Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.09.2018 Ran by bill (administrator) on LT-HPZ-BNORRIS (30-09-2018 17:18:08) Running from C:\Users\bill.LT-HPZ-BNORRIS\Downloads Loaded Profiles: bill (Available Profiles: admin1 & bill) Platform: Windows 10 Pro Version 1803 17134.285 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64_skl_kit127358.inf_amd64_2b94ab23909d4e28\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe (Conexant Systems, Inc.) C:\Windows\CxSvc\CxUtilSvc.exe (Conexant Systems, Inc) C:\Windows\CxSvc\CxMonSvc.exe (Intel Corporation) C:\Windows\System32\ibtsiva.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe () C:\Windows\System32\fpCSEvtSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Broadcom Corporation) C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe (Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64_skl_kit127358.inf_amd64_2b94ab23909d4e28\IntelCpHDCPSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Crossmatch, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpCardEngine.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (HP) C:\Program Files (x86)\HP\Shared\hpqwmiex.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Conexant) C:\Windows\System32\MicTray64.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64_skl_kit127358.inf_amd64_2b94ab23909d4e28\igfxEM.exe (Crossmatch, Inc.) C:\Program Files (x86)\HP\HP ProtectTools Security Manager\Bin\DPAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (DigitalPersona, Inc.) C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpAgent.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.10311.0_x64__8wekyb3d8bbwe\Video.UI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Thunderbolt Software\Thunderbolt.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SmartAudio3.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.89.313.0_x86__zpdnekdrzrea0\Spotify.exe (LiveQoS Incorporated) C:\Program Files\HP\HP Velocity\SysTrayApp.exe (HP) C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe (Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.89.313.0_x86__zpdnekdrzrea0\Spotify.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\acrotray.exe (Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.89.313.0_x86__zpdnekdrzrea0\Spotify.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.89.313.0_x86__zpdnekdrzrea0\Spotify.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Akamai Technologies, Inc.) C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Akamai\netsession_win.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.2.8172.0_x86__8wekyb3d8bbwe\Solitaire.exe (Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation) HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [225248 2018-04-28] (Realtek Semiconductor Corp.) HKLM\...\Run: [DeliveryAndStatusCheck] => C:\Program Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe [301832 2015-11-10] (HP) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2670056 2018-09-10] (Adobe Systems, Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-04-08] (Apple Inc.) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322120 2017-06-26] (Intel Corporation) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM-x32\...\Run: [Discover HP Touchpoint Manager] => C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe [426208 2015-10-22] (HP) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\Acrotray.exe [1871344 2018-06-29] (Adobe Systems Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3753280 2018-09-25] (Dropbox, Inc.) HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [709416 2018-03-10] (Autodesk, Inc.) HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [324600 2017-04-25] (HP) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-12-03] (Intel Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\HP\HP ProtectTools Security Manager\Bin\DPAgent.exe, HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation) HKU\S-1-5-21-452880241-1879257384-3564544769-1003\...\Run: [Akamai NetSession Interface] => C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Akamai\netsession_win.exe [4490200 2017-09-08] (Akamai Technologies, Inc.) HKU\S-1-5-21-452880241-1879257384-3564544769-1003\...\Policies\Explorer: [] Lsa: [Notification Packages] DPPassFilter scecli Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Velocity.lnk [2017-02-09] ShortcutTarget: HP Velocity.lnk -> C:\Program Files\HP\HP Velocity\SysTrayApp.exe (LiveQoS Incorporated) CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{c04f8f53-c67b-4ee3-8872-18f33f6384ca}: [DhcpNameServer] 71.10.216.1 71.10.216.2 Tcpip\..\Interfaces\{ffc80b9f-37bd-410b-9486-3fb2aca71b12}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKU\S-1-5-21-452880241-1879257384-3564544769-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp SearchScopes: HKU\S-1-5-21-452880241-1879257384-3564544769-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-452880241-1879257384-3564544769-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-09-15] (Microsoft Corporation) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\x64\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\x64\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-09-10] (Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\x64\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2017\AcroIEFavStub.dll [2017-04-24] (Adobe Systems Incorporated) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-10] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-10] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-10] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-10] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: h1edqa6r.default FF ProfilePath: C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default [2018-09-30] FF Homepage: Mozilla\Firefox\Profiles\h1edqa6r.default -> hxxps://classifieds.gorge.net/ FF Extension: (Cisco Webex Extension) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\Extensions\ciscowebexstart1@cisco.com.xpi [2018-06-15] FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\Extensions\firefox@ghostery.com.xpi [2018-08-25] FF Extension: (uBlock Origin) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\Extensions\uBlock0@raymondhill.net.xpi [2018-09-24] FF Extension: (Quick Locale Switcher) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\Extensions\{25A1388B-6B18-46c3-BEBA-A81915D0DE8F}.xpi [2018-03-26] [Legacy] FF Extension: (Open With Microsoft Edge) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\Extensions\{b3366bd6-b352-4c2c-82df-2a8edb27178d}.xpi [2018-03-26] FF Extension: (Firefox Monitor) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\features\{5fbe5c4c-c610-4027-b85d-0bc393fa4c87}\fxmonitor@mozilla.org.xpi [2018-09-22] FF Extension: (Telemetry coverage) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Mozilla\Firefox\Profiles\h1edqa6r.default\features\{5fbe5c4c-c610-4027-b85d-0bc393fa4c87}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-09-22] [Legacy] FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-02-02] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - C:\Program Files (x86)\HP\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome => not found FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] () FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-09-10] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-09-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 2017\Acrobat\Air\nppdf32.dll [2018-06-29] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default [2018-09-27] CHR Extension: (Slides) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-04-02] CHR Extension: (Docs) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-02] CHR Extension: (Google Drive) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-02] CHR Extension: (YouTube) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-04-02] CHR Extension: (Adobe Acrobat) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-04-02] CHR Extension: (Sheets) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-04-02] CHR Extension: (Google Docs Offline) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-26] CHR Extension: (Chrome Web Store Payments) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-06-14] CHR Extension: (Gmail) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-04-02] CHR Extension: (Chrome Media Router) - C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-26] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1374072 2018-03-10] (Autodesk Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2910696 2018-09-10] (Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2704872 2018-09-10] (Adobe Systems, Incorporated) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-03-29] (Apple Inc.) R2 BrcmMgmtAgent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [215040 2014-08-13] (Broadcom Corporation) [File not signed] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9658664 2018-09-08] (Microsoft Corporation) R2 CxMonSvc; C:\WINDOWS\CxSvc\CxMonSvc.exe [34424 2017-06-22] (Conexant Systems, Inc) R2 CxUtilSvc; C:\WINDOWS\CxSvc\CxUtilSvc.exe [148600 2017-04-13] (Conexant Systems, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-03-19] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-03-19] (Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2018-09-25] (Dropbox, Inc.) R2 DpHost; C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe [529088 2017-11-08] (Crossmatch, Inc.) R2 fpCsEvtSvc; C:\WINDOWS\system32\fpCSEvtSvc.exe [13824 2015-04-28] () R3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1077568 2017-04-10] (HP) S3 hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [1102560 2015-10-19] (HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc.) R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-27] (HP Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18504 2017-06-26] (Intel Corporation) R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [541896 2018-05-15] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\SocketHeciServer.exe [743728 2017-11-16] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-07-06] (Intel Corporation) [File not signed] S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe [720184 2017-11-16] (Intel(R) Corporation) S3 Intel(R) WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-09-17] (Intel Corporation) S2 IntelAudioService; C:\WINDOWS\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe [216600 2018-05-04] (Intel) S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-07-06] () [File not signed] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [205968 2017-12-03] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265864 2018-03-19] () R2 NVWMI; C:\WINDOWS\system32\nvwmi64.exe [4445600 2018-05-25] (NVIDIA Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-14] (Microsoft Corporation) S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246872 2017-12-22] (Synaptics Incorporated) R3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2302696 2018-03-22] (Intel Corporation) R2 valWBFPolicyService; C:\WINDOWS\system32\valWBFPolicyService.exe [90976 2018-07-19] (Synaptics Incorporated) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-11] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [106904 2018-08-02] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3848328 2018-03-19] (Intel® Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [53752 2018-05-15] (HP) S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2018-03-06] (The OpenVPN Project) R3 CnxtHdAudService; C:\WINDOWS\system32\drivers\CHDRT64ISST.sys [2234328 2018-01-23] (Conexant Systems Inc.) R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [40960 2018-05-15] (HP) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [136728 2018-05-15] (Intel Corporation) R1 IPeakLWF; C:\WINDOWS\system32\DRIVERS\ipeaklwf.sys [398848 2015-12-09] (LiveQoS Incorporated) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [259360 2018-09-28] (Malwarebytes) R1 