1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

STOP C0000135 The program can't start because %hs is missing

Discussion in 'Windows 7' started by chinchymcchilla, Jun 27, 2016.

Thread Status:
Not open for further replies.
  1. chinchymcchilla

    chinchymcchilla Thread Starter

    Joined:
    Jun 27, 2016
    Messages:
    2
    Hello all,

    I am running into a hard blue screen at boot with the following error:

    STOP: C0000135 The program can't start because %hs is missing

    After searching through the internet, I saw multiple reports of using FRST to find the missing/corrupt files and replace them. However, these required some tricky writing of a fixlist.txt for FRST to run, which I basically winged.

    Once I'd done that, the machine would start to boot, and I would get a cursor, and then it would hard crash with a "Critical files missing" or similar bluescreen.

    I system restored back to the %hs missing error and was hoping someone could help me interpret the below output and figure out what fixlist.txt text to use in order to clear up the issue.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2016 02
    Ran by SYSTEM on MININT-T2OMMDE (27-06-2016 14:34:17)
    Running from F:\
    Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Recovery
    Default: ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [708952 2013-07-08] (Alps Electric Co., Ltd.)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
    HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] ()
    HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
    HKLM\...\Run: [DFEPApplication] => C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077880 2013-01-22] (Dell Inc.)
    HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686744 2012-09-05] ()
    HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4791024 2013-04-18] (Intel® Corporation)
    HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2747680 2013-12-03] ()
    HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [257392 2011-05-27] (Wave Systems Corp.)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [821144 2010-10-25] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2010-10-25] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-10-25] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-06] (Avast Software s.r.o.)
    HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
    HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
    HKLM-x32\...\Run: [Dell PanelMgr] => C:\Windows\Dell\panelmgr\SSMMgr.exe /autorun
    HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
    HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [112408 2011-08-08] (Intel Corporation)
    HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-17] (CyberLink Corp.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
    HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
    HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.)
    HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
    HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2016-04-08] (Microsoft Corporation)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
    HKU\David Ayres\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AdobeCollabSync.exe [1216416 2010-10-25] (Adobe Systems Incorporated)
    HKU\David Ayres\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
    HKU\David Ayres\...\Run: [DCO XMPP Desktop Client] => C:\Program Files (x86)\DCO XMPP Desktop Client\DCO XMPP Desktop Client.exe [3993560 2012-10-18] (Jabber, Inc.)
    HKU\David Ayres\...\Run: [Google Update] => C:\Users\David Ayres\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
    HKU\David Ayres\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION)
    HKU\David Ayres\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
    HKU\David Ayres\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
    HKU\UpdatusUser\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516096 2010-11-20] (Microsoft Corporation)
    AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-12-03] (NVIDIA Corporation)
    Lsa: [Authentication Packages] msv1_0 wvauth
    Startup: C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\David Ayres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2016-06-15]
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\David Ayres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    GroupPolicyScripts: Restriction <======= ATTENTION
    GroupPolicyScripts\User: Restriction <======= ATTENTION

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
    S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-06] (Avast Software s.r.o.)
    S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-06] (Avast Software)
    S2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
    S2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
    S2 Dell B2375dfw Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\B2375wServer64.exe [247800 2013-11-11] (Dell Inc)
    S2 DFEPService; c:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280952 2013-01-22] (Dell Inc.)
    S3 InstallRoot; C:\Program Files\DoD-PKE\InstallRoot\InstallRootService.exe [655032 2014-01-15] ()
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
    S2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
    S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1633280 2011-02-17] ()
    S2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1600000 2011-07-01] (Wave Systems Corp.)
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
    S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3388144 2013-04-18] (Intel® Corporation)
    S3 EFS; %SystemRoot%\System32\lsass.exe [X]
    S3 KeyIso; %SystemRoot%\system32\lsass.exe [X]
    S3 Netlogon; %systemroot%\system32\lsass.exe [X]
    S3 ProtectedStorage; %SystemRoot%\system32\lsass.exe [X]
    S2 SamSs; %SystemRoot%\system32\lsass.exe [X]
    S3 VaultSvc; %SystemRoot%\system32\lsass.exe [X]

