can result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-10-2017 01
Ran by Linda (administrator) on LINDA-PC (05-10-2017 16:41:41)
Running from C:\Users\Linda\Desktop
Loaded Profiles: Linda (Available Profiles: Linda)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtWatchDog.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1266176 2016-07-24] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [256744 2016-07-24] (Trend Micro Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-03-08]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{7F3C578C-852A-45D8-A90F-3B4AA0DFAB3A}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3748863924-3211053123-401377555-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3748863924-3211053123-401377555-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://start.duckduckgo.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1403\2.7.1088\TmopIEPlg.dll [2017-01-10] (Trend Micro Inc.)
BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe64.dll [2016-06-28] (Trend Micro Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1403\2.7.1088\TmopIEPlg32.dll [2017-01-10] (Trend Micro Inc.)
BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll [2016-06-28] (Trend Micro Inc.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe64.dll [2016-06-28] (Trend Micro Inc.)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll [2016-06-28] (Trend Micro Inc.)
Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1403\2.7.1088\TmopIEPlg.dll [2017-01-10] (Trend Micro Inc.)
Handler-x32: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1403\2.7.1088\TmopIEPlg32.dll [2017-01-10] (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2016-07-24] (Trend Micro Inc.)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\firefoxextension
FF Extension: (Trend Micro BEP Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\firefoxextension [2017-01-08]
FF HKLM\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension
FF Extension: (No Name) - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension [2017-05-07] [not signed]
FF HKLM\...\Firefox\Extensions: [com.trendmicro.tmopfirefox.ext@trendop] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension\com.trendmicro.tmopfirefox.ext@trendop.xpi
FF Extension: (Trend Micro Osprey Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension\com.trendmicro.tmopfirefox.ext@trendop.xpi [2017-01-23]
FF HKLM-x32\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [com.trendmicro.tmopfirefox.ext@trendop] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension\com.trendmicro.tmopfirefox.ext@trendop.xpi
FF HKU\S-1-5-21-3748863924-3211053123-401377555-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-03-08] [not signed]
FF Plugin: @java.com/DTPlugin,version=10.17.2 -> C:\Windows\system32\npDeployJava1.dll [2013-03-06] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-03-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-08-17] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [idkknaphebegndgimgdpfnconcickdfn] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - <no Path/update_url>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Amsp; C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [365576 2016-07-16] (Trend Micro Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-07-21] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1145856 2016-07-24] (Trend Micro Inc.)
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-10-05] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [142544 2017-04-06] (Trend Micro Inc.)
R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [434896 2017-04-06] (Trend Micro Inc.)
R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [72504 2016-01-04] (Trend Micro Inc.)
R3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [143648 2016-06-20] (Trend Micro Inc.)
R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [118992 2017-04-06] (Trend Micro Inc.)
R3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [561952 2016-06-23] (Trend Micro Inc.)
R1 tmumh; C:\Windows\System32\DRIVERS\TMUMH.sys [113880 2017-04-12] (Trend Micro Inc.)
R2 tmusa; C:\Windows\System32\DRIVERS\tmusa.sys [131800 2017-02-08] (Trend Micro Inc.)
S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-11-11] (LG Electronics Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U2 TMAgent; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-05 16:41 - 2017-10-05 16:42 - 000013600 _____ C:\Users\Linda\Desktop\FRST.txt
2017-10-05 16:41 - 2017-10-05 16:41 - 000000000 ____D C:\FRST
2017-10-05 16:40 - 2017-10-05 16:40 - 002399744 _____ (Farbar) C:\Users\Linda\Desktop\FRST64.exe
2017-10-04 15:40 - 2017-10-04 15:40 - 000001391 _____ C:\Users\Linda\Desktop\MBAM.txt
2017-10-04 15:11 - 2017-10-05 16:14 - 000192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-10-04 15:10 - 2017-10-04 15:10 - 000001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-10-04 15:10 - 2017-10-04 15:10 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-10-04 15:10 - 2017-10-04 15:10 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-10-04 15:10 - 2016-03-10 14:09 - 000064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-10-04 15:10 - 2016-03-10 14:08 - 000140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-10-04 15:10 - 2016-03-10 14:08 - 000027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-10-04 14:58 - 2017-10-04 14:58 - 022851472 _____ (Malwarebytes ) C:\Users\Linda\Desktop\mbam-setup-FileHippo.19901-2.2.1.1043.exe
2017-10-03 10:44 - 2017-10-03 10:44 - 000022007 _____ C:\Users\Linda\Desktop\energy-report.html
2017-10-03 10:27 - 2017-10-03 10:27 - 000022007 _____ C:\Windows\system32\energy-report.html