MpKsl4044a6a4; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C55B2E55-55EE-49EF-A22C-F5CA3C4180AD}\MpKsl4044a6a4.sys [58120 2018-09-29] (Microsoft Corporation) S3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7689728 2018-04-11] (Intel Corporation) R3 Netwtw06; C:\WINDOWS\system32\DRIVERS\Netwtw06.sys [8751600 2018-04-10] (Intel Corporation) R3 nhi; C:\WINDOWS\system32\DRIVERS\tbt100x.sys [137768 2018-03-26] (Intel Corporation) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvbl.inf_amd64_5d8c77eb01b0593c\nvlddmkm.sys [17538080 2018-05-25] (NVIDIA Corporation) S3 pmxdrv; C:\WINDOWS\system32\drivers\pmxdrv.sys [31152 2018-08-17] () R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [864704 2017-10-19] (Realsil Semiconductor Corporation) S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-27] (Realsil Semiconductor Corporation) R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3236320 2018-04-28] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [42088 2016-03-21] (Synaptics Incorporated) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42584 2017-12-22] (Synaptics Incorporated) R3 usbaud; C:\WINDOWS\system32\DRIVERS\usbaud64.sys [81400 2017-11-16] (Conexant Systems, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44616 2018-04-11] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [331680 2018-04-11] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-11] (Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP) R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-09-30 17:18 - 2018-09-30 17:18 - 000029087 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\FRST.txt 2018-09-30 17:17 - 2018-09-30 17:18 - 000000000 ____D C:\FRST 2018-09-30 17:16 - 2018-09-30 17:16 - 002414080 _____ (Farbar) C:\Users\bill.LT-HPZ-BNORRIS\Downloads\FRST64.exe 2018-09-30 17:11 - 2018-09-30 17:11 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\mbam 2018-09-26 17:46 - 2018-09-26 17:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2018-09-25 04:52 - 2018-09-25 04:52 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2018-09-25 04:52 - 2018-09-25 04:52 - 000050232 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2018-09-25 04:52 - 2018-09-25 04:52 - 000050232 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2018-09-25 04:52 - 2018-09-25 04:52 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2018-09-15 19:38 - 2018-09-15 19:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2018-09-15 12:18 - 2018-09-15 12:18 - 000014805 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\Example-Oral-Abstract-3.pdf 2018-09-15 12:17 - 2018-09-15 12:17 - 000045707 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\Example-Oral-Abstract-1.pdf 2018-09-15 12:17 - 2018-09-15 12:17 - 000016847 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\Example-Poster-Abstract-2.pdf 2018-09-15 12:17 - 2018-09-15 12:17 - 000015360 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\Example-Poster-Abstract-1.pdf 2018-09-15 12:17 - 2018-09-15 12:17 - 000014447 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\Example-Oral-Abstract-2.pdf 2018-09-15 11:27 - 2018-09-15 11:27 - 000175832 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\RRNW-2019-CALL_Presentations.pdf 2018-09-14 10:53 - 2018-08-30 20:44 - 001222440 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2018-09-14 10:53 - 2018-08-30 20:42 - 009090016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2018-09-14 10:53 - 2018-08-30 20:42 - 007520064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2018-09-14 10:53 - 2018-08-30 20:42 - 007436192 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2018-09-14 10:53 - 2018-08-30 20:28 - 006570040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2018-09-14 10:53 - 2018-08-30 20:28 - 006043680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2018-09-14 10:53 - 2018-08-30 20:26 - 025847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2018-09-14 10:53 - 2018-08-30 20:21 - 022008320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2018-09-14 10:53 - 2018-08-30 20:20 - 022715904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2018-09-14 10:53 - 2018-08-30 20:18 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2018-09-14 10:53 - 2018-08-30 20:16 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2018-09-14 10:53 - 2018-08-30 20:16 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2018-09-14 10:53 - 2018-08-30 20:16 - 004382720 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2018-09-14 10:53 - 2018-08-30 20:15 - 007577088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2018-09-14 10:53 - 2018-08-30 20:15 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2018-09-14 10:53 - 2018-08-30 20:15 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2018-09-14 10:53 - 2018-08-30 20:13 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2018-09-14 10:53 - 2018-08-30 20:10 - 005777920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2018-09-14 10:53 - 2018-08-30 20:10 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2018-09-14 10:53 - 2018-08-28 00:17 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2018-09-14 10:53 - 2018-08-09 02:37 - 002267944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll 2018-09-14 10:53 - 2018-08-09 02:32 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2018-09-14 10:53 - 2018-08-09 02:31 - 001617728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2018-09-14 10:53 - 2018-08-09 02:14 - 012709376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2018-09-14 10:53 - 2018-08-09 02:11 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2018-09-14 10:53 - 2018-08-09 01:38 - 001538976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll 2018-09-14 10:53 - 2018-08-09 01:24 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2018-09-14 10:53 - 2018-08-08 22:02 - 001035144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2018-09-14 10:53 - 2018-08-08 21:53 - 002765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2018-09-14 