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-06] ()
    S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-06] (Avast Software s.r.o.)
    S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-06] (Avast Software s.r.o.)
    S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-06] ()
    S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-06] (Avast Software s.r.o.)
    S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-06] (Avast Software s.r.o.)
    S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-06] (Avast Software s.r.o.)
    S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-06] ()
    S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-04-16] (DT Soft Ltd)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S3 HBtnKey; C:\Windows\system32\drivers\HBtnKey.sys [20424 2011-07-19] (Dell Inc.)
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
    S1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-12-03] (NVIDIA Corporation)
    S2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-06] (Avast Software)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-06-27 11:07 - 2016-06-27 14:34 - 00000000 ____D C:\FRST
    2016-06-27 08:44 - 2016-06-27 08:44 - 00003352 ____N C:\bootsqm.dat
    2016-06-24 07:49 - 2016-06-24 07:49 - 00975171 _____ C:\Users\David Ayres\Desktop\dd2930.pdf
    2016-06-21 10:15 - 2016-06-21 10:15 - 00044828 _____ C:\Users\David Ayres\Downloads\uNET_v8_e8149_20160105_ATO-SCA_QR_20160621.xlsx
    2016-06-20 06:55 - 2016-06-20 06:55 - 00035032 _____ C:\Users\David Ayres\Downloads\CHLK_cTB_v14.8_e2027_20160609_BC-VAL_QR_20160615_HPE-20160617 (1).xlsx
    2016-06-20 06:54 - 2016-06-20 06:54 - 00035032 _____ C:\Users\David Ayres\Downloads\CHLK_cTB_v14.8_e2027_20160609_BC-VAL_QR_20160615_HPE-20160617.xlsx
    2016-06-20 06:48 - 2016-06-20 06:48 - 00412166 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Multi_Seat-Std_Seat-SECNET54_060916_Workbook_SSC_Atlantic_Review_061516_Rev1_061716.xlsx
    2016-06-20 06:48 - 2016-06-20 06:48 - 00000165 ____H C:\Users\David Ayres\Downloads\~$CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Multi_Seat-Std_Seat-SECNET54_060916_Workbook_SSC_Atlantic_Review_061516_Rev1_061716.xlsx
    2016-06-17 08:18 - 2016-06-17 09:18 - 09717952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2016-06-16 10:03 - 2016-06-16 10:03 - 00036508 _____ C:\Users\David Ayres\Downloads\LEMR_cTB_v18.7_e1829_20160606_RECERT-VAL_QR_20160613_HPE-20160614 (1).xlsx
    2016-06-16 10:02 - 2016-06-16 10:02 - 00036508 _____ C:\Users\David Ayres\Downloads\LEMR_cTB_v18.7_e1829_20160606_RECERT-VAL_QR_20160613_HPE-20160614.xlsx
    2016-06-15 07:34 - 2016-06-15 07:34 - 00293405 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_AR2_120815_NT_Artifacts.zip
    2016-06-15 07:28 - 2016-06-15 07:28 - 00252727 _____ C:\Users\David Ayres\Downloads\0512-ATO-NMCI-EMASS-2027-NAWS-CHLK.pdf
    2016-06-15 07:12 - 2016-06-15 07:12 - 00385690 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_122115_Workbook_Rev1_VR_010416.xlsx
    2016-06-15 06:15 - 2016-06-15 06:15 - 00181553 _____ C:\Users\David Ayres\Downloads\1679-NMCI-EMASS-4121-KWMP-CPSAS.pdf
    2016-06-15 05:51 - 2016-06-06 08:58 - 00041704 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
    2016-06-15 05:51 - 2016-06-06 08:50 - 01204224 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
    2016-06-15 05:51 - 2016-06-03 05:05 - 01413120 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00569856 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00544256 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00276480 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\System32\centel.dll
    2016-06-15 05:51 - 2016-05-22 05:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
    2016-06-15 05:51 - 2016-05-18 08:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2016-06-15 05:51 - 2016-05-18 08:09 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
    2016-06-15 05:51 - 2016-05-13 13:54 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2016-06-15 05:51 - 2016-05-13 13:27 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2016-06-15 05:51 - 2016-05-12 09:20 - 00154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2016-06-15 05:51 - 2016-05-12 09:20 - 00095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2016-06-15 05:51 - 2016-05-12 09:15 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\System32\winipsec.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 01212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\System32\gpsvc.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\System32\gpprefcl.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\System32\IPSECSVC.DLL
    2016-06-15 05:51 - 2016-05-12 09:14 - 00463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\System32\polstore.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00344064 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00316416 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\System32\gpapi.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\System32\FwRemoteSvr.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\gpscript.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2016-06-15 05:51 - 2016-05-12 07:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\gpscript.exe
    2016-06-15 05:51 - 2016-05-12 07:03 - 03217408 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00464896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
    2016-06-15 05:51 - 2016-05-12 06:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll
    2016-06-15 05:51 - 2016-05-12 06:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe
    2016-06-15 05:51 - 2016-05-12 05:05 - 00459640 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2016-06-15 05:51 - 2016-05-12 05:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\System32\bcryptprimitives.dll
    2016-06-15 05:51 - 2016-05-12 05:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\System32\winhttp.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\mswsock.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\System32\ws2_32.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
    2016-06-15 05:51 - 2016-05-11 07:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\netbtugc.exe
    2016-06-15 05:51 - 2016-05-11 07:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
    2016-06-15 05:51 - 2016-05-11 06:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
    2016-06-15 05:51 - 2016-04-14 08:46 - 00114408 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
    2016-06-15 05:51 - 2016-04-14 08:42 - 03243520 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00070144 _____ (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\msimsg.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
    2016-06-15 05:51 - 2016-04-14 07:19 - 00128000 _____ (Microsoft Corporation) C:\Windows\System32\msiexec.exe
    2016-06-15 05:51 - 2016-04-14 07:11 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
    2016-06-15 05:51 - 2016-04-08 22:58 - 14186496 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2016-06-15 05:51 - 2016-04-08 22:57 - 01867776 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
    2016-06-15 05:51 - 2016-04-08 22:54 - 12881408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2016-06-15 05:51 - 2016-04-08 22:54 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
    2016-06-15 05:51 - 2016-04-08 21:53 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2016-06-15 05:51 - 2016-04-08 21:44 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2016-06-15 05:51 - 2016-03-09 11:00 - 00396800 _____ (Microsoft Corporation) C:\Windows\System32\webio.dll
    2016-06-15 05:51 - 2016-03-09 10:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2016-06-15 05:50 - 2016-05-23 15:37 - 00394960 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2016-06-15 05:50 - 2016-05-23 14:54 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2016-06-15 05:50 - 2016-05-21 09:28 - 25802752 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2016-06-15 05:50 - 2016-05-21 08:57 - 20341248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2016-06-15 05:50 - 2016-05-20 14:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2016-06-15 05:50 - 2016-05-20 14:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
    2016-06-15 05:50 - 2016-05-20 14:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2016-06-15 05:50 - 2016-05-20 14:10 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2016-06-15 05:50 - 2016-05-20 14:09 - 00572416 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2016-06-15 05:50 - 2016-05-20 14:09 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
    2016-06-15 05:50 - 2016-05-20 14:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
    2016-06-15 05:50 - 2016-05-20 14:08 - 02895360 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2016-06-15 05:50 - 2016-05-20 14:08 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
    2016-06-15 05:50 - 2016-05-20 14:02 - 06051328 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2016-06-15 05:50 - 2016-05-20 14:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2016-06-15 05:50 - 2016-05-20 13:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2016-06-15 05:50 - 2016-05-20 13:56 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2016-06-15 05:50 - 2016-05-20 13:56 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2016-06-15 05:50 - 2016-05-20 13:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2016-06-15 05:50 - 2016-05-20 13:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
    2016-06-15 05:50 - 2016-05-20 13:50 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2016-06-15 05:50 - 2016-05-20 13:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2016-06-15 05:50 - 2016-05-20 13:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2016-06-15 05:50 - 2016-05-20 13:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    2016-06-15 05:50 - 2016-05-20 13:45 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2016-06-15 05:50 - 2016-05-20 13:44 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2016-06-15 05:50 - 2016-05-20 13:44 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2016-06-15 05:50 - 2016-05-20 13:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2016-06-15 05:50 - 2016-05-20 13:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2016-06-15 05:50 - 2016-05-20 13:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2016-06-15 05:50 - 2016-05-20 13:33 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
    2016-06-15 05:50 - 2016-05-20 13:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
    2016-06-15 05:50 - 2016-05-20 13:29 - 13815808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2016-06-15 05:50 - 2016-05-20 13:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2016-06-15 05:50 - 2016-05-20 13:27 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2016-06-15 05:50 - 2016-05-20 13:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-06-15 05:50 - 2016-05-20 13:26 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2016-06-15 05:50 - 2016-05-20 13:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2016-06-15 05:50 - 2016-05-20 13:23 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2016-06-15 05:50 - 2016-05-20 13:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2016-06-15 05:50 - 2016-05-20 13:22 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
    2016-06-15 05:50 - 2016-05-20 13:21 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2016-06-15 05:50 - 2016-05-20 13:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2016-06-15 05:50 - 2016-05-20 13:14 - 04610048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2016-06-15 05:50 - 2016-05-20 13:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2016-06-15 05:50 - 2016-05-20 13:11 - 15420928 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2016-06-15 05:50 - 2016-05-20 13:11 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
    2016-06-15 05:50 - 2016-05-20 13:09 - 00725504 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2016-06-15 05:50 - 2016-05-20 13:09 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2016-06-15 05:50 - 2016-05-20 13:08 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2016-06-15 05:50 - 2016-05-20 13:08 - 00806400 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2016-06-15 05:50 - 2016-05-20 13:07 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
    2016-06-15 05:50 - 2016-05-20 13:07 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2016-06-15 05:50 - 2016-05-20 13:06 - 02131968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2016-06-15 05:50 - 2016-05-20 12:46 - 02597888 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2016-06-15 05:50 - 2016-05-20 12:42 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2016-06-15 05:50 - 2016-05-20 12:38 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2016-06-15 05:50 - 2016-05-20 12:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2016-06-15 05:50 - 2016-05-20 12:34 - 01544192 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2016-06-15 05:50 - 2016-05-20 12:23 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2016-06-15 04:50 - 2016-06-15 04:50 - 00044350 _____ C:\Users\David Ayres\Downloads\uNET_v8_e8149_20160105_ATO-SCA_QR_20160615.xlsx
    2016-06-15 04:41 - 2016-06-15 04:44 - 00037609 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610_HPE-20160613 (1).xlsx
    2016-06-14 19:50 - 2016-06-14 19:52 - 71640712 _____ C:\Users\David Ayres\Downloads\zack ep 47.rar
    2016-06-14 09:11 - 2016-06-14 09:11 - 00999149 _____ C:\Users\David Ayres\Downloads\KWMP_Key_West,_FL_(Navy_cPSAS)_ATO_NTPkg_Recert_060916_Topology_Artifacts.zip
    2016-06-14 08:59 - 2016-06-14 08:59 - 02349792 _____ C:\Users\David Ayres\Downloads\CRAN_Crane,_IN_(Navy_cTB)_ATO_NTPkg_Recert_042716_Topology_Artifacts.zip
    2016-06-14 06:34 - 2016-06-14 06:34 - 00036592 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610_HPE-20160613.xlsx
    2016-06-14 06:33 - 2016-06-14 06:36 - 467140542 _____ C:\Users\David Ayres\Downloads\Second Ghost Final.rar
    2016-06-13 08:01 - 2016-06-13 08:01 - 00000000 ____D C:\Users\David Ayres\Desktop\U_Microsoft_IE8_V1R19_STIG
    2016-06-10 09:52 - 2016-06-10 09:52 - 00635953 _____ C:\Users\David Ayres\Downloads\STIGViewer_2.3.jar
    2016-06-10 05:43 - 2016-06-10 05:44 - 00036937 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610.xlsx
    2016-06-09 10:04 - 2016-06-09 10:06 - 403140469 _____ C:\Users\David Ayres\Downloads\sailor moon zack.rar
    2016-06-08 11:30 - 2016-06-08 11:30 - 01156929 _____ C:\Users\David Ayres\Downloads\2276-ATO-NMCI-EMASS-2099-CFALN (1).pdf
    2016-06-08 11:25 - 2016-06-08 11:25 - 00052905 _____ C:\Users\David Ayres\Downloads\LEMR_Lemoore,_CA_(Navy_cTB)_NATO_Handling_Letter_1Oct2014 (1).pdf
    2016-06-08 11:01 - 2016-06-08 11:01 - 00052905 _____ C:\Users\David Ayres\Downloads\LEMR_Lemoore,_CA_(Navy_cTB)_NATO_Handling_Letter_1Oct2014.pdf
    2016-06-08 10:54 - 2016-06-08 10:54 - 00254054 _____ C:\Users\David Ayres\Downloads\2820-ATO-NMCI-EMASS-1829-CLEMR.pdf
    2016-06-08 10:25 - 2016-06-08 10:25 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM (2).xlsx
    2016-06-08 10:13 - 2016-06-08 10:13 - 00757649 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_AR1_011116_NT_Artifacts.zip
    2016-06-08 10:05 - 2016-06-08 10:05 - 01156929 _____ C:\Users\David Ayres\Downloads\2276-ATO-NMCI-EMASS-2099-CFALN.pdf
    2016-06-08 10:04 - 2016-06-08 10:04 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM (1).xlsx
    2016-06-08 10:00 - 2016-06-08 10:00 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM.xlsx
    2016-06-08 07:27 - 2016-06-08 07:27 - 133687369 _____ C:\Users\David Ayres\Downloads\Episode 47 Joel.rar
    2016-06-06 16:05 - 2016-06-06 16:08 - 373812950 _____ C:\Users\David Ayres\Downloads\TWA47_Dustin.zip
    2016-06-06 09:19 - 2016-06-06 09:19 - 00306803 _____ C:\Users\David Ayres\Downloads\MTWN_Moorestown,_NJ_(Navy_cTB)_ATO_NTPkg_New_Seat-Std_090513_NATO.pdf
    2016-06-03 10:57 - 2016-06-03 10:57 - 03603067 _____ C:\Users\David Ayres\Downloads\MTWN_Moorestown,_NJ_(Navy_cTB)_ATO_NTpkg_Recert_060116_Workbook.xlsx
    2016-06-02 11:10 - 2016-06-02 11:13 - 556599639 _____ C:\Users\David Ayres\Downloads\kamenfinal.rar
    2016-06-02 09:00 - 2016-06-02 09:00 - 00000000 ____D C:\Users\David Ayres\AppData\Local\Nicke_Manarin
    2016-06-02 08:59 - 2016-06-02 08:59 - 00427206 _____ C:\Users\David Ayres\Downloads\ScreenToGif 2.zip
    2016-06-01 04:52 - 2016-06-01 04:52 - 00035787 _____ C:\Users\David Ayres\Downloads\SPGF_cTB_v5_e931_20160309_RECERT-SCA_QR_20160524_HPE-20160531.xlsx