2017-10-02 00:06 - 2017-08-19 08:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-10-02 00:06 - 2017-08-19 08:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-10-02 00:06 - 2017-08-16 08:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-10-02 00:06 - 2017-08-16 08:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-10-02 00:06 - 2017-08-16 07:57 - 003224576 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-02 00:06 - 2017-08-15 18:10 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-10-02 00:06 - 2017-08-15 17:25 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-10-02 00:06 - 2017-08-15 08:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-10-02 00:06 - 2017-08-15 08:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-10-02 00:06 - 2017-08-15 08:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-10-02 00:06 - 2017-08-15 08:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-10-02 00:06 - 2017-08-15 07:06 - 015260160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-02 00:06 - 2017-08-15 07:01 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-10-02 00:06 - 2017-08-15 07:01 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-10-02 00:06 - 2017-08-15 07:01 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-10-02 00:06 - 2017-08-15 06:58 - 013673984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2017-10-02 00:06 - 2017-08-14 10:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2017-10-02 00:06 - 2017-08-14 10:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2017-10-02 00:06 - 2017-08-13 14:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-10-02 00:06 - 2017-08-13 14:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2017-10-02 00:06 - 2017-08-13 11:58 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-02 00:06 - 2017-08-13 10:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-02 00:06 - 2017-08-13 10:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-10-02 00:06 - 2017-08-13 10:06 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-10-02 00:06 - 2017-08-13 10:05 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-02 00:06 - 2017-08-13 10:05 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-02 00:06 - 2017-08-13 10:05 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-10-02 00:06 - 2017-08-13 10:05 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-10-02 00:06 - 2017-08-13 10:04 - 002899968 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-02 00:06 - 2017-08-13 09:56 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-02 00:06 - 2017-08-13 09:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-10-02 00:06 - 2017-08-13 09:54 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-10-02 00:06 - 2017-08-13 09:52 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-02 00:06 - 2017-08-13 09:51 - 005981696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-02 00:06 - 2017-08-13 09:51 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-02 00:06 - 2017-08-13 09:51 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-10-02 00:06 - 2017-08-13 09:50 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-02 00:06 - 2017-08-13 09:50 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-10-02 00:06 - 2017-08-13 09:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-10-02 00:06 - 2017-08-13 09:41 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-02 00:06 - 2017-08-13 09:38 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-02 00:06 - 2017-08-13 09:30 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-10-02 00:06 - 2017-08-13 09:29 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-10-02 00:06 - 2017-08-13 09:29 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-10-02 00:06 - 2017-08-13 09:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-10-02 00:06 - 2017-08-13 09:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-02 00:06 - 2017-08-13 09:29 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-10-02 00:06 - 2017-08-13 09:28 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-10-02 00:06 - 2017-08-13 09:27 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-10-02 00:06 - 2017-08-13 09:24 - 002291200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-10-02 00:06 - 2017-08-13 09:24 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-10-02 00:06 - 2017-08-13 09:23 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-02 00:06 - 2017-08-13 09:22 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-10-02 00:06 - 2017-08-13 09:21 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-10-02 00:06 - 2017-08-13 09:20 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-02 00:06 - 2017-08-13 09:19 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-10-02 00:06 - 2017-08-13 09:18 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-10-02 00:06 - 2017-08-13 09:17 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-10-02 00:06 - 2017-08-13 09:17 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-10-02 00:06 - 2017-08-13 09:17 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-10-02 00:06 - 2017-08-13 09:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-10-02 00:06 - 2017-08-13 09:04 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-02 00:06 - 2017-08-13 09:04 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-10-02 00:06 - 2017-08-13 09:02 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-10-02 00:06 - 2017-08-13 09:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-02 00:06 - 2017-08-13 09:01 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-10-02 00:06 - 2017-08-13 09:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-10-02 00:06 - 2017-08-13 09:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-10-02 00:06 - 2017-08-13 08:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-10-02 00:06 - 2017-08-13 08:53 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-10-02 00:06 - 2017-08-13 08:48 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-10-02 00:06 - 2017-08-13 08:46 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-10-02 00:06 - 2017-08-13 08:44 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-10-02 00:06 - 2017-08-13 08:43 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-10-02 00:06 - 2017-08-13 08:43 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-10-02 00:06 - 2017-08-13 08:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-02 00:06 - 2017-08-13 08:27 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-02 00:06 - 2017-08-13 08:18 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-10-02 00:06 - 2017-08-13 08:17 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-10-02 00:06 - 2017-08-13 08:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-10-02 00:06 - 2017-08-13 08:13 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-10-02 00:06 - 2017-08-10 23:42 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-10-02 00:06 - 2017-08-10 23:38 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-02 00:06 - 2017-08-10 23:38 