10:53 - 2018-08-08 21:29 - 002253584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2018-09-14 10:53 - 2018-08-08 21:28 - 003395072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2018-09-14 10:53 - 2018-08-08 21:24 - 002368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2018-09-14 10:53 - 2018-08-08 21:23 - 003148288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2018-09-14 10:53 - 2018-08-08 21:22 - 004615680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2018-09-14 10:53 - 2018-08-08 21:09 - 004191232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2018-09-14 10:53 - 2018-08-03 01:39 - 021389368 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2018-09-14 10:53 - 2018-08-03 01:20 - 004049408 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2018-09-14 10:53 - 2018-08-03 00:43 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2018-09-14 10:53 - 2018-08-03 00:27 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2018-09-14 10:53 - 2018-08-02 20:09 - 001932288 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll 2018-09-14 10:53 - 2018-08-02 20:09 - 001395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2018-09-14 10:53 - 2018-08-02 20:09 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2018-09-14 10:53 - 2018-08-02 20:06 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2018-09-14 10:52 - 2018-08-31 00:46 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2018-09-14 10:52 - 2018-08-31 00:45 - 000348328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2018-09-14 10:52 - 2018-08-31 00:43 - 001524152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2018-09-14 10:52 - 2018-08-31 00:42 - 001636232 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2018-09-14 10:52 - 2018-08-31 00:27 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2018-09-14 10:52 - 2018-08-31 00:27 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2018-09-14 10:52 - 2018-08-31 00:26 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys 2018-09-14 10:52 - 2018-08-31 00:25 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll 2018-09-14 10:52 - 2018-08-31 00:25 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe 2018-09-14 10:52 - 2018-08-31 00:24 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll 2018-09-14 10:52 - 2018-08-31 00:24 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll 2018-09-14 10:52 - 2018-08-31 00:24 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2018-09-14 10:52 - 2018-08-31 00:23 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2018-09-14 10:52 - 2018-08-31 00:23 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2018-09-14 10:52 - 2018-08-31 00:22 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2018-09-14 10:52 - 2018-08-31 00:22 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2018-09-14 10:52 - 2018-08-30 23:55 - 001455960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2018-09-14 10:52 - 2018-08-30 23:53 - 001327504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2018-09-14 10:52 - 2018-08-30 23:41 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2018-09-14 10:52 - 2018-08-30 23:41 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2018-09-14 10:52 - 2018-08-30 23:40 - 000216576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll 2018-09-14 10:52 - 2018-08-30 23:37 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2018-09-14 10:52 - 2018-08-30 23:37 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2018-09-14 10:52 - 2018-08-30 23:37 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2018-09-14 10:52 - 2018-08-30 23:36 - 001469952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2018-09-14 10:52 - 2018-08-30 20:50 - 000273720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll 2018-09-14 10:52 - 2018-08-30 20:50 - 000270648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2018-09-14 10:52 - 2018-08-30 20:44 - 001064744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2018-09-14 10:52 - 2018-08-30 20:44 - 001030952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2018-09-14 10:52 - 2018-08-30 20:44 - 000568600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2018-09-14 10:52 - 2018-08-30 20:44 - 000136488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2018-09-14 10:52 - 2018-08-30 20:44 - 000076256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2018-09-14 10:52 - 2018-08-30 20:43 - 002719216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2018-09-14 10:52 - 2018-08-30 20:43 - 000722880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 002824672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2018-09-14 10:52 - 2018-08-30 20:42 - 002461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 001767064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 001458552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2018-09-14 10:52 - 2018-08-30 20:42 - 001258352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2018-09-14 10:52 - 2018-08-30 20:42 - 001142000 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2018-09-14 10:52 - 2018-08-30 20:42 - 001097720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 000983080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2018-09-14 10:52 - 2018-08-30 20:42 - 000885928 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 000632296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpx.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 000604640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2018-09-14 10:52 - 2018-08-30 20:42 - 000527328 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 000494472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll 2018-09-14 10:52 - 2018-08-30 20:42 - 000155112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 001989496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 001514352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 001129728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 000568568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 000453104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpx.dll 2018-09-14 10:52 - 2018-08-30 20:28 - 000134936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2018-09-14 10:52 - 2018-08-30 20:17 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2018-09-14 10:52 - 2018-08-30 20:17 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\netevent.dll 2018-09-14 10:52 - 2018-08-30 20:15 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2018-09-14 10:52 - 2018-08-30 20:15 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2018-09-14 10:52 - 2018-08-30 20:15 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys 2018-09-14 10:52 - 2018-08-30 20:14 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2018-09-14 10:52 - 2018-08-30 20:14 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2018-09-14 10:52 - 2018-08-30 20:14 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2018-09-14 10:52 - 2018-08-30 20:14 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2018-09-14 10:52 - 2018-08-30 20:14 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2018-09-14 10:52 - 2018-08-30 20:13 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll 2018-09-14 10:52 - 2018-08-30 20:13 - 000402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 2018-09-14 10:52 - 2018-08-30 20:12 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2018-09-14 10:52 - 2018-08-30 20:12 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netevent.dll 2018-09-14 10:52 - 2018-08-30 20:11 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2018-09-14 10:52 - 2018-08-30 20:11 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2018-09-14 10:52 - 2018-08-30 20:11 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2018-09-14 10:52 - 2018-08-30 20:11 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2018-09-14 10:52 - 2018-08-30 20:11 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2018-09-14 10:52 - 2018-08-30 20:11 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2018-09-14 10:52 - 2018-08-30 20:11 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2018-09-14 10:52 - 2018-08-30 20:10 - 001375744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2018-09-14 10:52 - 2018-08-30 20:10 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2018-09-14 10:52 - 2018-08-30 20:09 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2018-09-14 10:52 - 2018-08-30 20:09 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2018-09-14 10:52 - 2018-08-30 20:08 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2018-09-14 10:52 - 2018-08-30 20:07 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2018-09-14 10:52 - 2018-08-30 20:07 - 000856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2018-09-14 10:52 - 2018-08-30 20:07 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2018-09-14 10:52 - 2018-08-30 20:06 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2018-09-14 10:52 - 2018-08-30 18:57 - 000001308 _____ C:\WINDOWS\system32\tcbres.wim 2018-09-14 10:52 - 2018-08-27 23:56 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll 2018-09-14 10:52 - 2018-08-27 23:49 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll 2018-09-14 10:52 - 2018-08-27 23:48 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll 2018-09-14 10:52 - 2018-08-27 23:45 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll 2018-09-14 10:52 - 2018-08-27 22:51 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll 2018-09-14 10:52 - 2018-08-13 19:14 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2018-09-14 10:52 - 2018-08-13 19:14 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2018-09-14 10:52 - 2018-08-09 02:31 - 000766872 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll 2018-09-14 10:52 - 2018-08-09 02:31 - 000253544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2018-09-14 10:52 - 2018-08-09 02:31 - 000236624 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2018-09-14 10:52 - 2018-08-09 02:17 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2018-09-14 10:52 - 2018-08-09 02:14 - 000466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll 2018-09-14 10:52 - 2018-08-09 02:14 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollUI.dll 2018-09-14 10:52 - 2018-08-09 02:14 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdeploy.dll 2018-09-14 10:52 - 2018-08-09 02:13 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2018-09-14 10:52 - 2018-08-09 02:13 - 000517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe 2018-09-14 10:52 - 2018-08-09 02:13 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll 2018-09-14 10:52 - 2018-08-09 02:13 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsExt.dll 2018-09-14 10:52 - 2018-08-09 02:12 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2018-09-14 10:52 - 2018-08-09 02:12 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2018-09-14 10:52 - 2018-08-09 02:12 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2018-09-14 10:52 - 2018-08-09 02:11 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2018-09-14 10:52 - 2018-08-09 02:11 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2018-09-14 10:52 - 2018-08-09 02:11 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2018-09-14 10:52 - 2018-08-09 02:11 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2018-09-14 10:52 - 2018-08-09 02:10 - 001557504 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe 2018-09-14 10:52 - 2018-08-09 02:10 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2018-09-14 10:52 - 2018-08-09 02:10 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2018-09-14 10:52 - 2018-08-09 02:09 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll 2018-09-14 10:52 - 2018-08-09 02:09 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll 2018-09-14 10:52 - 2018-08-09 02:09 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2018-09-14 10:52 - 2018-08-09 02:09 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageInspector.exe 2018-09-14 10:52 - 2018-08-09 01:36 - 