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-06-27 14:18 - 2015-12-03 04:34 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
    2016-06-27 14:18 - 2015-07-07 04:25 - 00000000 ____D C:\Users\David Ayres\AppData\Roaming\Audacity
    2016-06-27 14:18 - 2015-04-03 23:00 - 00000000 ___SD C:\Windows\System32\GWX
    2016-06-27 14:18 - 2014-09-26 07:08 - 00000000 ____D C:\users\UpdatusUser
    2016-06-27 14:18 - 2014-09-26 07:08 - 00000000 ____D C:\users\David Ayres
    2016-06-27 14:18 - 2012-09-28 19:37 - 00000000 ____D C:\Users\David Ayres\AppData\Roaming\Skype
    2016-06-27 14:18 - 2012-06-29 20:23 - 00000000 ___HD C:\Windows\System32\WLANProfiles
    2016-06-27 14:18 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
    2016-06-27 14:18 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
    2016-06-25 17:25 - 2012-07-20 09:29 - 00000000 ____D C:\Users\David Ayres\Documents\Outlook Files
    2016-06-25 17:17 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
    2016-06-22 11:59 - 2016-05-08 19:43 - 00000000 ____D C:\Users\David Ayres\Desktop\TWA
    2016-06-22 04:39 - 2012-06-29 20:39 - 00000000 ____D C:\ProgramData\Sonic
    2016-06-21 08:18 - 2012-06-29 20:06 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-06-21 08:05 - 2012-07-19 06:29 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1447834022-383018379-1482320732-1001UA.job
    2016-06-21 05:05 - 2012-07-19 06:29 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1447834022-383018379-1482320732-1001Core.job
    2016-06-21 04:36 - 2009-07-13 20:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-06-21 04:36 - 2009-07-13 20:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-06-21 04:22 - 2014-09-25 09:04 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
    2016-06-20 12:09 - 2009-07-13 21:13 - 00781790 _____ C:\Windows\System32\PerfStringBackup.INI
    2016-06-20 12:04 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-06-20 12:04 - 2009-07-13 20:45 - 00463152 _____ C:\Windows\System32\FNTCACHE.DAT
    2016-06-20 12:01 - 2014-12-10 00:20 - 00000000 ____D C:\Windows\System32\appraiser
    2016-06-17 09:18 - 2012-06-29 20:06 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2016-06-17 09:18 - 2012-06-29 20:06 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-06-17 09:18 - 2012-06-29 20:06 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2016-06-15 23:16 - 2013-08-14 23:02 - 00000000 ____D C:\Windows\System32\MRT
    2016-06-15 23:07 - 2015-02-26 12:32 - 142482544 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2016-06-15 23:04 - 2013-05-29 08:53 - 00000039 _____ C:\Windows\vbaddin.ini
    2016-06-13 15:31 - 2010-11-20 19:27 - 00484008 _____ (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
    2016-06-10 09:52 - 2016-04-12 10:33 - 00635953 _____ C:\Users\David Ayres\Desktop\STIGViewer_2.3.jar
    2016-06-08 09:16 - 2016-05-26 13:29 - 00078297 _____ C:\Users\David Ayres\Desktop\CyberAwareness Challenge DAyres 2016.pdf
    2016-06-08 04:41 - 2015-03-10 07:43 - 00000000 ___RD C:\Program Files (x86)\Skype
    2016-06-08 04:41 - 2012-09-28 19:37 - 00000000 ____D C:\ProgramData\Skype
    2016-06-01 23:00 - 2015-04-03 23:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2016-05-31 23:14 - 2014-09-26 11:02 - 00000000 ____D C:\Windows\Panther
    2016-05-31 23:10 - 2015-10-30 01:42 - 00000000 ___HD C:\$WINDOWS.~BT

    Some files in TEMP:
    ====================
    C:\Users\David Ayres\AppData\Local\Temp\GUR3D46.exe
    C:\Users\David Ayres\AppData\Local\Temp\GUR674B.exe
    C:\Users\David Ayres\AppData\Local\Temp\GURC138.exe
    C:\Users\David Ayres\AppData\Local\Temp\IntResource.dll
    C:\Users\David Ayres\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u60-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u71-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u77-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u91-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\{7DD24307-56CB-4349-97EA-3E07EA1653DA}-50.0.2661.94_49.0.2623.112_chrome_updater.exe
    C:\Users\David Ayres\AppData\Local\Temp\{F9CCA2AD-BB5B-4E99-9FED-32722D426167}-GoogleUpdateSetup.exe


    ==================== Known DLLs (Whitelisted) =========================

    C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION
    C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION
    C:\Windows\SysWOW64\rpcrt4.dll IS MISSING <==== ATTENTION

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe
    [2016-06-15 05:51] - [2016-04-08 21:53] - 3231232 ____A (Microsoft Corporation) 9DA3B83F80E205B6C601EEE1312FD0A0

    C:\Windows\SysWOW64\explorer.exe
    [2016-06-15 05:51] - [2016-04-08 21:44] - 2973184 ____A (Microsoft Corporation) 3DA48EA028AD771C5B71727F0C3984E9

    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\dnsapi.dll => MD5 is legit
    C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Association (Whitelisted) =============


    ==================== Restore Points =========================

    Restore point date: 2016-06-21 08:48

    ==================== Memory info ===========================

    Percentage of memory in use: 12%
    Total physical RAM: 8074.15 MB
    Available physical RAM: 7047.51 MB
    Total Virtual: 8072.35 MB
    Available Virtual: 7050.45 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:284.8 GB) (Free:125.12 GB) NTFS
    Drive e: (W7SP1_PROFESSIONAL) (CDROM) (Total:5.23 GB) (Free:0 GB) UDF
    Drive f: () (Removable) (Total:29.8 GB) (Free:29.79 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (RECOVERY) (Fixed) (Total:13.25 GB) (Free:4.35 GB) NTFS ==>[system with boot components (obtained from drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 76D260D2)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=13.3 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=284.8 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 29.8 GB) (Disk ID: 00000000)

    Partition: GPT.


    LastRegBack: 2016-06-16 20:52

    ==================== End of FRST.txt ============================Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2016 02
    Ran by SYSTEM on MININT-T2OMMDE (27-06-2016 14:34:17)
    Running from F:\
    Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Recovery
    Default: ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [708952 2013-07-08] (Alps Electric Co., Ltd.)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
    HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] ()
    HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
    HKLM\...\Run: [DFEPApplication] => C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077880 2013-01-22] (Dell Inc.)
    HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686744 2012-09-05] ()
    HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4791024 2013-04-18] (Intel® Corporation)
    HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2747680 2013-12-03] ()
    HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [257392 2011-05-27] (Wave Systems Corp.)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [821144 2010-10-25] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2010-10-25] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-10-25] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-06] (Avast Software s.r.o.)
    HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
    HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
    HKLM-x32\...\Run: [Dell PanelMgr] => C:\Windows\Dell\panelmgr\SSMMgr.exe /autorun
    HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
    HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [112408 2011-08-08] (Intel Corporation)
    HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-17] (CyberLink Corp.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
    HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
    HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.)
    HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
    HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2016-04-08] (Microsoft Corporation)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
    HKU\David Ayres\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AdobeCollabSync.exe [1216416 2010-10-25] (Adobe Systems Incorporated)
    HKU\David Ayres\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
    HKU\David Ayres\...\Run: [DCO XMPP Desktop Client] => C:\Program Files (x86)\DCO XMPP Desktop Client\DCO XMPP Desktop Client.exe [3993560 2012-10-18] (Jabber, Inc.)
    HKU\David Ayres\...\Run: [Google Update] => C:\Users\David Ayres\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
    HKU\David Ayres\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION)
    HKU\David Ayres\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
    HKU\David Ayres\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
    HKU\UpdatusUser\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516096 2010-11-20] (Microsoft Corporation)
    AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-12-03] (NVIDIA Corporation)
    Lsa: [Authentication Packages] msv1_0 wvauth
    Startup: C:\Users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\David Ayres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2016-06-15]
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\David Ayres\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk [2013-11-18]
    ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
    GroupPolicyScripts: Restriction <======= ATTENTION
    GroupPolicyScripts\User: Restriction <======= ATTENTION

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
    S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-06] (Avast Software s.r.o.)
    S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-06] (Avast Software)
    S2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
    S2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
    S2 Dell B2375dfw Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\B2375wServer64.exe [247800 2013-11-11] (Dell Inc)
    S2 DFEPService; c:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280952 2013-01-22] (Dell Inc.)
    S3 InstallRoot; C:\Program Files\DoD-PKE\InstallRoot\InstallRootService.exe [655032 2014-01-15] ()
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
    S2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
    S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1633280 2011-02-17] ()
    S2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1600000 2011-07-01] (Wave Systems Corp.)
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
    S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3388144 2013-04-18] (Intel® Corporation)
    S3 EFS; %SystemRoot%\System32\lsass.exe [X]
    S3 KeyIso; %SystemRoot%\system32\lsass.exe [X]
    S3 Netlogon; %systemroot%\system32\lsass.exe [X]
    S3 ProtectedStorage; %SystemRoot%\system32\lsass.exe [X]
    S2 SamSs; %SystemRoot%\system32\lsass.exe [X]
    S3 VaultSvc; %SystemRoot%\system32\lsass.exe [X]