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-10-02 00:06 - 2017-08-10 23:38 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-10-02 00:06 - 2017-08-10 23:38 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-02 00:06 - 2017-08-10 23:36 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-10-02 00:06 - 2017-08-10 23:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-10-02 00:06 - 2017-08-10 23:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-10-02 00:06 - 2017-08-10 23:21 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-10-02 00:06 - 2017-08-10 23:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-10-02 00:06 - 2017-08-10 23:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2017-10-02 00:06 - 2017-08-10 23:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 23:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-10-02 00:06 - 2017-08-10 23:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-10-02 00:06 - 2017-08-10 23:07 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-10-02 00:06 - 2017-08-10 23:07 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-10-02 00:06 - 2017-08-10 23:07 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-10-02 00:06 - 2017-08-10 23:06 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-10-02 00:06 - 2017-08-10 23:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-10-02 00:06 - 2017-08-10 23:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-10-02 00:06 - 2017-08-10 23:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-10-02 00:06 - 2017-08-10 23:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-10-02 00:06 - 2017-08-10 23:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-10-02 00:06 - 2017-08-10 23:00 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-02 00:06 - 2017-08-10 23:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-10-02 00:06 - 2017-08-10 22:59 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-02 00:06 - 2017-08-10 22:59 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-10-02 00:06 - 2017-08-10 22:59 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-02 00:06 - 2017-08-10 22:59 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-02 00:06 - 2017-08-10 22:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-02 00:06 - 2017-08-10 22:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-02 00:06 - 2017-08-10 22:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-10-02 00:06 - 2017-08-10 22:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-10-02 00:06 - 2017-08-10 22:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-10-02 00:06 - 2017-08-10 22:56 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-10-02 00:06 - 2017-08-10 22:56 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-10-02 00:06 - 2017-08-10 22:56 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-10-02 00:06 - 2017-08-10 22:55 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-10-02 00:06 - 2017-08-10 22:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 22:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 22:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-02 00:06 - 2017-08-10 22:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-02 00:06 - 2017-07-07 08:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2017-10-02 00:06 - 2017-07-07 08:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2017-09-25 10:49 - 2017-09-25 10:49 - 000089646 _____ C:\Users\Linda\Desktop\sfcdetails.txt
2017-09-24 21:32 - 2017-09-24 21:32 - 000004675 _____ C:\Users\Linda\Desktop\AdwCleaner[S0]-temp I saved.txt
2017-09-24 15:33 - 2017-09-24 15:33 - 000000972 _____ C:\Users\Linda\Desktop\AdwCleaner[S0].txt
2017-09-24 15:29 - 2017-09-25 15:28 - 000000000 ____D C:\AdwCleaner
2017-09-24 15:28 - 2017-09-24 15:28 - 008182736 _____ (Malwarebytes) C:\Users\Linda\Desktop\adwcleaner_7.0.2.1.exe
2017-09-24 15:10 - 2017-09-24 15:10 - 000000973 _____ C:\Users\Linda\Desktop\checkup.txt
2017-09-24 13:46 - 2017-09-24 13:46 - 000852798 _____ C:\Users\Linda\Desktop\SecurityCheck.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-05 09:50 - 2009-07-13 21:45 - 000029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-10-05 09:50 - 2009-07-13 21:45 - 000029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-10-05 09:39 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-10-04 20:56 - 2015-01-08 19:33 - 000000010 _____ C:\Users\Linda\AppData\Local\sponge.last.runtime.cache
2017-10-04 14:33 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\rescache
2017-10-04 10:50 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\system32\NDF
2017-10-03 09:56 - 2009-07-13 22:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2017-10-03 09:56 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2017-10-02 00:20 - 2009-07-13 21:45 - 000269152 _____ C:\Windows\system32\FNTCACHE.DAT
2017-10-02 00:17 - 2013-08-14 22:32 - 000000000 ____D C:\Windows\system32\MRT
2017-10-02 00:12 - 2013-03-18 12:01 - 138202976 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-10-02 00:08 - 2014-01-22 15:39 - 000774592 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-09-28 05:53 - 2009-07-13 22:08 - 000032616 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-09-25 09:20 - 2013-03-08 16:56 - 000000000 ____D C:\Users\Linda\AppData\Roaming\Yahoo!
2017-09-13 14:50 - 2015-01-28 11:43 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-09-13 14:50 - 2015-01-28 11:43 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-09-13 14:50 - 2013-03-06 16:32 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-09-13 14:50 - 2013-03-06 16:32 - 000000000 ____D C:\Windows\system32\Macromed
2017-09-13 14:49 - 2014-08-14 10:49 - 000000000 ____D C:\Users\Linda\AppData\Local\Adobe
==================== Files in the root of some directories =======
2013-03-06 17:02 - 2013-03-06 17:02 - 000000036 _____ () C:\Users\Linda\AppData\Local\housecall.guid.cache
2015-01-08 19:33 - 2017-10-04 20:56 - 000000010 _____ () C:\Users\Linda\AppData\Local\sponge.last.runtime.cache
2013-03-08 16:44 - 2013-05-08 14:31 - 000002625 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2015-08-28 18:32 - 2015-08-28 18:32 - 006583864 _____ () C:\Users\Linda\AppData\Local\Temp\paint.net.4.0.6.install.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-10-01 17:46
==================== End of FRST.txt ============================