000660896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll 2018-09-14 10:52 - 2018-08-09 01:36 - 000221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll 2018-09-14 10:52 - 2018-08-09 01:24 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdeploy.dll 2018-09-14 10:52 - 2018-08-09 01:23 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2018-09-14 10:52 - 2018-08-09 01:23 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollUI.dll 2018-09-14 10:52 - 2018-08-09 01:22 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2018-09-14 10:52 - 2018-08-09 01:22 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2018-09-14 10:52 - 2018-08-09 01:22 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2018-09-14 10:52 - 2018-08-09 01:22 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe 2018-09-14 10:52 - 2018-08-09 01:21 - 002894848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2018-09-14 10:52 - 2018-08-09 01:21 - 002016768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2018-09-14 10:52 - 2018-08-09 01:21 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe 2018-09-14 10:52 - 2018-08-09 01:21 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2018-09-14 10:52 - 2018-08-09 01:20 - 002401792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll 2018-09-14 10:52 - 2018-08-09 01:20 - 000423424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2018-09-14 10:52 - 2018-08-09 01:20 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll 2018-09-14 10:52 - 2018-08-09 01:20 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll 2018-09-14 10:52 - 2018-08-09 01:19 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe 2018-09-14 10:52 - 2018-08-08 22:01 - 000777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2018-09-14 10:52 - 2018-08-08 21:55 - 000230304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2018-09-14 10:52 - 2018-08-08 21:54 - 001019016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2018-09-14 10:52 - 2018-08-08 21:54 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2018-09-14 10:52 - 2018-08-08 21:54 - 000375704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2018-09-14 10:52 - 2018-08-08 21:54 - 000203568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll 2018-09-14 10:52 - 2018-08-08 21:54 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2018-09-14 10:52 - 2018-08-08 21:53 - 001947720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2018-09-14 10:52 - 2018-08-08 21:53 - 001026456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2018-09-14 10:52 - 2018-08-08 21:53 - 000932136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2018-09-14 10:52 - 2018-08-08 21:53 - 000714792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2018-09-14 10:52 - 2018-08-08 21:53 - 000482480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll 2018-09-14 10:52 - 2018-08-08 21:53 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll 2018-09-14 10:52 - 2018-08-08 21:53 - 000125600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptxml.dll 2018-09-14 10:52 - 2018-08-08 21:30 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2018-09-14 10:52 - 2018-08-08 21:30 - 000183992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll 2018-09-14 10:52 - 2018-08-08 21:29 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2018-09-14 10:52 - 2018-08-08 21:29 - 001174552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2018-09-14 10:52 - 2018-08-08 21:29 - 000581696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll 2018-09-14 10:52 - 2018-08-08 21:29 - 000099208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptxml.dll 2018-09-14 10:52 - 2018-08-08 21:28 - 001589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2018-09-14 10:52 - 2018-08-08 21:27 - 000428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2018-09-14 10:52 - 2018-08-08 21:27 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll 2018-09-14 10:52 - 2018-08-08 21:27 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe 2018-09-14 10:52 - 2018-08-08 21:26 - 000990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2018-09-14 10:52 - 2018-08-08 21:26 - 000572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll 2018-09-14 10:52 - 2018-08-08 21:26 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2018-09-14 10:52 - 2018-08-08 21:26 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2018-09-14 10:52 - 2018-08-08 21:26 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsAuth.dll 2018-09-14 10:52 - 2018-08-08 21:26 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsCfg.dll 2018-09-14 10:52 - 2018-08-08 21:26 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000797184 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2018-09-14 10:52 - 2018-08-08 21:25 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2018-09-14 10:52 - 2018-08-08 21:24 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2018-09-14 10:52 - 2018-08-08 21:23 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2018-09-14 10:52 - 2018-08-08 21:23 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2018-09-14 10:52 - 2018-08-08 21:23 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2018-09-14 10:52 - 2018-08-08 21:22 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2018-09-14 10:52 - 2018-08-08 21:22 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2018-09-14 10:52 - 2018-08-08 21:22 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2018-09-14 10:52 - 2018-08-08 21:21 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2018-09-14 10:52 - 2018-08-08 21:13 - 001189376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2018-09-14 10:52 - 2018-08-08 21:13 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe 2018-09-14 10:52 - 2018-08-08 21:12 - 000652288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsAuth.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsCfg.dll 2018-09-14 10:52 - 2018-08-08 21:11 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2018-09-14 10:52 - 2018-08-08 21:10 - 002893824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2018-09-14 10:52 - 2018-08-08 21:10 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2018-09-14 10:52 - 2018-08-08 21:10 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2018-09-14 10:52 - 2018-08-08 21:09 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2018-09-14 10:52 - 2018-08-08 21:08 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2018-09-14 10:52 - 2018-08-08 20:08 - 000806416 _____ C:\WINDOWS\SysWOW64\locale.nls 2018-09-14 10:52 - 2018-08-08 20:08 - 000806416 _____ C:\WINDOWS\system32\locale.nls 2018-09-14 10:52 - 2018-08-03 01:39 - 000790304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2018-09-14 10:52 - 2018-08-03 01:25 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2018-09-14 10:52 - 2018-08-03 01:24 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll 2018-09-14 10:52 - 2018-08-03 01:24 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2018-09-14 10:52 - 2018-08-03 01:24 - 000046592 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2018-09-14 10:52 - 2018-08-03 01:21 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys 2018-09-14 10:52 - 2018-08-03 00:45 - 000663128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2018-09-14 10:52 - 2018-08-03 00:33 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2018-09-14 10:52 - 2018-08-03 00:32 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2018-09-14 10:52 - 2018-08-03 00:30 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll 2018-09-14 10:52 - 2018-08-02 20:47 - 000128920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys 2018-09-14 10:52 - 2018-08-02 20:41 - 000061736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvhostsvc.dll 2018-09-14 10:52 - 2018-08-02 20:40 - 000566568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2018-09-14 10:52 - 2018-08-02 20:40 - 000228136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys 2018-09-14 10:52 - 2018-08-02 20:40 - 000072800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2018-09-14 10:52 - 2018-08-02 20:39 - 000692240 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2018-09-14 10:52 - 2018-08-02 20:39 - 000114080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys 2018-09-14 10:52 - 2018-08-02 20:39 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys 2018-09-14 10:52 - 2018-08-02 20:39 - 000031648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhv.sys 2018-09-14 10:52 - 2018-08-02 20:38 - 001285536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2018-09-14 10:52 - 2018-08-02 20:38 - 000115640 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll 2018-09-14 10:52 - 2018-08-02 20:27 - 000061032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2018-09-14 10:52 - 2018-08-02 20:25 - 000539168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2018-09-14 10:52 - 2018-08-02 20:17 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmgid.sys 2018-09-14 10:52 - 2018-08-02 20:16 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll 2018-09-14 10:52 - 2018-08-02 20:15 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys 2018-09-14 10:52 - 2018-08-02 20:14 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2018-09-14 10:52 - 2018-08-02 20:14 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSAssessment.dll 2018-09-14 10:52 - 2018-08-02 20:12 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2018-09-14 10:52 - 2018-08-02 20:12 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys 2018-09-14 10:52 - 2018-08-02 20:11 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2018-09-14 10:52 - 2018-08-02 20:10 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll 2018-09-14 10:52 - 2018-08-02 20:08 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2018-09-14 10:52 - 2018-08-02 20:08 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2018-09-14 10:52 - 2018-08-02 20:08 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2018-09-14 10:52 - 2018-08-02 20:06 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2018-09-14 10:52 - 2018-08-02 20:05 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2018-09-14 10:52 - 2018-08-02 20:05 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2018-09-10 09:10 - 2018-09-10 09:14 - 000010584 _____ C:\Users\bill.LT-HPZ-BNORRIS\Desktop\September 2018 Food and Lodging.xlsx 2018-09-10 08:30 - 2018-09-10 08:31 - 000642428 _____ C:\Users\bill.LT-HPZ-BNORRIS\Downloads\fleet-107-ii_3.pdf 2018-09-10 08:21 - 2018-09-15 19:38 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2018-09-10 08:21 - 2018-09-10 08:21 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive 2018-09-09 07:53 - 2018-09-28 13:34 - 000259360 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2018-09-08 06:02 - 2018-09-08 06:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Suite Sync ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-09-30 17:16 - 2018-04-11 16:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2018-09-30 15:46 - 2018-04-11 16:38 - 000000000 ___HD C:\Program Files\WindowsApps 2018-09-30 15:46 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2018-09-30 15:45 - 2018-06-13 09:42 - 000004162 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2AA514D0-1766-46B6-AE4D-1C9B94A7AD2B} 2018-09-30 15:42 - 2018-03-29 13:39 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Akamai 2018-09-30 15:41 - 2018-03-26 14:05 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\LocalLow\Mozilla 2018-09-29 12:05 - 2017-05-18 14:35 - 000000000 ____D C:\ProgramData\NVIDIA 2018-09-29 12:01 - 2018-04-02 11:24 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\Documents\Outlook Files 2018-09-29 10:34 - 2018-08-29 10:21 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\QuickBooks 2018-09-29 10:28 - 2018-06-13 09:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-09-29 09:31 - 2018-03-27 10:37 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\Documents\Outlook_Backups 2018-09-29 08:20 - 2018-06-13 09:35 - 000934208 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2018-09-29 08:20 - 2018-04-11 16:36 - 000000000 ____D C:\WINDOWS\INF 2018-09-29 08:16 - 2017-05-18 14:36 - 000000000 ____D C:\ProgramData\Synaptics 2018-09-28 13:35 - 2018-06-13 09:36 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS 2018-09-28 13:34 - 2018-06-13 09:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-09-28 07:49 - 2017-10-20 00:52 - 000000358 _____ C:\WINDOWS\Tasks\HPCeeScheduleForbill.job 2018-09-28 07:48 - 2018-04-11 14:04 - 001310720 _____ C:\WINDOWS\system32\config\BBI 2018-09-28 05:41 - 2018-06-13 09:42 - 000003246 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForbill 2018-09-26 17:46 - 2018-03-19 16:45 - 000000000 ____D C:\Program Files (x86)\Dropbox 2018-09-26 07:45 - 2018-03-26 10:23 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Google 2018-09-25 17:17 - 2018-03-26 10:23 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Packages 2018-09-25 16:06 - 2017-11-17 12:22 - 000000000 ____D C:\ProgramData\boost_interprocess 2018-09-23 20:02 - 2018-06-13 09:42 - 000003372 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-452880241-1879257384-3564544769-1003 2018-09-23 20:02 - 2018-06-13 09:36 - 000002412 _____ C:\Users\bill.LT-HPZ-BNORRIS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-09-23 20:02 - 2018-03-26 10:24 - 000000000 ___RD C:\Users\bill.LT-HPZ-BNORRIS\OneDrive 2018-09-23 09:02 - 2017-11-16 17:20 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-09-23 09:02 - 2017-11-16 17:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-09-22 19:45 - 2017-11-16 17:20 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-09-22 05:39 - 2018-03-19 16:45 - 000000912 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2018-09-22 05:39 - 2018-03-19 16:45 - 000000908 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 2018-09-21 13:49 - 2018-06-13 09:42 - 000003972 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA 2018-09-21 13:49 - 2018-06-13 09:42 - 000003740 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore 2018-09-20 09:52 - 2018-03-27 10:36 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\Documents\Fish Passage 2018-09-20 09:13 - 2018-06-13 09:42 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2018-09-20 09:13 - 2018-03-30 09:32 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2018-09-20 07:36 - 2017-10-16 15:27 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 2017.lnk 2018-09-20 07:36 - 2017-10-16 15:27 - 000002131 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller 2017.lnk 2018-09-20 07:33 - 2017-10-16 15:21 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-09-19 08:14 - 2018-06-13 09:42 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update 2018-09-15 19:38 - 2017-10-16 08:48 - 000002505 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002499 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002462 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk 2018-09-15 19:38 - 2017-10-16 08:48 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk 2018-09-15 19:37 - 2017-02-09 05:01 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2018-09-15 19:06 - 2018-03-27 10:55 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\Documents\Presentations 2018-09-14 11:57 - 2018-03-27 10:56 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\Documents\Tech 2018-09-14 10:57 - 2018-06-13 09:42 - 000000000 ___RD C:\Users\bill.LT-HPZ-BNORRIS\3D Objects 2018-09-14 10:57 - 2016-11-20 11:54 - 000000000 __RHD C:\Users\Public\AccountPictures 2018-09-14 10:56 - 2018-06-13 09:28 - 000608376 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ___SD C:\WINDOWS\system32\F12 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ___RD C:\Program Files\Windows Defender 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\TextInput 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\system32\oobe 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\ShellExperiences 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\bcastdvr 2018-09-14 10:56 - 2018-04-11 16:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2018-09-14 10:56 - 2018-04-11 14:04 - 000000000 ____D C:\WINDOWS\system32\Dism 2018-09-14 10:54 - 2018-04-11 16:30 - 000000000 ____D C:\WINDOWS\CbsTemp 2018-09-14 10:52 - 2017-05-18 14:36 - 000000000 ____D C:\WINDOWS\system32\Intel 2018-09-11 12:28 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2018-09-11 06:48 - 2018-03-26 10:23 - 000000000 ____D C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\Adobe 2018-09-11 06:46 - 2018-06-13 09:42 - 000004584 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier 2018-09-11 06:46 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2018-09-11 06:46 - 2018-04-11 16:38 - 000000000 ____D C:\WINDOWS\system32\Macromed 2018-09-10 08:21 - 2018-04-11 16:34 - 000002234 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-09-10 08:21 - 2018-04-11 16:34 - 000002234 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-09-09 07:53 - 2018-06-15 08:38 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys ==================== Files in the root of some directories ======= 2018-09-25 11:23 - 2018-09-25 11:23 - 000000000 _____ () C:\Users\bill.LT-HPZ-BNORRIS\AppData\Local\oobelibMkey.log Some files in TEMP: ==================== 2018-03-26 09:50 - 2015-01-26 09:34 - 000015752 _____ (Autodesk, Inc.) C:\Users\administrator\AppData\Local\Temp\AcDeltree.exe 2018-03-26 09:48 - 2018-03-26 09:58 - 002398688 _____ (Flexera Software LLC) C:\Users\administrator\AppData\Local\Temp\FNP_ACT_InstallerCA.dll 2017-12-28 13:57 - 2017-01-18 04:50 - 000066472 _____ (Autodesk, Inc.) C:\Users\bill\AppData\Local\Temp\AcDeltree.exe 2018-01-11 09:37 - 2018-01-03 12:43 - 021070224 _____ (Spotify Ltd) C:\Users\bill\AppData\Local\Temp\SpotifyUninstall.exe 2017-11-16 16:24 - 2017-10-17 15:01 - 000927784 _____ () C:\Users\bill\AppData\Local\Temp\TAInstaller.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-06-13 09:28 ==================== End of FRST.txt ============================