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-06] ()
    S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-06] (Avast Software s.r.o.)
    S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-06] (Avast Software s.r.o.)
    S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-06] ()
    S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-06] (Avast Software s.r.o.)
    S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-06] (Avast Software s.r.o.)
    S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-06] (Avast Software s.r.o.)
    S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-06] ()
    S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-04-16] (DT Soft Ltd)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S3 HBtnKey; C:\Windows\system32\drivers\HBtnKey.sys [20424 2011-07-19] (Dell Inc.)
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
    S1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-12-03] (NVIDIA Corporation)
    S2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-06] (Avast Software)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-06-27 11:07 - 2016-06-27 14:34 - 00000000 ____D C:\FRST
    2016-06-27 08:44 - 2016-06-27 08:44 - 00003352 ____N C:\bootsqm.dat
    2016-06-24 07:49 - 2016-06-24 07:49 - 00975171 _____ C:\Users\David Ayres\Desktop\dd2930.pdf
    2016-06-21 10:15 - 2016-06-21 10:15 - 00044828 _____ C:\Users\David Ayres\Downloads\uNET_v8_e8149_20160105_ATO-SCA_QR_20160621.xlsx
    2016-06-20 06:55 - 2016-06-20 06:55 - 00035032 _____ C:\Users\David Ayres\Downloads\CHLK_cTB_v14.8_e2027_20160609_BC-VAL_QR_20160615_HPE-20160617 (1).xlsx
    2016-06-20 06:54 - 2016-06-20 06:54 - 00035032 _____ C:\Users\David Ayres\Downloads\CHLK_cTB_v14.8_e2027_20160609_BC-VAL_QR_20160615_HPE-20160617.xlsx
    2016-06-20 06:48 - 2016-06-20 06:48 - 00412166 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Multi_Seat-Std_Seat-SECNET54_060916_Workbook_SSC_Atlantic_Review_061516_Rev1_061716.xlsx
    2016-06-20 06:48 - 2016-06-20 06:48 - 00000165 ____H C:\Users\David Ayres\Downloads\~$CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Multi_Seat-Std_Seat-SECNET54_060916_Workbook_SSC_Atlantic_Review_061516_Rev1_061716.xlsx
    2016-06-17 08:18 - 2016-06-17 09:18 - 09717952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
    2016-06-16 10:03 - 2016-06-16 10:03 - 00036508 _____ C:\Users\David Ayres\Downloads\LEMR_cTB_v18.7_e1829_20160606_RECERT-VAL_QR_20160613_HPE-20160614 (1).xlsx
    2016-06-16 10:02 - 2016-06-16 10:02 - 00036508 _____ C:\Users\David Ayres\Downloads\LEMR_cTB_v18.7_e1829_20160606_RECERT-VAL_QR_20160613_HPE-20160614.xlsx
    2016-06-15 07:34 - 2016-06-15 07:34 - 00293405 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_AR2_120815_NT_Artifacts.zip
    2016-06-15 07:28 - 2016-06-15 07:28 - 00252727 _____ C:\Users\David Ayres\Downloads\0512-ATO-NMCI-EMASS-2027-NAWS-CHLK.pdf
    2016-06-15 07:12 - 2016-06-15 07:12 - 00385690 _____ C:\Users\David Ayres\Downloads\CHLK_China_Lake,_CA_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_122115_Workbook_Rev1_VR_010416.xlsx
    2016-06-15 06:15 - 2016-06-15 06:15 - 00181553 _____ C:\Users\David Ayres\Downloads\1679-NMCI-EMASS-4121-KWMP-CPSAS.pdf
    2016-06-15 05:51 - 2016-06-06 08:58 - 00041704 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
    2016-06-15 05:51 - 2016-06-06 08:50 - 01204224 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
    2016-06-15 05:51 - 2016-06-03 05:05 - 01413120 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00569856 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00544256 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00276480 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
    2016-06-15 05:51 - 2016-05-27 05:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\System32\centel.dll
    2016-06-15 05:51 - 2016-05-22 05:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
    2016-06-15 05:51 - 2016-05-18 08:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2016-06-15 05:51 - 2016-05-18 08:09 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
    2016-06-15 05:51 - 2016-05-13 13:54 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2016-06-15 05:51 - 2016-05-13 13:27 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2016-06-15 05:51 - 2016-05-12 09:20 - 00154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2016-06-15 05:51 - 2016-05-12 09:20 - 00095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2016-06-15 05:51 - 2016-05-12 09:15 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\System32\winipsec.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
    2016-06-15 05:51 - 2016-05-12 09:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 01212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\System32\gpsvc.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\System32\gpprefcl.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\System32\IPSECSVC.DLL
    2016-06-15 05:51 - 2016-05-12 09:14 - 00463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\System32\polstore.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00344064 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00316416 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\System32\gpapi.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\System32\FwRemoteSvr.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
    2016-06-15 05:51 - 2016-05-12 09:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\gpscript.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
    2016-06-15 05:51 - 2016-05-12 07:18 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2016-06-15 05:51 - 2016-05-12 07:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\gpscript.exe
    2016-06-15 05:51 - 2016-05-12 07:03 - 03217408 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00464896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
    2016-06-15 05:51 - 2016-05-12 06:58 - 00129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
    2016-06-15 05:51 - 2016-05-12 06:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll
    2016-06-15 05:51 - 2016-05-12 06:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe
    2016-06-15 05:51 - 2016-05-12 05:05 - 00459640 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2016-06-15 05:51 - 2016-05-12 05:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\System32\bcryptprimitives.dll
    2016-06-15 05:51 - 2016-05-12 05:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\System32\winhttp.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\mswsock.dll
    2016-06-15 05:51 - 2016-05-11 09:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\System32\ws2_32.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
    2016-06-15 05:51 - 2016-05-11 07:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
    2016-06-15 05:51 - 2016-05-11 07:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\netbtugc.exe
    2016-06-15 05:51 - 2016-05-11 07:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
    2016-06-15 05:51 - 2016-05-11 06:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
    2016-06-15 05:51 - 2016-04-14 08:46 - 00114408 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
    2016-06-15 05:51 - 2016-04-14 08:42 - 03243520 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00070144 _____ (Microsoft Corporation) C:\Windows\System32\appinfo.dll
    2016-06-15 05:51 - 2016-04-14 08:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\msimsg.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2016-06-15 05:51 - 2016-04-14 07:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
    2016-06-15 05:51 - 2016-04-14 07:19 - 00128000 _____ (Microsoft Corporation) C:\Windows\System32\msiexec.exe
    2016-06-15 05:51 - 2016-04-14 07:11 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
    2016-06-15 05:51 - 2016-04-08 22:58 - 14186496 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2016-06-15 05:51 - 2016-04-08 22:57 - 01867776 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
    2016-06-15 05:51 - 2016-04-08 22:54 - 12881408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2016-06-15 05:51 - 2016-04-08 22:54 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
    2016-06-15 05:51 - 2016-04-08 21:53 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2016-06-15 05:51 - 2016-04-08 21:44 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2016-06-15 05:51 - 2016-03-09 11:00 - 00396800 _____ (Microsoft Corporation) C:\Windows\System32\webio.dll
    2016-06-15 05:51 - 2016-03-09 10:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2016-06-15 05:50 - 2016-05-23 15:37 - 00394960 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2016-06-15 05:50 - 2016-05-23 14:54 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2016-06-15 05:50 - 2016-05-21 09:28 - 25802752 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2016-06-15 05:50 - 2016-05-21 08:57 - 20341248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2016-06-15 05:50 - 2016-05-20 14:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2016-06-15 05:50 - 2016-05-20 14:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
    2016-06-15 05:50 - 2016-05-20 14:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2016-06-15 05:50 - 2016-05-20 14:10 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2016-06-15 05:50 - 2016-05-20 14:09 - 00572416 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2016-06-15 05:50 - 2016-05-20 14:09 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
    2016-06-15 05:50 - 2016-05-20 14:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
    2016-06-15 05:50 - 2016-05-20 14:08 - 02895360 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2016-06-15 05:50 - 2016-05-20 14:08 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
    2016-06-15 05:50 - 2016-05-20 14:02 - 06051328 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2016-06-15 05:50 - 2016-05-20 14:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2016-06-15 05:50 - 2016-05-20 13:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2016-06-15 05:50 - 2016-05-20 13:57 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2016-06-15 05:50 - 2016-05-20 13:56 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2016-06-15 05:50 - 2016-05-20 13:56 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2016-06-15 05:50 - 2016-05-20 13:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
    2016-06-15 05:50 - 2016-05-20 13:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2016-06-15 05:50 - 2016-05-20 13:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
    2016-06-15 05:50 - 2016-05-20 13:50 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2016-06-15 05:50 - 2016-05-20 13:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2016-06-15 05:50 - 2016-05-20 13:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2016-06-15 05:50 - 2016-05-20 13:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
    2016-06-15 05:50 - 2016-05-20 13:45 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2016-06-15 05:50 - 2016-05-20 13:44 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2016-06-15 05:50 - 2016-05-20 13:44 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2016-06-15 05:50 - 2016-05-20 13:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2016-06-15 05:50 - 2016-05-20 13:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2016-06-15 05:50 - 2016-05-20 13:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2016-06-15 05:50 - 2016-05-20 13:33 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
    2016-06-15 05:50 - 2016-05-20 13:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
    2016-06-15 05:50 - 2016-05-20 13:29 - 13815808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2016-06-15 05:50 - 2016-05-20 13:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2016-06-15 05:50 - 2016-05-20 13:27 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2016-06-15 05:50 - 2016-05-20 13:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-06-15 05:50 - 2016-05-20 13:26 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2016-06-15 05:50 - 2016-05-20 13:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2016-06-15 05:50 - 2016-05-20 13:23 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2016-06-15 05:50 - 2016-05-20 13:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2016-06-15 05:50 - 2016-05-20 13:22 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
    2016-06-15 05:50 - 2016-05-20 13:21 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2016-06-15 05:50 - 2016-05-20 13:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2016-06-15 05:50 - 2016-05-20 13:14 - 04610048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2016-06-15 05:50 - 2016-05-20 13:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2016-06-15 05:50 - 2016-05-20 13:11 - 15420928 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2016-06-15 05:50 - 2016-05-20 13:11 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
    2016-06-15 05:50 - 2016-05-20 13:09 - 00725504 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2016-06-15 05:50 - 2016-05-20 13:09 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2016-06-15 05:50 - 2016-05-20 13:08 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2016-06-15 05:50 - 2016-05-20 13:08 - 00806400 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2016-06-15 05:50 - 2016-05-20 13:07 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
    2016-06-15 05:50 - 2016-05-20 13:07 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2016-06-15 05:50 - 2016-05-20 13:06 - 02131968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2016-06-15 05:50 - 2016-05-20 12:46 - 02597888 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2016-06-15 05:50 - 2016-05-20 12:42 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2016-06-15 05:50 - 2016-05-20 12:38 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2016-06-15 05:50 - 2016-05-20 12:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2016-06-15 05:50 - 2016-05-20 12:34 - 01544192 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2016-06-15 05:50 - 2016-05-20 12:23 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2016-06-15 04:50 - 2016-06-15 04:50 - 00044350 _____ C:\Users\David Ayres\Downloads\uNET_v8_e8149_20160105_ATO-SCA_QR_20160615.xlsx
    2016-06-15 04:41 - 2016-06-15 04:44 - 00037609 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610_HPE-20160613 (1).xlsx
    2016-06-14 19:50 - 2016-06-14 19:52 - 71640712 _____ C:\Users\David Ayres\Downloads\zack ep 47.rar
    2016-06-14 09:11 - 2016-06-14 09:11 - 00999149 _____ C:\Users\David Ayres\Downloads\KWMP_Key_West,_FL_(Navy_cPSAS)_ATO_NTPkg_Recert_060916_Topology_Artifacts.zip
    2016-06-14 08:59 - 2016-06-14 08:59 - 02349792 _____ C:\Users\David Ayres\Downloads\CRAN_Crane,_IN_(Navy_cTB)_ATO_NTPkg_Recert_042716_Topology_Artifacts.zip
    2016-06-14 06:34 - 2016-06-14 06:34 - 00036592 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610_HPE-20160613.xlsx
    2016-06-14 06:33 - 2016-06-14 06:36 - 467140542 _____ C:\Users\David Ayres\Downloads\Second Ghost Final.rar
    2016-06-13 08:01 - 2016-06-13 08:01 - 00000000 ____D C:\Users\David Ayres\Desktop\U_Microsoft_IE8_V1R19_STIG
    2016-06-10 09:52 - 2016-06-10 09:52 - 00635953 _____ C:\Users\David Ayres\Downloads\STIGViewer_2.3.jar
    2016-06-10 05:43 - 2016-06-10 05:44 - 00036937 _____ C:\Users\David Ayres\Downloads\ATLN_cPSAS_v3_e3996_20160318_RECERT-SCA_QR_20160610.xlsx
    2016-06-09 10:04 - 2016-06-09 10:06 - 403140469 _____ C:\Users\David Ayres\Downloads\sailor moon zack.rar
    2016-06-08 11:30 - 2016-06-08 11:30 - 01156929 _____ C:\Users\David Ayres\Downloads\2276-ATO-NMCI-EMASS-2099-CFALN (1).pdf
    2016-06-08 11:25 - 2016-06-08 11:25 - 00052905 _____ C:\Users\David Ayres\Downloads\LEMR_Lemoore,_CA_(Navy_cTB)_NATO_Handling_Letter_1Oct2014 (1).pdf
    2016-06-08 11:01 - 2016-06-08 11:01 - 00052905 _____ C:\Users\David Ayres\Downloads\LEMR_Lemoore,_CA_(Navy_cTB)_NATO_Handling_Letter_1Oct2014.pdf
    2016-06-08 10:54 - 2016-06-08 10:54 - 00254054 _____ C:\Users\David Ayres\Downloads\2820-ATO-NMCI-EMASS-1829-CLEMR.pdf
    2016-06-08 10:25 - 2016-06-08 10:25 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM (2).xlsx
    2016-06-08 10:13 - 2016-06-08 10:13 - 00757649 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_AR1_011116_NT_Artifacts.zip
    2016-06-08 10:05 - 2016-06-08 10:05 - 01156929 _____ C:\Users\David Ayres\Downloads\2276-ATO-NMCI-EMASS-2099-CFALN.pdf
    2016-06-08 10:04 - 2016-06-08 10:04 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM (1).xlsx
    2016-06-08 10:00 - 2016-06-08 10:00 - 00382720 _____ C:\Users\David Ayres\Downloads\FALN_Fallon,_NV_(Navy_cTB)_ATO_NTPkg_BC_Seat-Std_121015_Workbook_VR_PBM.xlsx
    2016-06-08 07:27 - 2016-06-08 07:27 - 133687369 _____ C:\Users\David Ayres\Downloads\Episode 47 Joel.rar
    2016-06-06 16:05 - 2016-06-06 16:08 - 373812950 _____ C:\Users\David Ayres\Downloads\TWA47_Dustin.zip
    2016-06-06 09:19 - 2016-06-06 09:19 - 00306803 _____ C:\Users\David Ayres\Downloads\MTWN_Moorestown,_NJ_(Navy_cTB)_ATO_NTPkg_New_Seat-Std_090513_NATO.pdf
    2016-06-03 10:57 - 2016-06-03 10:57 - 03603067 _____ C:\Users\David Ayres\Downloads\MTWN_Moorestown,_NJ_(Navy_cTB)_ATO_NTpkg_Recert_060116_Workbook.xlsx
    2016-06-02 11:10 - 2016-06-02 11:13 - 556599639 _____ C:\Users\David Ayres\Downloads\kamenfinal.rar
    2016-06-02 09:00 - 2016-06-02 09:00 - 00000000 ____D C:\Users\David Ayres\AppData\Local\Nicke_Manarin
    2016-06-02 08:59 - 2016-06-02 08:59 - 00427206 _____ C:\Users\David Ayres\Downloads\ScreenToGif 2.zip
    2016-06-01 04:52 - 2016-06-01 04:52 - 00035787 _____ C:\Users\David Ayres\Downloads\SPGF_cTB_v5_e931_20160309_RECERT-SCA_QR_20160524_HPE-20160531.xlsx

