2017-05-20 07:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-06-14 13:36 - 2017-05-20 07:57 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-06-14 13:36 - 2017-05-20 07:56 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-06-14 13:36 - 2017-05-20 07:56 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-06-14 13:36 - 2017-05-20 07:55 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-06-14 13:36 - 2017-05-20 07:55 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-06-14 13:36 - 2017-05-20 07:55 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-06-14 13:36 - 2017-05-20 07:54 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-06-14 13:36 - 2017-05-20 07:54 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-06-14 13:36 - 2017-05-20 07:54 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-06-14 13:36 - 2017-05-20 07:52 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-06-14 13:36 - 2017-05-20 07:52 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-06-14 13:36 - 2017-05-20 07:51 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-06-14 13:36 - 2017-05-20 07:50 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-06-14 13:36 - 2017-05-20 07:48 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-06-14 13:36 - 2017-05-20 07:48 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-06-14 13:36 - 2017-05-20 07:47 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2017-06-14 13:36 - 2017-05-20 07:47 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
==================== Een Maand Gewijzigd bestanden en mappen ========
(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)
==================== Bestanden in de root van sommige mappen =======
2017-06-25 21:19 - 2017-06-25 21:19 - 0049472 _____ () C:\ProgramData\agent.1498418359.bdinstall.bin
2017-06-25 21:30 - 2017-06-25 21:30 - 0466165 _____ () C:\ProgramData\cl.1498418602.bdinstall.bin
2017-06-29 00:25 - 2017-06-29 00:25 - 0216696 _____ () C:\ProgramData\cl.uninstall.1498688601.bdinstall.bin
2017-06-25 21:31 - 2017-06-25 21:31 - 0056456 _____ () C:\ProgramData\dm.1498419035.bdinstall.bin
2017-06-29 00:23 - 2017-06-29 00:23 - 0035978 _____ () C:\ProgramData\dm.uninstall.1498688612.bdinstall.bin
2017-06-24 17:11 - 2017-06-24 17:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Sommige bestanden in TEMP:
====================
2017-01-26 09:26 - 2017-01-26 09:26 - 4297200 _____ (Bandicam Company) C:\Users\hikma\AppData\Local\Temp\bdfilters.dll
2017-06-29 01:01 - 2017-06-29 01:01 - 13460656 _____ (Reimage) C:\Users\hikma\AppData\Local\Temp\ReimagePackage.exe
==================== Bamital & volsnap ======================
(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)
C:\WINDOWS\system32\winlogon.exe => Bestand is getekend
C:\WINDOWS\system32\wininit.exe => Bestand is getekend
C:\WINDOWS\explorer.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\explorer.exe => Bestand is getekend
C:\WINDOWS\system32\svchost.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\svchost.exe => Bestand is getekend
C:\WINDOWS\system32\services.exe => Bestand is getekend
C:\WINDOWS\system32\User32.dll => Bestand is getekend
C:\WINDOWS\SysWOW64\User32.dll => Bestand is getekend
C:\WINDOWS\system32\userinit.exe => Bestand is getekend
C:\WINDOWS\SysWOW64\userinit.exe => Bestand is getekend
C:\WINDOWS\system32\rpcss.dll => Bestand is getekend
C:\WINDOWS\system32\dnsapi.dll => Bestand is getekend
C:\WINDOWS\SysWOW64\dnsapi.dll => Bestand is getekend
C:\WINDOWS\system32\Drivers\volsnap.sys => Bestand is getekend
LastRegBack: 2017-06-24 13:49
==================== Eind van FRST.txt ============================