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-06-27 14:18 - 2015-12-03 04:34 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
    2016-06-27 14:18 - 2015-07-07 04:25 - 00000000 ____D C:\Users\David Ayres\AppData\Roaming\Audacity
    2016-06-27 14:18 - 2015-04-03 23:00 - 00000000 ___SD C:\Windows\System32\GWX
    2016-06-27 14:18 - 2014-09-26 07:08 - 00000000 ____D C:\users\UpdatusUser
    2016-06-27 14:18 - 2014-09-26 07:08 - 00000000 ____D C:\users\David Ayres
    2016-06-27 14:18 - 2012-09-28 19:37 - 00000000 ____D C:\Users\David Ayres\AppData\Roaming\Skype
    2016-06-27 14:18 - 2012-06-29 20:23 - 00000000 ___HD C:\Windows\System32\WLANProfiles
    2016-06-27 14:18 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
    2016-06-27 14:18 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
    2016-06-25 17:25 - 2012-07-20 09:29 - 00000000 ____D C:\Users\David Ayres\Documents\Outlook Files
    2016-06-25 17:17 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
    2016-06-22 11:59 - 2016-05-08 19:43 - 00000000 ____D C:\Users\David Ayres\Desktop\TWA
    2016-06-22 04:39 - 2012-06-29 20:39 - 00000000 ____D C:\ProgramData\Sonic
    2016-06-21 08:18 - 2012-06-29 20:06 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-06-21 08:05 - 2012-07-19 06:29 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1447834022-383018379-1482320732-1001UA.job
    2016-06-21 05:05 - 2012-07-19 06:29 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1447834022-383018379-1482320732-1001Core.job
    2016-06-21 04:36 - 2009-07-13 20:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-06-21 04:36 - 2009-07-13 20:45 - 00031312 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-06-21 04:22 - 2014-09-25 09:04 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
    2016-06-20 12:09 - 2009-07-13 21:13 - 00781790 _____ C:\Windows\System32\PerfStringBackup.INI
    2016-06-20 12:04 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-06-20 12:04 - 2009-07-13 20:45 - 00463152 _____ C:\Windows\System32\FNTCACHE.DAT
    2016-06-20 12:01 - 2014-12-10 00:20 - 00000000 ____D C:\Windows\System32\appraiser
    2016-06-17 09:18 - 2012-06-29 20:06 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2016-06-17 09:18 - 2012-06-29 20:06 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-06-17 09:18 - 2012-06-29 20:06 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2016-06-15 23:16 - 2013-08-14 23:02 - 00000000 ____D C:\Windows\System32\MRT
    2016-06-15 23:07 - 2015-02-26 12:32 - 142482544 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2016-06-15 23:04 - 2013-05-29 08:53 - 00000039 _____ C:\Windows\vbaddin.ini
    2016-06-13 15:31 - 2010-11-20 19:27 - 00484008 _____ (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
    2016-06-10 09:52 - 2016-04-12 10:33 - 00635953 _____ C:\Users\David Ayres\Desktop\STIGViewer_2.3.jar
    2016-06-08 09:16 - 2016-05-26 13:29 - 00078297 _____ C:\Users\David Ayres\Desktop\CyberAwareness Challenge DAyres 2016.pdf
    2016-06-08 04:41 - 2015-03-10 07:43 - 00000000 ___RD C:\Program Files (x86)\Skype
    2016-06-08 04:41 - 2012-09-28 19:37 - 00000000 ____D C:\ProgramData\Skype
    2016-06-01 23:00 - 2015-04-03 23:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2016-05-31 23:14 - 2014-09-26 11:02 - 00000000 ____D C:\Windows\Panther
    2016-05-31 23:10 - 2015-10-30 01:42 - 00000000 ___HD C:\$WINDOWS.~BT

    Some files in TEMP:
    ====================
    C:\Users\David Ayres\AppData\Local\Temp\GUR3D46.exe
    C:\Users\David Ayres\AppData\Local\Temp\GUR674B.exe
    C:\Users\David Ayres\AppData\Local\Temp\GURC138.exe
    C:\Users\David Ayres\AppData\Local\Temp\IntResource.dll
    C:\Users\David Ayres\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u60-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u71-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u77-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\jre-8u91-windows-au.exe
    C:\Users\David Ayres\AppData\Local\Temp\{7DD24307-56CB-4349-97EA-3E07EA1653DA}-50.0.2661.94_49.0.2623.112_chrome_updater.exe
    C:\Users\David Ayres\AppData\Local\Temp\{F9CCA2AD-BB5B-4E99-9FED-32722D426167}-GoogleUpdateSetup.exe


    ==================== Known DLLs (Whitelisted) =========================

    C:\Windows\System32\LPK.dll IS MISSING <==== ATTENTION
    C:\Windows\SysWOW64\LPK.dll IS MISSING <==== ATTENTION
    C:\Windows\SysWOW64\rpcrt4.dll IS MISSING <==== ATTENTION

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe
    [2016-06-15 05:51] - [2016-04-08 21:53] - 3231232 ____A (Microsoft Corporation) 9DA3B83F80E205B6C601EEE1312FD0A0

    C:\Windows\SysWOW64\explorer.exe
    [2016-06-15 05:51] - [2016-04-08 21:44] - 2973184 ____A (Microsoft Corporation) 3DA48EA028AD771C5B71727F0C3984E9

    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\dnsapi.dll => MD5 is legit
    C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Association (Whitelisted) =============


    ==================== Restore Points =========================

    Restore point date: 2016-06-21 08:48

    ==================== Memory info ===========================

    Percentage of memory in use: 12%
    Total physical RAM: 8074.15 MB
    Available physical RAM: 7047.51 MB
    Total Virtual: 8072.35 MB
    Available Virtual: 7050.45 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:284.8 GB) (Free:125.12 GB) NTFS
    Drive e: (W7SP1_PROFESSIONAL) (CDROM) (Total:5.23 GB) (Free:0 GB) UDF
    Drive f: () (Removable) (Total:29.8 GB) (Free:29.79 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (RECOVERY) (Fixed) (Total:13.25 GB) (Free:4.35 GB) NTFS ==>[system with boot components (obtained from drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 76D260D2)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=13.3 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=284.8 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 29.8 GB) (Disk ID: 00000000)

    Partition: GPT.


    LastRegBack: 2016-06-16 20:52

    ==================== End of FRST.txt ============================
     
  2. chinchymcchilla

    chinchymcchilla Thread Starter

    Joined:
    Jun 27, 2016
    Messages:
    2
    In addition, here are the search texts for the two missing DLLs!


    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23346_none_12b8c292bebb0ba0\lpk.dll
    [2016-03-09 06:23][2016-02-05 14:39] 0025600 ____A (Microsoft Corporation) 9C75CEED81D8EA8802A0563B00E13DE5

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23188_none_128f7faabed9b3c4\lpk.dll
    [2015-09-08 12:37][2015-09-01 18:36] 0025600 ____A (Microsoft Corporation) 3EDCBF9078520F613922E0D70A5906A7

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23149_none_12bbbfa4beb85d57\lpk.dll
    [2015-08-12 04:15][2015-07-30 09:53] 0025600 ____A (Microsoft Corporation) FFE0FA7543E1B9B37352710BC8B9121C

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23126_none_12ce5e9ebeaad970\lpk.dll
    [2015-07-20 19:35][2015-07-14 18:58] 0025600 ____A (Microsoft Corporation) 20503EB76CAE40D601ABD38FC1B2CDCF

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23117_none_12da2ed4bea1d6d6\lpk.dll
    [2015-07-14 12:36][2015-07-03 09:46] 0025600 ____A (Microsoft Corporation) E6BD42B2ACD11455768A4DDA38CED674

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22974_none_12967466bed5020e\lpk.dll
    [2015-03-10 23:17][2015-02-19 21:14] 0025600 ____A (Microsoft Corporation) 7B1CABC4896210612AE600238E59CF15

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22350_none_12a807b2bec875e6\lpk.dll
    [2014-09-26 23:24][2013-06-05 21:07] 0025600 ____A (Microsoft Corporation) 84CA3579EEB69D8E1EE67E4F721BF71C

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.19146_none_122f23e1a59d6eaf\lpk.dll
    [2016-03-09 06:23][2016-02-05 10:50] 0025600 ____A (Microsoft Corporation) BC8EA7CD95A7BA8B468B47BD7D9E55AF

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18985_none_120309dfa5be94b3\lpk.dll
    [2015-09-08 12:37][2015-09-01 18:47] 0025600 ____A (Microsoft Corporation) 415FB89174E6D8BFC885A00A01C3446B

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18946_none_122f49d9a59d3e46\lpk.dll
    [2015-08-12 04:15][2015-07-30 09:55] 0025600 ____A (Microsoft Corporation) 9E2F12744DD9810961031C56FBB691F4

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18923_none_1241e8d3a58fba5f\lpk.dll
    [2015-07-20 19:35][2015-07-14 18:54] 0025600 ____A (Microsoft Corporation) D80ECB18D64AE3C2A9D8220ABEBCE40A

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18914_none_124db909a586b7c5\lpk.dll
    [2015-07-14 12:36][2015-07-03 09:55] 0025600 ____A (Microsoft Corporation) 4644A3B2AFDDAEA57C3EC30F8D079E54

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18768_none_121ba6c9a5abae88\lpk.dll
    [2015-03-10 23:17][2015-02-19 20:12] 0025600 ____A (Microsoft Corporation) 01D9C9A70323BC7E5835B92442DD7EC2

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18177_none_120fcb2fa5b4c238\lpk.dll
    [2014-09-26 23:24][2013-06-05 20:57] 0025600 ____A (Microsoft Corporation) CC23295DA8F7B5C53F93804D2F5D30EB

    C:\Windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_124dc839a586a988\lpk.dll
    [2009-07-13 15:25][2009-07-13 17:11] 0025600 ____A (Microsoft Corporation) 384721EF4024890092625E20CADFAF85

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23346_none_086418408a5a49a5\lpk.dll
    [2016-03-09 06:23][2016-02-05 15:06] 0041472 ____A (Microsoft Corporation) 09D95D7531E858F6BC2C8ABAD3A27D49

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23188_none_083ad5588a78f1c9\lpk.dll
    [2015-09-08 12:37][2015-09-01 19:10] 0041984 ____A (Microsoft Corporation) 38E22ADC0D95A1C860C900513A8DC5E9

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23149_none_086715528a579b5c\lpk.dll
    [2015-08-12 04:15][2015-07-30 10:22] 0041984 ____A (Microsoft Corporation) 6399191EEE641F711E094B95B91DBA4B

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23126_none_0879b44c8a4a1775\lpk.dll
    [2015-07-20 19:35][2015-07-14 19:20] 0041984 ____A (Microsoft Corporation) 7F55FE319EF06C1986B994A3E86C52B4

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.23117_none_088584828a4114db\lpk.dll
    [2015-07-14 12:36][2015-07-03 10:13] 0041984 ____A (Microsoft Corporation) 2F518A6C7BE454C9A60880281F9BEAAA

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22974_none_0841ca148a744013\lpk.dll
    [2015-03-10 23:17][2015-02-19 21:25] 0041984 ____A (Microsoft Corporation) DEEE064A330560593BBED835F591F0A5

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22350_none_08535d608a67b3eb\lpk.dll
    [2014-09-26 23:24][2013-06-05 21:17] 0041472 ____A (Microsoft Corporation) 22FC61B8E1EBA296FF416C3678E26DD3

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.19146_none_07da798f713cacb4\lpk.dll
    [2016-03-09 06:23][2016-02-05 10:54] 0041472 ____A (Microsoft Corporation) C8B4E3DBD1D0A6E5819AA8F546945504

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18985_none_07ae5f8d715dd2b8\lpk.dll
    [2015-09-08 12:37][2015-09-01 19:04] 0041984 ____A (Microsoft Corporation) 0E8D254B70E880F032036BFD45266754

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18946_none_07da9f87713c7c4b\lpk.dll
    [2015-08-12 04:15][2015-07-30 10:06] 0041984 ____A (Microsoft Corporation) 0365E7AED8A38CB5FFF1DFB4458C0593

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18923_none_07ed3e81712ef864\lpk.dll
    [2015-07-20 19:35][2015-07-14 19:19] 0041984 ____A (Microsoft Corporation) D57C03D365BC71C7A30504644515F3F8

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18914_none_07f90eb77125f5ca\lpk.dll
    [2015-07-14 12:36][2015-07-03 10:05] 0041984 ____A (Microsoft Corporation) 373CB9C184589E3BE07412DFD5DF3D4F

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18768_none_07c6fc77714aec8d\lpk.dll
    [2015-03-10 23:17][2015-02-19 20:41] 0041984 ____A (Microsoft Corporation) F351B0E520502552734BE70AA5940784

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18177_none_07bb20dd7154003d\lpk.dll
    [2014-09-26 23:24][2013-06-05 21:50] 0041472 ____A (Microsoft Corporation) 796B47A4B82EF1C39F13435B88834C48

    C:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_07f91de77125e78d\lpk.dll
    [2009-07-13 15:38][2009-07-13 17:41] 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

    X:\Windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_07f91de77125e78d\lpk.dll
    [2010-11-20 01:50][2009-07-13 17:41] 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70

    X:\Windows\System32\lpk.dll
    [2010-11-20 01:50][2009-07-13 17:41] 0041984 ____A (Microsoft Corporation) D202223587518B13D72D68937B7E3F70



    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23418_none_1d02bb6fa92ed9b5\rpcrt4.dll
    [2016-05-11 05:53][2016-04-08 22:54] 0666112 ____A (Microsoft Corporation) 16DAAA689DF16BFF36F52FAE8F7242F6

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23392_none_1ca6386da975240c\rpcrt4.dll
    [2016-04-12 22:02][2016-03-17 14:31] 0666112 ____A (Microsoft Corporation) 405B50ED43C2D73B32056168494DEA24

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23391_none_1ca53823a9760ab5\rpcrt4.dll
    [2016-04-12 22:02][2016-03-16 10:31] 0666112 ____A (Microsoft Corporation) EE8F843C8E84419DC6BCF4928B92E8C6

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23390_none_1ca437d9a976f15e\rpcrt4.dll
    [2016-04-12 22:02][2016-03-15 15:54] 0666112 ____A (Microsoft Corporation) 31093B1EE39FAC60BE0247BCBAEFFC78

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23349_none_1ce34a0fa94649b8\rpcrt4.dll
    [2016-03-09 06:23][2016-02-10 10:30] 0666112 ____A (Microsoft Corporation) B978608718B392E1B4BCA162E42923D8

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23338_none_1ced19b1a93f1470\rpcrt4.dll
    [2016-02-10 05:36][2016-01-21 22:06] 0666112 ____A (Microsoft Corporation) 5B3D111C3363E767ACDBF50C013F3D43

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23334_none_1ce91889a942af14\rpcrt4.dll
    [2016-02-10 05:37][2016-01-16 16:17] 0666112 ____A (Microsoft Corporation) 3FEC5882119F859961F1749BBEB27BFA

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23313_none_1cfdb817a9335ddb\rpcrt4.dll
    [2016-01-13 01:40][2015-12-30 10:55] 0666112 ____A (Microsoft Corporation) 2976FDAF1EE81918D7593C9DC4B07034

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23250_none_1ccf75a3a9568473\rpcrt4.dll
    [2015-11-12 05:24][2015-10-19 16:45] 0665600 ____A (Microsoft Corporation) 93020D4C3C5E3001BEF1F381356E36BB

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23249_none_1ce34829a9464c91\rpcrt4.dll
    [2015-11-12 05:26][2015-10-16 09:42] 0665600 ____A (Microsoft Corporation) 057B1B11F5C12F2E8D923734097BB5E9

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23223_none_1cf2e645a93b7ca5\rpcrt4.dll
    [2015-10-13 09:40][2015-09-28 12:15] 0665600 ____A (Microsoft Corporation) 7D0DFF65A31D12324651A255FD536D6C

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23153_none_1cd2749ba953d351\rpcrt4.dll
    [2015-09-08 23:55][2015-08-04 09:51] 0665600 ____A (Microsoft Corporation) A68D77C46CA3D1E377DE2AB321540B52

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23142_none_1cdc443da94c9e09\rpcrt4.dll
    [2015-09-08 12:38][2015-07-22 15:56] 0665600 ____A (Microsoft Corporation) 19A4D76B90CE09AA9737D435B35FFB22

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23136_none_1ceb1551a940e774\rpcrt4.dll
    [2015-08-12 04:16][2015-07-15 09:48] 0665600 ____A (Microsoft Corporation) F9A3FEB68148043D15B90E2E678DF7B7

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23126_none_1cf5e53da938cb83\rpcrt4.dll
    [2015-08-12 04:16][2015-07-14 18:58] 0665600 ____A (Microsoft Corporation) EC8C74840FF2715E49D00DE49F91A74E

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23115_none_1cffb4dfa931963b\rpcrt4.dll
    [2015-07-14 12:36][2015-07-01 09:51] 0665600 ____A (Microsoft Corporation) 8F240A482D0F78A2EAA85CAE198C1351

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23112_none_1cfcb401a9344a36\rpcrt4.dll
    [2015-07-14 12:36][2015-06-27 10:02] 0665600 ____A (Microsoft Corporation) A896EDA1162FF0176612B4091F55C6FC

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.22743_none_1cdd66b3a94b8ca9\rpcrt4.dll
    [2014-09-26 23:15][2014-07-13 17:41] 0665088 ____A (Microsoft Corporation) 9706C6A9CEE9D2C28B254F884AE44CD5

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19160_none_1c3b08ec9041009a\rpcrt4.dll
    [2016-03-09 06:23][2016-02-11 10:38] 0665088 ____A (Microsoft Corporation) 81D70F77DBC2A20E8057FB373D0F9AE6

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19135_none_1c607a2290242b7a\rpcrt4.dll
    [2016-02-10 05:36][2016-01-21 22:06] 0665088 ____A (Microsoft Corporation) B1D78C40DFB3D3AB0B24F4C452AF2D32

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19131_none_1c5c78fa9027c61e\rpcrt4.dll
    [2016-02-10 05:37][2016-01-16 10:37] 0665088 ____A (Microsoft Corporation) 276D90E7D7C85EBBE8FC422520C189CB

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19110_none_1c711888901874e5\rpcrt4.dll
    [2016-01-13 01:40][2015-12-30 10:41] 0665088 ____A (Microsoft Corporation) D92212049589535FBB25B806FF8A20C5

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19045_none_1c55a850902c4a44\rpcrt4.dll
    [2015-11-12 05:24][2015-10-19 16:44] 0665088 ____A (Microsoft Corporation) CFF504AD277328CE10BE56D76297FDAC

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19044_none_1c54a806902d30ed\rpcrt4.dll
    [2015-11-12 05:26][2015-10-17 09:46] 0665088 ____A (Microsoft Corporation) 6E5ED4A4F7FB0CF184355687856168EB

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19043_none_1c53a7bc902e1796\rpcrt4.dll
    [2015-11-12 05:26][2015-10-16 09:36] 0665088 ____A (Microsoft Corporation) B514E03BA08BF30AF910A62656196975

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19018_none_1c7918f290114276\rpcrt4.dll
    [2015-10-13 09:41][2015-09-28 18:57] 0665088 ____A (Microsoft Corporation) 2421C989BF8485B6A9EBBAC35ACADF1D

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18939_none_1c64a1429020606d\rpcrt4.dll
    [2015-09-08 12:38][2015-07-22 09:52] 0665088 ____A (Microsoft Corporation) 34026F26713F620CF9C4E62AE1F5738F

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18933_none_1c5e9f869025c863\rpcrt4.dll
    [2015-08-12 04:16][2015-07-15 09:53] 0665088 ____A (Microsoft Corporation) 37CE74C8094AD7D1D3B79A8D2849803E

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18923_none_1c696f72901dac72\rpcrt4.dll
    [2015-08-12 04:16][2015-07-14 18:54] 0665088 ____A (Microsoft Corporation) 14267AC74ADB60D42104B9C7015563FE

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18912_none_1c733f149016772a\rpcrt4.dll
    [2015-07-14 12:36][2015-07-01 12:29] 0665088 ____A (Microsoft Corporation) 02CD86D59807467D065F521BE81BB858

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18909_none_1c85110690080c9a\rpcrt4.dll
    [2015-07-14 12:36][2015-06-27 09:49] 0665088 ____A (Microsoft Corporation) CB773DEED66ECE1B9CFF826773BBF543

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18532_none_1c5d97a49026ba70\rpcrt4.dll
    [2014-09-26 23:15][2014-07-13 17:40] 0664064 ____A (Microsoft Corporation) D8BED6BA298DBAAF6F3D746739FCD333

    C:\Windows\winsxs\wow64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.17514_none_1c754ed890149b9b\rpcrt4.dll
    [2010-11-20 19:24][2010-11-20 19:24] 0663040 ____A (Microsoft Corporation) C5AD8083CF94201F1F8084ECC696A8B7

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23452_none_127ccfb174f3ef74\rpcrt4.dll
    [2016-06-15 05:51][2016-05-12 09:14] 1212928 ____A (Microsoft Corporation) 8D1DA6D15045AAFCC1D61D66B0F0E7E3

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23418_none_12ae111d74ce17ba\rpcrt4.dll
    [2016-05-11 05:53][2016-04-08 22:58] 1212928 ____A (Microsoft Corporation) 1A4B160C110AD3EC2E6534242A6CCA8C

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23392_none_12518e1b75146211\rpcrt4.dll
    [2016-04-12 22:02][2016-03-17 14:57] 1212928 ____A (Microsoft Corporation) 54D7B147EB4E7691AA5A2FA110A38363

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23391_none_12508dd1751548ba\rpcrt4.dll
    [2016-04-12 22:02][2016-03-16 10:52] 1212928 ____A (Microsoft Corporation) 1DA5F2E559C9E80B65985E4594961E3A

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23390_none_124f8d8775162f63\rpcrt4.dll
    [2016-04-12 22:02][2016-03-15 16:16] 1212928 ____A (Microsoft Corporation) 8DC5614DFF50344BEC41669CE6C6B9F8

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23349_none_128e9fbd74e587bd\rpcrt4.dll
    [2016-03-09 06:23][2016-02-10 10:54] 1212928 ____A (Microsoft Corporation) B939A69838F3F81DC61FF1C88A2472A2

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23338_none_12986f5f74de5275\rpcrt4.dll
    [2016-02-10 05:36][2016-01-21 22:28] 1213952 ____A (Microsoft Corporation) D38976E042267BE5916389B7B80453B9

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23334_none_12946e3774e1ed19\rpcrt4.dll
    [2016-02-10 05:37][2016-01-16 16:31] 1212928 ____A (Microsoft Corporation) 887509BAA9E8595B476C8A0296183B03

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23313_none_12a90dc574d29be0\rpcrt4.dll
    [2016-01-13 01:40][2015-12-30 11:12] 1212928 ____A (Microsoft Corporation) 443796670CF2A05B00FCD7C9BBB2EF91

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23250_none_127acb5174f5c278\rpcrt4.dll
    [2015-11-12 05:24][2015-10-19 17:11] 1216512 ____A (Microsoft Corporation) A73D710D9F0D02CABF0C74FFD5369970

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23249_none_128e9dd774e58a96\rpcrt4.dll
    [2015-11-12 05:26][2015-10-16 10:11] 1216512 ____A (Microsoft Corporation) 6C37388E5C04B6F7CBF207C66DAB4714

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23226_none_12a13cd174d806af\rpcrt4.dll
    [2015-10-13 09:40][2015-10-01 10:06] 1216512 ____A (Microsoft Corporation) 2EFCAF8BFF160004F63217C205A5F225

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23223_none_129e3bf374dabaaa\rpcrt4.dll
    [2015-10-13 09:41][2015-09-28 10:16] 1216512 ____A (Microsoft Corporation) 8973C0A6E2FD229B4423CD65D13AB022

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23153_none_127dca4974f31156\rpcrt4.dll
    [2015-09-08 23:55][2015-08-04 10:12] 1216512 ____A (Microsoft Corporation) 3A5530C095423CD44FE8CF04EC1C9D42

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23142_none_128799eb74ebdc0e\rpcrt4.dll
    [2015-09-08 12:38][2015-07-22 14:04] 1216512 ____A (Microsoft Corporation) F78FB76B1EA356477CA09670C168432E

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23136_none_12966aff74e02579\rpcrt4.dll
    [2015-08-12 04:16][2015-07-15 10:09] 1216512 ____A (Microsoft Corporation) 952E784B1DBB44F726E91115183223FB

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23126_none_12a13aeb74d80988\rpcrt4.dll
    [2015-08-12 04:16][2015-07-14 19:20] 1216512 ____A (Microsoft Corporation) A2C4E4A3748114B1A1AD63C1D4330C54

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23115_none_12ab0a8d74d0d440\rpcrt4.dll
    [2015-07-14 12:36][2015-07-01 10:20] 1216512 ____A (Microsoft Corporation) E15F5EC4ED0C1902BB26A6836CC15046

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.23112_none_12a809af74d3883b\rpcrt4.dll
    [2015-07-14 12:36][2015-06-27 10:12] 1216512 ____A (Microsoft Corporation) 08ED683B9417A514AC4F3742BB28C76D

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.22743_none_1288bc6174eacaae\rpcrt4.dll
    [2014-09-26 23:15][2014-07-13 17:52] 1215488 ____A (Microsoft Corporation) A8FEA8508378D5D7D979768E49B88EE6

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19160_none_11e65e9a5be03e9f\rpcrt4.dll
    [2016-03-09 06:23][2016-02-11 10:48] 1214464 ____A (Microsoft Corporation) 9A16001E1924D9EAAC3CA359A516EEE7

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19135_none_120bcfd05bc3697f\rpcrt4.dll
    [2016-02-10 05:36][2016-01-21 22:19] 1214464 ____A (Microsoft Corporation) C96D13751309F1099FF89347F0289789

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19131_none_1207cea85bc70423\rpcrt4.dll
    [2016-02-10 05:37][2016-01-16 11:01] 1214464 ____A (Microsoft Corporation) F774D22AC14AC154CF7335D25BE164AD

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19110_none_121c6e365bb7b2ea\rpcrt4.dll
    [2016-01-13 01:40][2015-12-30 11:01] 1214464 ____A (Microsoft Corporation) 1E22F3C99BB02A51179F9CCFEE242925

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19045_none_1200fdfe5bcb8849\rpcrt4.dll
    [2015-11-12 05:24][2015-10-19 17:05] 1216512 ____A (Microsoft Corporation) 1AE4881BAA7C3DE4D9EC8EA38A3F6BCC

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19044_none_11fffdb45bcc6ef2\rpcrt4.dll
    [2015-11-12 05:26][2015-10-17 10:09] 1216512 ____A (Microsoft Corporation) 14D2BFA76B5B486B1D3E057AC4C93E70

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19043_none_11fefd6a5bcd559b\rpcrt4.dll
    [2015-11-12 05:26][2015-10-16 10:04] 1216512 ____A (Microsoft Corporation) 47C9DAE61D284298495CF0735AF490CE

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.19018_none_12246ea05bb0807b\rpcrt4.dll
    [2015-10-13 09:41][2015-09-28 19:10] 1216512 ____A (Microsoft Corporation) 338FD40323ADD43B5C94B4A6CB91874B

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18939_none_120ff6f05bbf9e72\rpcrt4.dll
    [2015-09-08 12:38][2015-07-22 16:02] 1216512 ____A (Microsoft Corporation) 3375DC60062A5AA8245B035C4515B05E

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18933_none_1209f5345bc50668\rpcrt4.dll
    [2015-08-12 04:16][2015-07-15 10:10] 1216512 ____A (Microsoft Corporation) A0502BF52867F00FD9C67D1C355F6C91

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18923_none_1214c5205bbcea77\rpcrt4.dll
    [2015-08-12 04:16][2015-07-14 19:20] 1216512 ____A (Microsoft Corporation) 61153507FEE1C3DE9A68CFD090041A25

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18912_none_121e94c25bb5b52f\rpcrt4.dll
    [2015-07-14 12:36][2015-07-01 12:49] 1216512 ____A (Microsoft Corporation) A66FF313F2F8A6CBF9BB2B0CC92D5ACD

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18909_none_123066b45ba74a9f\rpcrt4.dll
    [2015-07-14 12:36][2015-06-27 10:03] 1216512 ____A (Microsoft Corporation) 65F0EFD62296DBC13813ACCE92E1F84D

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.18532_none_1208ed525bc5f875\rpcrt4.dll
    [2014-09-26 23:15][2014-07-13 18:02] 1216000 ____A (Microsoft Corporation) F947D57534E01E3CA597BCF2AD8AE65B

    C:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.17514_none_1220a4865bb3d9a0\rpcrt4.dll
    [2010-11-20 19:24][2010-11-20 19:24] 1219584 ____A (Microsoft Corporation) 0611473C1AD9E2D991CD9482068417F7

    C:\Windows\System32\rpcrt4.dll
    [2016-06-15 05:51][2016-05-12 09:14] 1212928 ____A (Microsoft Corporation) 8D1DA6D15045AAFCC1D61D66B0F0E7E3

    X:\Windows\winsxs\amd64_microsoft-windows-rpc-local_31bf3856ad364e35_6.1.7601.17514_none_1220a4865bb3d9a0\rpcrt4.dll
    [2010-11-20 01:25][2010-11-20 05:27] 1219584 ____A (Microsoft Corporation) 0611473C1AD9E2D991CD9482068417F7

    X:\Windows\System32\rpcrt4.dll
    [2010-11-20 01:25][2010-11-20 05:27] 1219584 ____A (Microsoft Corporation) 0611473C1AD9E2D991CD9482068417F7

    The first time I tried to fix it, I used the first listed version of each DLL and placed it in the appropriate folder using fixtext.... but its possible I did it incorrectly

    Any help would be INCREDIBLY useful, this is my work laptop and I know IT will just wipe the thing, so I'd love to be able to fix it myself.

    Thanks!
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Tags:
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1173625

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice