Zoek.exe v5.0.0.0 Updated 06-December-2014 Tool run by Tjorven on zo 07/12/2014 at 15:29:10,70. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Tjorven\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 7/12/2014 15:33:15 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Users\Tjorven\AppData\Roaming\337Games deleted successfully C:\Users\Tjorven\AppData\Roaming\hpqlog deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe C:\Program Files (x86)\STab\ProtectService.exe C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe C:\Program Files (x86)\LuckyTab\LuckyTab.exe C:\Program Files (x86)\STab\cmdshell.exe C:\Program Files (x86)\STab\HPNotify.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppService.exe C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppService.exe C:\Windows\syswow64\wwahost.exe C:\Program Files (x86)\Box Rock\bin\utilBoxRock.exe C:\Program Files (x86)\Box Rock\updateBoxRock.exe C:\Users\Tjorven\Downloads\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Program Files (x86)\Box Rock\bin\BoxRock.expext.exe C:\Program Files (x86)\Box Rock\bin\BoxRock.BOASHelper.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update Box Rock deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update Box Rock deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util Box Rock deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util Box Rock deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsMangerProtect deleted successfully ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] @="C:\\Program Files\\Internet Explorer\\iexplore.exe" ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Pokki"=- ==== Deleting Files \ Folders ====================== C:\Users\Tjorven\AppData\Roaming\337Games not found C:\ProgramData\WindowsMangerProtect deleted C:\Program Files\Enigma Software Group deleted C:\Users\Tjorven\AppData\Roaming\VOPackage deleted C:\ProgramData\IHProtectUpDate deleted C:\Users\Tjorven\AppData\Roaming\webssearches deleted C:\Program Files (x86)\YourFileDownloader deleted C:\Users\Public\Pokki deleted C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader deleted C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk deleted C:\PROGRA~3\Package Cache deleted C:\Users\Default\AppData\Local\Pokki deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk deleted C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage deleted C:\windows\SysNative\tasks\LuckyTab deleted C:\windows\SysNative\drivers\{16059ec5-52e8-4756-b01c-cdf3d1058db7}Gw64.sys deleted C:\windows\SysNative\drivers\{18b49811-f378-4f92-bc18-136e95d50889}Gw64.sys deleted C:\windows\SysNative\GroupPolicy\machine deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCall.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla2.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla21.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla31.exe" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla32.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla33.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla34.dll" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseCustomCalla37.exe" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP\WiseData.ini" deleted "C:\Program Files (x86)\Box Rock\updateBoxRock.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\analytics.db" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\engine_update.db" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\notifications.db" deleted "C:\Program Files (x86)\STab\BrowserAction.dll" deleted "C:\Program Files (x86)\STab\CmdShell.exe" deleted "C:\Program Files (x86)\STab\HPNotify.exe" deleted "C:\Program Files (x86)\STab\IeWatchDog.dll" deleted "C:\Program Files (x86)\STab\msvcp110.dll" deleted "C:\Program Files (x86)\STab\msvcr110.dll" not deleted "C:\Program Files (x86)\STab\ProtectService.exe" deleted "C:\PROGRA~2\YourFileDownloaderUpdater\htmlayout.dll" deleted "C:\PROGRA~2\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe" deleted "C:\PROGRA~2\LuckyTab\LuckyTab.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\analytics.db" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\engine_update.db" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\notifications.db" deleted "C:\PROGRA~2\Box Rock\updateBoxRock.exe" deleted "C:\Program Files (x86)\Box Rock\bin\BoxRock.BOASHelper.exe" deleted "C:\Program Files (x86)\Box Rock\bin\BoxRock.expext.exe" deleted "C:\Program Files (x86)\Box Rock\bin\BoxRock.expextdll.dll" deleted "C:\Program Files (x86)\Box Rock\bin\BoxRock.PurBrowse64.exe" deleted "C:\Program Files (x86)\Box Rock\bin\utilBoxRock.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppService.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\StartMenuIndexer.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Pokkies\installed_pokkies.db" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\000009.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000008" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppService.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine\StartMenuIndexer.exe" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Pokkies\installed_pokkies.db" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\000009.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000008" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000012" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000013.log" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000012" deleted "C:\PROGRA~2\Box Rock\bin\BoxRock.BOASHelper.exe" deleted "C:\PROGRA~2\Box Rock\bin\BoxRock.expext.exe" deleted "C:\PROGRA~2\Box Rock\bin\BoxRock.expextdll.dll" deleted "C:\PROGRA~2\Box Rock\bin\BoxRock.PurBrowse64.exe" deleted "C:\PROGRA~2\Box Rock\bin\utilBoxRock.exe" deleted "C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP" deleted "C:\Program Files (x86)\Box Rock" not deleted "C:\Users\Tjorven\AppData\Local\Pokki" not deleted "C:\Program Files (x86)\STab" not deleted "C:\PROGRA~2\YourFileDownloaderUpdater" not deleted "C:\PROGRA~2\LuckyTab" deleted "C:\Users\Tjorven\AppData\Local\Pokki" not deleted "C:\PROGRA~2\Box Rock" not deleted "C:\Program Files (x86)\Box Rock\bin" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\Pokkies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\Engine" not deleted "C:\Users\Tjorven\AppData\Local\Pokki\Pokkies" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\34e8f5c0c9e5744bf2cdb514283762dd0524776b-websheet\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Tjorven\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted "C:\PROGRA~2\Box Rock\bin" not deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8123 MB CPU Info: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz CPU Speed: 2422,7 MHz Sound Card: luidspreker/Hoofdtelefoon (Real | Display Adapters: Intel(R) HD Graphics Family | Intel(R) HD Graphics Family | Intel(R) HD Graphics Family Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1600 X 900 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Bluetooth-apparaat (Personal Area Network) | Broadcom BCM43142 802.11 bgn Wi-Fi Adapter | Realtek PCIe FE Family Controller CD / DVD Drives: 1x (E: | ) E: hp DVDRAM GU90N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 444,3GB | D: 20,4GB Hard Disks - Free: C: 400,5GB | D: 2,1GB Manufacturer *: Insyde BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1 Time Zone: Romance (standaardtijd) Motherboard *: Hewlett-Packard 227F Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: McAfee Antivirus en antispyware On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: McAfee Antivirus en antispyware disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Firewall: McAfee Firewall disabled Internet Explorer Version: 11.0.9600.17416 Shockwave Player version: 12.0.4r144 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-12-03 17:29:40 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\Windows\explorer.exe ====== C:\Users\Tjorven\AppData\Local\Temp ==== 2014-12-05 23:10:14 D4A2A59FABF967B23F746445D3A57205 84041160 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\oct2A1A.tmp.exe 2014-12-05 20:02:07 5973A242277FB7B19D46BB73178246FC 47329360 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\SHSetup.exe 2014-12-05 19:26:35 4B0666FD4A8B70889D81CBF3693A47F3 304848 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_64.exe 2014-12-05 19:26:18 821C4D8963A02B55569ECD8B22406577 298496 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\sdf2F4E.exe 2014-12-05 19:26:17 859B2571598147FC05A25A3F9AEA378E 212520 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\F2iNEfHEJL.exe 2014-12-05 19:26:12 28F987C71E90CE932F69F341F8809E1F 583376 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\ivX8lVqmUU.exe 2014-12-05 19:26:06 6DC70518A987E7615E3C673B7FEEE68E 309872 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\QESQjr7cip.exe 2014-11-26 19:13:30 FFF502B10BC4B91D8357A243F709B8AD 484352 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\{3D2B3714-F20B-486C-81A2-1949BAE31CF2}_AZ\{50472A36-E0E1-4508-9D19-10C009DF99E4}_DYG\tmp\wpm_v20.0.0.1277.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-12-06 19:03:45 02E324E880F6E54187A2B3C9F53DD70E 12730880 ----a-w- C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-12-06 19:03:30 AA3E2CEECFCD89D49FF902ECAD197946 2071552 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll 2014-12-06 19:03:30 495B4CA2AF924CE5C08BBC9D5E7E1103 2145472 ----a-w- C:\Windows\SysWOW64\mfcore.dll 2014-12-06 19:03:24 69567319D077611FFF5A07BDCDF2A400 889344 ----a-w- C:\Windows\SysWOW64\Windows.Media.dll 2014-12-06 19:03:21 E011C6CA6921FAC88F8B163C68E554BF 2410976 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL 2014-12-06 19:03:20 0C666352A0F9C61AB07019D3928463ED 391000 ----a-w- C:\Windows\SysWOW64\netcfgx.dll 2014-12-06 19:03:19 D39BD0DB9D91A4376F759282B2C276AE 1057792 ----a-w- C:\Windows\SysWOW64\printui.dll 2014-12-06 19:03:19 0120A5300040B9A1E459A03B364A74D5 1741824 ----a-w- C:\Windows\SysWOW64\SRH.dll 2014-12-06 19:03:18 3EAE3411A4A492C253A88534209E3045 355800 ----a-w- C:\Windows\SysWOW64\mfreadwrite.dll 2014-12-06 19:03:18 3362D78214C5B0A5CAE9E5C1692FA12B 474112 ----a-w- C:\Windows\SysWOW64\AppxPackaging.dll 2014-12-06 19:03:18 190228E527C47A96D9B865F07BF2EC19 889856 ----a-w- C:\Windows\SysWOW64\aclui.dll 2014-12-06 19:03:17 86A8EEFADBDDA52474456818D76DFAAA 302080 ----a-w- C:\Windows\SysWOW64\wlanmsm.dll 2014-12-06 19:03:16 F7A00AA3EA30F2F923C1F8A0DE76A113 180720 ----a-w- C:\Windows\SysWOW64\mftranscode.dll 2014-12-06 19:03:16 B393F30C63DCD1A0D6977A8E27A42A57 707536 ----a-w- C:\Windows\SysWOW64\mfplat.dll 2014-12-06 19:03:16 427A26A303BBF3736B054244EAFFAA4D 439296 ----a-w- C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll 2014-12-06 19:03:16 3C120DEE84D42246A17A917B2B934A36 513544 ----a-w- C:\Windows\SysWOW64\locale.nls 2014-12-06 19:03:14 FB970EC73EAB710FE1F529C139E258A0 477200 ----a-w- C:\Windows\SysWOW64\SHCore.dll 2014-12-06 19:03:14 9D75171689317D82FBF8B155FCF34AE8 371712 ----a-w- C:\Windows\SysWOW64\winspool.drv 2014-12-06 19:03:09 6ADEF3CCE9788849FA7F8D28A85B2833 540672 ----a-w- C:\Windows\SysWOW64\comdlg32.dll 2014-12-06 19:03:08 05B976CBCB4ADE4D3F4E75DAD196EECD 313856 ----a-w- C:\Windows\SysWOW64\clusapi.dll 2014-12-06 19:03:07 95719EC346E3A9FDD87662BE886EB200 1817088 ----a-w- C:\Windows\SysWOW64\Display.dll 2014-12-06 19:03:06 FEC1F6C1F496944BC40D995957D971CF 1404416 ----a-w- C:\Windows\SysWOW64\storagewmi.dll 2014-12-06 19:03:06 7BB5166433C5319CED9E8D05A0C5F7E8 230400 ----a-w- C:\Windows\SysWOW64\wlanapi.dll 2014-12-06 19:03:05 19C5844B56BCA187625D2CFA9A7C1144 127544 ----a-w- C:\Windows\SysWOW64\winmmbase.dll 2014-12-06 19:03:04 0F3DF44347B0051D30B23EED12973D8C 210944 ----a-w- C:\Windows\SysWOW64\wisp.dll 2014-12-06 19:03:02 F19F4DF5361132D5E19FBE1A0DCDC80B 335680 ----a-w- C:\Windows\SysWOW64\bcryptprimitives.dll 2014-12-06 19:03:01 8FC068ACF45786301D04CED5B58A13E3 1319936 ----a-w- C:\Windows\SysWOW64\wsecedit.dll 2014-12-06 19:03:01 704AA3D6466B2070D321C63C99368448 95232 ----a-w- C:\Windows\SysWOW64\AppxSip.dll 2014-12-06 19:03:00 E5FB6044A36E74484DA958AC17FA9504 1290752 ----a-w- C:\Windows\SysWOW64\XpsPrint.dll 2014-12-06 19:03:00 21A13082B44A898B8DCC54972B2B5C31 128568 ----a-w- C:\Windows\SysWOW64\winmm.dll 2014-12-06 19:02:58 E1F38BF986C7285AB13FB369243A41E0 448000 ----a-w- C:\Windows\SysWOW64\VAN.dll 2014-12-06 19:02:58 D9ABDEC0BDCD1FE7391EF756A2A9107B 180208 ----a-w- C:\Windows\SysWOW64\SndVol.exe 2014-12-06 19:02:58 42A350B81E0E9A427D7366E1E8BFBADC 198656 ----a-w- C:\Windows\SysWOW64\WebClnt.dll 2014-12-06 19:02:58 2F6410A7641BE1196DC423025F208285 98048 ----a-w- C:\Windows\SysWOW64\dwmapi.dll 2014-12-06 19:02:55 FC36740153F03C81ADA5B5EEF22C8064 1048064 ----a-w- C:\Windows\SysWOW64\gpedit.dll 2014-12-06 19:02:55 EBA5466233255ADAF7D5501F0CC2B9CF 189016 ----a-w- C:\Windows\SysWOW64\rsaenh.dll 2014-12-06 19:02:55 DA5AD8EA1331015BCC2FCFB1B7EE4EBC 168960 ----a-w- C:\Windows\SysWOW64\iasnap.dll 2014-12-06 19:02:54 1CD80290AEB1DA851B6AA9B9822F25F2 779264 ----a-w- C:\Windows\SysWOW64\osk.exe 2014-12-06 19:02:53 D32E7F10D61EFF5A26FB806934FB1088 1029632 ----a-w- C:\Windows\SysWOW64\mispace.dll 2014-12-06 19:02:53 CB587DCB837D0367B43584855BD22F25 432128 ----a-w- C:\Windows\SysWOW64\Windows.Networking.dll 2014-12-06 19:02:53 0836AC3FEF8E7380D1973E6DB14E31A7 459264 ----a-w- C:\Windows\SysWOW64\SettingSync.dll 2014-12-06 19:02:52 F7CA5639A235A1E2071500B4D1FCC6F8 51200 ----a-w- C:\Windows\SysWOW64\wshbth.dll 2014-12-06 19:02:52 14D03A4F5F0AFCDB93CAFB68B77ACDB6 288768 ----a-w- C:\Windows\SysWOW64\stobject.dll 2014-12-06 19:02:51 FE166ADB02C1E146005789C17E065143 8192 ----a-w- C:\Windows\SysWOW64\KBDRUM.DLL 2014-12-06 19:02:51 F1FCD3780D71FD21EAA2A42D3A924B1F 832512 ----a-w- C:\Windows\SysWOW64\ActionCenter.dll 2014-12-06 19:02:50 8A073508726DE4A69ED702A7A6082808 1351168 ----a-w- C:\Windows\SysWOW64\GdiPlus.dll 2014-12-06 19:02:50 0A6ABB521CDCE96D3A50939CF7964E24 206336 ----a-w- C:\Windows\SysWOW64\powercfg.cpl 2014-12-06 19:02:48 FB38126A24BDC4912C175C4C430E911C 7168 ----a-w- C:\Windows\SysWOW64\KBDRU1.DLL 2014-12-06 19:02:48 A40516F4443996DC92350D6890546E4A 7168 ----a-w- C:\Windows\SysWOW64\KBDYAK.DLL 2014-12-06 19:02:48 44AABDB92C816F112E054FC3523B51E8 7168 ----a-w- C:\Windows\SysWOW64\KBDBASH.DLL 2014-12-06 19:02:48 35D1AA379B4C2873F1DD62EDCA740C19 6656 ----a-w- C:\Windows\SysWOW64\KBDRU.DLL 2014-12-06 19:02:46 7D6731C5BA01769612A3EDC42A7C931B 79872 ----a-w- C:\Windows\SysWOW64\BluetoothApis.dll 2014-12-06 19:02:46 594CEF2E9CD8A5BB8310B3844614C127 7168 ----a-w- C:\Windows\SysWOW64\KBDTAT.DLL 2014-12-06 19:02:44 DB46A1A84AEC3A7F0FBA4E20320F3159 7168 ----a-w- C:\Windows\SysWOW64\KBDTT102.DLL 2014-12-05 22:40:46 B18F87B3C283054035AD0ABEF6296355 714208 ----a-w- C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-05 22:40:46 79C5F5F1B07576B8CBEF4D94893FCE3E 106976 ----a-w- C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-05 17:10:43 5F333FDBF392850373C89BDA31EBEC1B 1346048 ----a-w- C:\Windows\SysWOW64\user32.dll 2014-12-05 17:10:39 3B45EA6108E48406828D4E015FF41DD0 12800 ----a-w- C:\Windows\SysWOW64\winshfhc.dll 2014-12-03 19:05:31 BC426A818B7F3DB5F509BC1B62FF1501 357376 ----a-w- C:\Windows\SysWOW64\schannel.dll 2014-12-03 19:05:30 B2AC9E081A847ACBD5B62BE25AF39DA1 88800 ----a-w- C:\Windows\SysWOW64\ncryptsslp.dll 2014-12-03 19:05:01 2C01D8EA2B0FA834597FCD96AAAE4F52 406400 ----a-w- C:\Windows\SysWOW64\dxgi.dll 2014-12-03 19:04:20 DBC4D46A7DDC14D1D1ED4B613F9E41A4 1064448 ----a-w- C:\Windows\SysWOW64\gdi32.dll 2014-12-03 19:02:51 1DEC681B79501A714F0D3FA2787183C3 305152 ----a-w- C:\Windows\SysWOW64\wusa.exe 2014-12-03 18:58:12 E86549FED3008360730A6B722079D537 756224 ----a-w- C:\Windows\SysWOW64\WSShared.dll 2014-12-03 18:58:11 7BEE9E040222E7033A820780E1A61204 5777408 ----a-w- C:\Windows\SysWOW64\mstscax.dll 2014-12-03 18:58:11 074BF061D97E49AAF04F2FAF46409A14 5902848 ----a-w- C:\Windows\SysWOW64\Windows.UI.Search.dll 2014-12-03 18:58:10 DA65F1320538BC417B8FAE0BCAC330A0 265216 ----a-w- C:\Windows\SysWOW64\SkyDriveShell.dll 2014-12-03 18:58:04 76831C139BD9E227712B283A6A5ABBA8 840192 ----a-w- C:\Windows\SysWOW64\SearchFolder.dll 2014-12-03 18:58:04 1FA2D34A17E366C269FBE94DE06B177F 855552 ----a-w- C:\Windows\SysWOW64\rdvidcrl.dll 2014-12-03 18:58:03 DBA00F3FC75495058A25B24906C24599 1205976 ----a-w- C:\Windows\SysWOW64\propsys.dll 2014-12-03 18:58:03 BFC6F7889A9CFF451A418862444B9F63 321024 ----a-w- C:\Windows\SysWOW64\Wldap32.dll 2014-12-03 18:58:03 A4E624F7658D08C1717542FA10E0A973 1467384 ----a-w- C:\Windows\SysWOW64\ntdll.dll 2014-12-03 18:58:03 24B30DB8D1F8CF0F8C1AAAE319BC508E 838144 ----a-w- C:\Windows\SysWOW64\KernelBase.dll 2014-12-03 17:30:04 38045850ACB96313A1983A8803302906 35480 ----a-w- C:\Windows\SysWOW64\TsWpfWrp.exe 2014-12-03 17:29:40 1E4CD5DB4F61DF2A9053C8B9A46B4013 50176 ----a-w- C:\Windows\SysWOW64\UXInit.dll 2014-12-03 17:29:40 195822ACCDAA2B4815DD01BAFC335595 2084520 ----a-w- C:\Windows\SysWOW64\explorer.exe 2014-12-03 17:29:36 9F6204775EB03156B430FD095E3D0B5C 325632 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-12-03 17:29:35 A6145F4F8C69C3B46653B1C5E75A7BD6 688640 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-12-03 17:29:35 971D57DFB6F3FBC98EB74D1AF8E3C13B 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-12-03 17:29:35 7B0D22C64F9B6A8CD79EFADD29700693 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-12-03 17:29:35 45CDC0E37774D30BEE8C5F62CE30D599 1042944 ----a-w- C:\Windows\SysWOW64\actxprxy.dll 2014-12-03 17:29:35 07330241FD9D9A03811DDBDC4F9FD18F 19781632 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-12-03 17:29:35 027A2CF002AD94399B51C07E855E3B2B 1310208 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-12-03 17:29:33 98D83B6B4FBA32C39585D1E07121BEA0 2277376 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-12-03 17:29:33 8FC2FB51EB90E6AA582BDBA39C1935FD 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-12-03 17:29:33 7BCC24D058205664BD700D272B169AEC 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-12-03 17:29:33 154532E0EC2317E6924A9D27F894FF2F 12819456 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-12-03 17:29:33 108D84EE2359C595CCEA32820A2D5405 2051072 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-12-03 17:29:31 3CA90FDAB95FB2B0D91249BEDE3DE0D9 4298240 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-12-03 17:29:31 1BE74145FDF58734CFE968063533FBEC 708096 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-12-03 17:29:31 03D7DF4711B851EF286562F97429211D 1892864 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-12-03 17:29:25 F169B03C4B9996708DB20FF0C875B4FF 880128 ----a-w- C:\Windows\SysWOW64\inetcomm.dll 2014-12-03 17:29:25 E855B15E1BE0B58F84843D31F4CC4795 501248 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-12-03 17:29:25 8A88AD059EDC1014D5D6A472A6D1D66C 661504 ----a-w- C:\Windows\SysWOW64\jscript.dll 2014-12-03 17:29:24 FCAF49AE2E10EF3823262D10E7F2D0DE 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-03 17:29:24 EF7A48E5955736BEECF0B0ABB478E90E 478208 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-12-03 17:29:23 BE5EDCACB9E83C3695F650094367740C 99328 ----a-w- C:\Windows\SysWOW64\hlink.dll 2014-12-03 17:29:23 8DFBD587DBEBBC8EB50AD169DE88C449 340992 ----a-w- C:\Windows\SysWOW64\html.iec 2014-12-03 17:29:23 8A109878FA68DD1A4C91D8D499797E22 128000 ----a-w- C:\Windows\SysWOW64\iepeers.dll 2014-12-03 17:29:23 236AD481F1632F4CE7E9835FFD4AF41D 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-12-03 17:29:23 1D391C687102569FD1EA154F0C1A4CE8 91136 ----a-w- C:\Windows\SysWOW64\inseng.dll 2014-12-03 17:29:23 151E64E5D34DFB95D57B5B97C50DE64D 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2014-12-03 17:29:22 FC51834D5057B9D7847666AE88BC981C 130048 ----a-w- C:\Windows\SysWOW64\occache.dll 2014-12-03 17:29:22 F1313045CDCBBC4C90C34AEF67CEE088 112128 ----a-w- C:\Windows\SysWOW64\IEAdvpack.dll 2014-12-03 17:29:22 EF7B7299A1D6604AD3CA2CE1BEF8C8F3 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-12-03 17:29:22 ED5A4451A1A2777C6C5DB4238FD09078 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-12-03 17:29:22 DCFF6E5356CFF5B50BBA0FAAE01A0412 90624 ----a-w- C:\Windows\SysWOW64\iesysprep.dll 2014-12-03 17:29:22 A66A88FFE53BBB9DDAACE0110A8232EC 137728 ----a-w- C:\Windows\SysWOW64\wextract.exe 2014-12-03 17:29:22 8D1E12756ED6F1FDB026AD3CF264F90C 40448 ----a-w- C:\Windows\SysWOW64\imgutil.dll 2014-12-03 17:29:22 615D259116D1B331911CE28C8CD1CCF3 73216 ----a-w- C:\Windows\SysWOW64\tdc.ocx 2014-12-03 17:29:22 59607FB7C6B84860CE2D1C5F7C57E052 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-03 17:29:22 53E15B8DBD615567CA8895D65746C8D3 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-03 17:29:22 3C544C566EE7091AC52D4D9156C62687 235520 ----a-w- C:\Windows\SysWOW64\url.dll 2014-12-03 17:29:22 316280CC22CBB15271A91D83CDFB73C3 27136 ----a-w- C:\Windows\SysWOW64\licmgr10.dll 2014-12-03 17:29:22 26F4BDB6EA83011885E217A51A4A3E68 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-12-03 17:29:22 159199095C9959BE75E61C0FF947708F 152064 ----a-w- C:\Windows\SysWOW64\iexpress.exe 2014-12-03 17:29:22 0FEEFF4B96CA5972121F59525142A14E 52736 ----a-w- C:\Windows\SysWOW64\msfeedsbs.dll 2014-12-03 17:29:22 0812A503FF349D1DCEEB820B2E4FEE15 57344 ----a-w- C:\Windows\SysWOW64\pngfilt.dll 2014-12-03 17:29:22 02FF387F6228169EDDCB41F5E4B1A4E4 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-12-03 17:29:21 3FA76B67F25D84B3C2A4E8A8C0919E6E 12800 ----a-w- C:\Windows\SysWOW64\mshta.exe 2014-12-03 17:29:21 1BD4CD20A25B4A3A5F7BAAC25E9D9202 11264 ----a-w- C:\Windows\SysWOW64\msfeedssync.exe 2014-12-03 17:27:55 3BF6BEBD0A5666BDB426A734A4578D9B 1346048 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-12-03 17:27:51 BA4FA107EF9A728C58A81B2EFCD6FE2B 26784 ----a-w- C:\Windows\SysWOW64\mrt100.dll 2014-12-03 17:27:51 6923D6FAB7CBA8D82BD792182B4F3DE4 80032 ----a-w- C:\Windows\SysWOW64\mrt_map.dll 2014-12-02 20:18:26 949E0E42DAAD0418513B44C31A697CA5 1797896 ----a-w- C:\Windows\SysWOW64\d3d9.dll 2014-12-02 20:18:23 EA15CC7B75A2DE287E3B0C266A35490C 235008 ----a-w- C:\Windows\SysWOW64\framedynos.dll 2014-12-02 20:18:23 E4783EB6A6B2D04F3B541B378E843617 229888 ----a-w- C:\Windows\SysWOW64\dhcpcore6.dll 2014-12-02 20:18:23 E28501E3A241DDC5DC65382E55661B1D 285696 ----a-w- C:\Windows\SysWOW64\dhcpcore.dll 2014-12-02 20:18:22 0CCDFED2DFCD4FBA73EE989249379458 52736 ----a-w- C:\Windows\SysWOW64\ncobjapi.dll 2014-12-02 20:18:21 BEA7A26C2C22381B6DD88758352B9D9B 62976 ----a-w- C:\Windows\SysWOW64\dhcpcsvc.dll 2014-12-02 20:18:21 BA6E52B0D82682EDE4B49D9CCC7D529B 207360 ----a-w- C:\Windows\SysWOW64\framedyn.dll 2014-12-02 20:18:21 57E0A896C38C41C8B5B7F3127F8FD0D9 56320 ----a-w- C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-12-02 20:18:21 4E07710A2C9EA43E7509BF7D0452430E 106496 ----a-w- C:\Windows\SysWOW64\Robocopy.exe 2014-12-02 20:18:20 191B7F25BE13D9F9E56B2B4EA595AC62 11776 ----a-w- C:\Windows\SysWOW64\d3d8thk.dll 2014-12-02 20:17:47 0FDDBC46B0FE68B9516BED5CDC2A5296 5104640 ----a-w- C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2014-12-02 20:17:42 90C83CF02C884315E595FA07CA9C64EF 387896 ----a-w- C:\Windows\SysWOW64\mfsvr.dll 2014-12-02 20:17:42 87AB9959EC23455326C8C55E59DE0A88 669856 ----a-w- C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-12-02 20:17:41 EC4FA776548BF1A05DAE3B5EFB0FFE6F 1209616 ----a-w- C:\Windows\SysWOW64\winmde.dll 2014-12-02 20:17:41 A54EB398BC2D792A0C603A97F7975FD8 357376 ----a-w- C:\Windows\SysWOW64\GeofenceMonitorService.dll 2014-12-02 20:17:41 76892045ECB1D830185618DBD3467562 337408 ----a-w- C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-12-02 20:17:40 A4F3682781DD8B36E97FD04BA50845A2 209920 ----a-w- C:\Windows\SysWOW64\rdpencom.dll 2014-12-02 20:17:40 8C25FBB338147754DA42DF990FB3AE4A 285144 ----a-w- C:\Windows\SysWOW64\MFCaptureEngine.dll 2014-12-02 20:17:40 5FAEA469BCE03F8FABAFB63D7603DC3C 982016 ----a-w- C:\Windows\SysWOW64\Windows.Media.Streaming.dll 2014-12-02 20:17:39 A624CA7CDFA7941EECD6F96F1A47CCA3 178184 ----a-w- C:\Windows\SysWOW64\MSVideoDSP.dll 2014-12-02 20:17:39 4874EB05C1BE374B8A4AC15DF3DB07B0 111528 ----a-w- C:\Windows\SysWOW64\gpapi.dll 2014-12-02 20:17:38 88A821BC72CB1A935C92F453586233EF 518544 ----a-w- C:\Windows\SysWOW64\mf.dll 2014-12-02 20:17:38 15905E6B799C1446A37915ED23CD17E5 144384 ----a-w- C:\Windows\SysWOW64\rpchttp.dll 2014-12-02 20:17:37 E697F1E4E819EB12C40AE01F88626BAB 219136 ----a-w- C:\Windows\SysWOW64\resutils.dll 2014-12-02 20:17:37 619C6E72B8433B3F67738F7E6C972A96 230808 ----a-w- C:\Windows\SysWOW64\wintrust.dll 2014-12-02 20:17:36 D0E0E176F86C3B1048A67144DE0C5CD3 46592 ----a-w- C:\Windows\SysWOW64\tlscsp.dll 2014-12-02 20:17:34 68A23F58F6F16B81BCBFCAA07CDF0680 61440 ----a-w- C:\Windows\SysWOW64\srclient.dll 2014-12-02 20:17:34 3DA5CD1E3B9BDAF79731CB6CB1029CB3 53248 ----a-w- C:\Windows\SysWOW64\tsgqec.dll 2014-12-02 20:17:34 3CABBCB26C4E73F3440A8A064EB490FF 11264 ----a-w- C:\Windows\SysWOW64\wlanhlp.dll 2014-12-02 20:08:36 1FB4389CA807D59B105B0827FCC8F768 11820544 ----a-w- C:\Windows\SysWOW64\twinui.dll 2014-12-02 20:08:34 CA23E168518460519DC8D49EC6AD9550 18723112 ----a-w- C:\Windows\SysWOW64\shell32.dll 2014-12-02 20:08:31 CDB3123A2ABB34B830224B986568F4D4 626688 ----a-w- C:\Windows\SysWOW64\MrmCoreR.dll 2014-12-02 20:08:31 1793FC07D568C930C04F9FF40FFF9A69 799744 ----a-w- C:\Windows\SysWOW64\MFMediaEngine.dll 2014-12-02 20:08:31 0EEE3F2278E447498B2CDBDF34C63C91 670384 ----a-w- C:\Windows\SysWOW64\mfmp4srcsnk.dll 2014-12-02 20:08:30 C1AD30D5E28B4291D4A16BC6944ABC0C 2030592 ----a-w- C:\Windows\SysWOW64\WsmSvc.dll 2014-12-02 20:08:30 A208DEE0CD61E24817C26D5A05503DA7 334336 ----a-w- C:\Windows\SysWOW64\puiobj.dll 2014-12-02 20:08:30 A0E20B50D66FDF786BC2324499F7C482 195584 ----a-w- C:\Windows\SysWOW64\prnntfy.dll 2014-12-02 20:08:30 710A55B8443155F1FF09E07C2E44D79D 200192 ----a-w- C:\Windows\SysWOW64\DafPrintProvider.dll 2014-12-02 20:08:29 558838A9A51259F3E76030E3E997A72A 162816 ----a-w- C:\Windows\SysWOW64\puiapi.dll 2014-12-02 20:08:29 46C1902654FF54C835E4C4E8C14B7F2A 239104 ----a-w- C:\Windows\SysWOW64\FXSAPI.dll 2014-12-02 20:08:29 17FC09725FEE2546B96A938288509719 485376 ----a-w- C:\Windows\SysWOW64\untfs.dll 2014-12-02 19:59:55 B09332CC976AC43EFF595B6F01AA275C 2459136 ----a-w- C:\Windows\SysWOW64\authui.dll 2014-12-02 19:59:53 46FBD043A1688EFD6AC1395EE886AD33 3607040 ----a-w- C:\Windows\SysWOW64\msi.dll 2014-12-02 19:59:52 48C20EB77757F22840FF4CED98D8DEB1 325120 ----a-w- C:\Windows\SysWOW64\msihnd.dll 2014-12-02 19:53:47 D1A07DE4DC408E5AA5CFBAE261919BDC 72192 ----a-w- C:\Windows\SysWOW64\packager.dll 2014-12-02 19:43:27 128EC9879D462F89829E663417FE5DBD 710144 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll 2014-12-02 19:37:58 DDAAC7C966436938526D4CF4C6042A5C 154112 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2014-12-02 19:37:58 A22688490DCC2DA19441CA09EF7299BF 736768 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2014-12-02 19:37:58 791BDC9FD3C95F92C7DB2162132C8645 324096 ----a-w- C:\Windows\SysWOW64\certcli.dll 2014-12-02 19:37:44 DB3ED0BA26D7C598481A23E7D06A370E 2344448 ----a-w- C:\Windows\SysWOW64\Wpc.dll 2014-12-02 19:37:04 5D2C15BDAD48646C8CBC83903252D87C 514048 ----a-w- C:\Windows\SysWOW64\rastls.dll 2014-12-02 19:37:03 F344D6066EA270AABABA83E2A6B6428F 723968 ----a-w- C:\Windows\SysWOW64\wuapi.dll 2014-12-02 19:37:03 DC523277A7EC2336A654960E08EB5BDC 81920 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2014-12-02 19:37:03 C17F3F1EE09758CF9D234B22B80A1006 25600 ----a-w- C:\Windows\SysWOW64\wups.dll 2014-12-02 19:37:03 529122F3ADC548F0CCBB6164D86FA116 124928 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2014-12-02 19:37:03 514AEA6CF4B70FAA30A2BC4B4CC10A39 29696 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2014-12-02 19:36:40 75D0FAD0165770819770628239BF57DB 602768 ----a-w- C:\Windows\SysWOW64\oleaut32.dll 2014-12-02 19:34:29 FACBA112943A89FBB8AC25085521924F 344536 ----a-w- C:\Windows\SysWOW64\AUDIOKSE.dll 2014-12-02 19:34:29 61F5222289E052C40274ECD182A8AA99 98816 ----a-w- C:\Windows\SysWOW64\drvinst.exe 2014-12-02 19:34:29 22B2920A0857BDD61B1331C30AD76F30 424544 ----a-w- C:\Windows\SysWOW64\AudioEng.dll 2014-12-02 19:34:29 0CBA301F325F922FAFB3B83AD3337BB2 370424 ----a-w- C:\Windows\SysWOW64\AudioSes.dll 2014-12-02 19:34:28 65FCEABE3128592F84B60140F814BDDB 1509888 ----a-w- C:\Windows\SysWOW64\DWrite.dll 2014-12-02 19:34:22 66F97677CC13F7B9E2408CC75750A389 208896 ----a-w- C:\Windows\SysWOW64\pku2u.dll 2014-12-02 19:34:22 4CD4C8D34213975444643A5F9594E363 806400 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2014-12-02 19:33:57 4C48253C6A21CCEBA071B58A5CDF17C1 875688 ----a-w- C:\Windows\SysWOW64\msvcr120_clr0400.dll 2014-12-02 19:33:33 684CF6A72A8DF7D66D262AC4A6E07845 270848 ----a-w- C:\Windows\SysWOW64\DaOtpCredentialProvider.dll 2014-12-02 19:33:01 0A9EB3956BCB7E5CDE15AF987BD81543 488960 ----a-w- C:\Windows\SysWOW64\qedit.dll 2014-12-02 19:32:56 4B7FA0A3D7B9D316BC6B2A409701E47D 828928 ----a-w- C:\Windows\SysWOW64\twinui.appcore.dll 2014-12-02 19:32:56 0542A44401EA9451D82D3DF4BF3BD871 419928 ----a-w- C:\Windows\SysWOW64\twinapi.appcore.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-12-06 19:03:50 49EEC8569BF200C95A38D00766AFB830 16874496 ----a-w- C:\Windows\Sysnative\Windows.UI.Xaml.dll 2014-12-06 19:03:38 CC59B18DEC31120F9957ABA55EC49FAC 2389504 ----a-w- C:\Windows\Sysnative\d3d10warp.dll 2014-12-06 19:03:31 AD3137A754F60D369C176EF4DD5084A0 2141920 ----a-w- C:\Windows\Sysnative\mfcore.dll 2014-12-06 19:03:29 69DB09F0263C637DA8568D404842466A 1261056 ----a-w- C:\Windows\Sysnative\gpsvc.dll 2014-12-06 19:03:29 3F5EF31C6AA204B099EE76497DF80A26 1532416 ----a-w- C:\Windows\Sysnative\wlansvc.dll 2014-12-06 19:03:28 61BF52E9FFAB27A0B6D621BE26088373 1600000 ----a-w- C:\Windows\Sysnative\workfolderssvc.dll 2014-12-06 19:03:27 11FA35E24D76F62BD3E64D43B12656EF 1231872 ----a-w- C:\Windows\Sysnative\Windows.Media.dll 2014-12-06 19:03:23 AEAD37FA03D6E90638D8A4DC30E50408 2050560 ----a-w- C:\Windows\Sysnative\SRH.dll 2014-12-06 19:03:23 8200B4C323229AA1F47C87EB37207E36 2574208 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL 2014-12-06 19:03:22 17E700D2F6671196D0512BF806BB6435 1182208 ----a-w- C:\Windows\Sysnative\printui.dll 2014-12-06 19:03:21 A9C015F01499761908DE61F172FAF65D 486744 ----a-w- C:\Windows\Sysnative\netcfgx.dll 2014-12-06 19:03:21 4301A4D673F1ACB195C4F30B306B70B9 1992192 ----a-w- C:\Windows\Sysnative\XpsPrint.dll 2014-12-06 19:03:20 B2C26168E74EA51BF65518A309B08C19 770048 ----a-w- C:\Windows\Sysnative\WorkfoldersControl.dll 2014-12-06 19:03:20 0A7F97DE49DB63E01CBCA067F4DA7AB8 544768 ----a-w- C:\Windows\Sysnative\AppxPackaging.dll 2014-12-06 19:03:19 BF6897E960C08E9FDD41B80726C61C2F 371200 ----a-w- C:\Windows\Sysnative\wlanmsm.dll 2014-12-06 19:03:19 A4CF0D2FF18BF8D128389AF26410FD8B 1018368 ----a-w- C:\Windows\Sysnative\aclui.dll 2014-12-06 19:03:18 8DC2979BC54C585BA5A4C9E6FABCD1B4 360480 ----a-w- C:\Windows\Sysnative\mfreadwrite.dll 2014-12-06 19:03:18 793EACA6BAE9F481C2059BCB3743EB4A 324096 ----a-w- C:\Windows\Sysnative\srvsvc.dll 2014-12-06 19:03:18 42FEA9E0BA9761D9E65A4F167D91515B 795136 ----a-w- C:\Windows\Sysnative\spoolsv.exe 2014-12-06 19:03:17 79EFAEE6FBD8ABC066B944E1A7A605BB 645592 ----a-w- C:\Windows\Sysnative\SHCore.dll 2014-12-06 19:03:16 3C120DEE84D42246A17A917B2B934A36 513544 ----a-w- C:\Windows\Sysnative\locale.nls 2014-12-06 19:03:15 7740658736BD07FC121EACB3CA7C9194 2397184 ----a-w- C:\Windows\Sysnative\storagewmi.dll 2014-12-06 19:03:14 FF1CB6C5D9288DAAA0DADAD6B1E35085 205512 ----a-w- C:\Windows\Sysnative\mftranscode.dll 2014-12-06 19:03:14 C40DE04CE3A8905EB8048B5CE0951DF0 882136 ----a-w- C:\Windows\Sysnative\mfplat.dll 2014-12-06 19:03:14 8EE8CA953542A8E70A841C453BC15196 427008 ----a-w- C:\Windows\Sysnative\clusapi.dll 2014-12-06 19:03:13 D0AD65EE089F735BF546ABFE28D192C0 621056 ----a-w- C:\Windows\Sysnative\comdlg32.dll 2014-12-06 19:03:12 D01BA613D268DAD03DD32A0DC5FD24DF 287232 ----a-w- C:\Windows\Sysnative\usbmon.dll 2014-12-06 19:03:11 40CC457FB140B509B50F96DAD9D8F80B 1660048 ----a-w- C:\Windows\Sysnative\winload.efi 2014-12-06 19:03:10 D249C3A58A4FCF755EF4C94F7047E015 449536 ----a-w- C:\Windows\Sysnative\defragsvc.dll 2014-12-06 19:03:10 835261C17478103B73F4FFB8454AF849 268288 ----a-w- C:\Windows\Sysnative\wisp.dll 2014-12-06 19:03:10 70696A95F26778CFCB106ECEAA40F4D9 1519560 ----a-w- C:\Windows\Sysnative\winload.exe 2014-12-06 19:03:10 5B6B32E83E371739B13AA67E260DC5C4 487936 ----a-w- C:\Windows\Sysnative\winspool.drv 2014-12-06 19:03:09 FE7E47BE6E0D9EF4F24D81381A829CEC 1463808 ----a-w- C:\Windows\Sysnative\wsecedit.dll 2014-12-06 19:03:09 C80D4D7AF450F7CAD615FF1D7B40D7AD 1488008 ----a-w- C:\Windows\Sysnative\winresume.efi 2014-12-06 19:03:09 3663F0BB881A16A689F33A21C1A3C76B 1356840 ----a-w- C:\Windows\Sysnative\winresume.exe 2014-12-06 19:03:08 EF1F8B57323E5D3FC6A0A25F98F90DBC 220160 ----a-w- C:\Windows\Sysnative\profsvc.dll 2014-12-06 19:03:07 EA10272605422080EE2FAB142A75120D 356864 ----a-w- C:\Windows\Sysnative\conhost.exe 2014-12-06 19:03:07 9D50C0B29FB20DF0A8FD197B332894B7 160600 ----a-w- C:\Windows\Sysnative\winmmbase.dll 2014-12-06 19:03:07 693CC2794DEFB8493ABFF68D509DACC4 127488 ----a-w- C:\Windows\Sysnative\WiFiDisplay.dll 2014-12-06 19:03:07 618A19EB31ECA7B7F2AA0207BAF598A5 84480 ----a-w- C:\Windows\Sysnative\wpdbusenum.dll 2014-12-06 19:03:06 F8A869262251B011A21DEC79AC1F3F5D 1844224 ----a-w- C:\Windows\Sysnative\Display.dll 2014-12-06 19:03:06 CD8CA57C36E596875865F451393C7C66 576512 ----a-w- C:\Windows\Sysnative\SettingSync.dll 2014-12-06 19:03:06 793DE7C6B82804D5973C43484F527849 117248 ----a-w- C:\Windows\Sysnative\AppxSip.dll 2014-12-06 19:03:06 1C683FB45C6CE0BB8A74BB0B1392599D 505344 ----a-w- C:\Windows\Sysnative\VAN.dll 2014-12-06 19:03:05 9A3AF816758D144B097AE477D99F7D79 834560 ----a-w- C:\Windows\Sysnative\osk.exe 2014-12-06 19:03:05 2C38FF9DE23A3BB335A95099622AB603 65536 ----a-w- C:\Windows\Sysnative\WorkFoldersGPExt.dll 2014-12-06 19:03:05 02FE7859AD2DEAD7E9E3C7BF5F484204 211216 ----a-w- C:\Windows\Sysnative\SndVol.exe 2014-12-06 19:03:03 83E7C4DA3BF4A21C3F809A506245CAEF 233888 ----a-w- C:\Windows\Sysnative\mfps.dll 2014-12-06 19:03:03 504DDEF8526CECAAD886D5AC5656DF1A 387896 ----a-w- C:\Windows\Sysnative\bcryptprimitives.dll 2014-12-06 19:03:02 CCC106273D4265A9091AA7B619DCC5DA 595456 ----a-w- C:\Windows\Sysnative\Windows.Networking.dll 2014-12-06 19:03:02 A6CB3CBF88DF671AC85FA9AABC33137F 125472 ----a-w- C:\Windows\Sysnative\dwmapi.dll 2014-12-06 19:03:02 7DEAD28D8FB9BCAE4A153A57338315E7 123920 ----a-w- C:\Windows\Sysnative\winmm.dll 2014-12-06 19:03:02 1922AAE64BCD761A0377F6981FC67736 721408 ----a-w- C:\Windows\Sysnative\twinapi.dll 2014-12-06 19:03:01 1A5835F2E6B49A83F0AEAD17B4537AF7 1656832 ----a-w- C:\Windows\Sysnative\GdiPlus.dll 2014-12-06 19:03:00 FD807B56AECFD89E4A46960C261D78BF 1089024 ----a-w- C:\Windows\Sysnative\gpedit.dll 2014-12-06 19:03:00 97F24AEACAD9C9038BEC5B2BA1ADA94C 187392 ----a-w- C:\Windows\Sysnative\WorkFoldersShell.dll 2014-12-06 19:02:59 91B18D7A1702ED589E67C6C81052B955 226816 ----a-w- C:\Windows\Sysnative\WebClnt.dll 2014-12-06 19:02:59 572EBBCDBBA56736F4C0B5487AE7BFA5 220160 ----a-w- C:\Windows\Sysnative\iasnap.dll 2014-12-06 19:02:57 0A3E1B697F6ACB7BC1C898DC14A96EC7 1287680 ----a-w- C:\Windows\Sysnative\mispace.dll 2014-12-06 19:02:56 FA86C3F979EF9CCCCED109B05DEBDD46 432640 ----a-w- C:\Windows\Sysnative\wwanconn.dll 2014-12-06 19:02:56 6ECFFE49AA43A74DC15701EFE6355621 92160 ----a-w- C:\Windows\Sysnative\dab.dll 2014-12-06 19:02:56 31C2E53FE0C039C1BF0F15154D8596E7 53248 ----a-w- C:\Windows\Sysnative\AppxSysprep.dll 2014-12-06 19:02:56 2B1C2CB5C97962C521CD806F0C86D2FE 102912 ----a-w- C:\Windows\Sysnative\wcmcsp.dll 2014-12-06 19:02:56 28E8D340402C130427F2901004B7FA99 321536 ----a-w- C:\Windows\Sysnative\stobject.dll 2014-12-06 19:02:56 0AB5085FE30F8F6942A2126BCFC1A606 263400 ----a-w- C:\Windows\Sysnative\SystemSettingsAdminFlows.exe 2014-12-06 19:02:55 B540693968BCA57F595A7B08DB4B46C3 216368 ----a-w- C:\Windows\Sysnative\rsaenh.dll 2014-12-06 19:02:55 AEDF08DDF4EA929FEDBC0A1CCF01F287 296960 ----a-w- C:\Windows\Sysnative\wlanapi.dll 2014-12-06 19:02:55 53F4FC66B94804BBF2016922CD826891 878592 ----a-w- C:\Windows\Sysnative\ActionCenter.dll 2014-12-06 19:02:54 69AF7212845FFCD0AA1F0FC5D51FB809 63488 ----a-w- C:\Windows\Sysnative\wshbth.dll 2014-12-06 19:02:52 A7762A36F92E57E41B0356EF5C672473 659968 ----a-w- C:\Windows\Sysnative\Windows.Devices.Bluetooth.dll 2014-12-06 19:02:52 3A80675FF8524B09817000B6A2E35B7A 18432 ----a-w- C:\Windows\Sysnative\wlansvcpal.dll 2014-12-06 19:02:52 041A999E4FF9A7CDBE67357751881FB8 134144 ----a-w- C:\Windows\Sysnative\browser.dll 2014-12-06 19:02:51 EB2BB6EC7AEBBDD04FAB8E8D6FCEDAA6 183808 ----a-w- C:\Windows\Sysnative\Defrag.exe 2014-12-06 19:02:51 CB9CEAB473897BE1E8C827D4F4EB1311 207360 ----a-w- C:\Windows\Sysnative\powercfg.cpl 2014-12-06 19:02:51 2067AF0531ACD5D28BD49DB30DF109CE 8192 ----a-w- C:\Windows\Sysnative\KBDRUM.DLL 2014-12-06 19:02:49 A4DE7868879498A4E4CBB12788FAA3E8 105472 ----a-w- C:\Windows\Sysnative\BluetoothApis.dll 2014-12-06 19:02:49 6A9650BDC13F1A770F20E7B99D29EE3D 6656 ----a-w- C:\Windows\Sysnative\KBDRU.DLL 2014-12-06 19:02:49 454A0735E836FBC31C064FED6C120B46 7168 ----a-w- C:\Windows\Sysnative\KBDRU1.DLL 2014-12-06 19:02:49 3429360674DA1E70F638924A6D5985CC 7168 ----a-w- C:\Windows\Sysnative\KBDYAK.DLL 2014-12-06 19:02:49 0AC5A816A01D0115588D4B997842780E 7168 ----a-w- C:\Windows\Sysnative\KBDBASH.DLL 2014-12-06 19:02:47 997E5E28492F02036E5C7BA6DB66ABDC 7168 ----a-w- C:\Windows\Sysnative\KBDTAT.DLL 2014-12-06 19:02:47 4F6203CBBEFB9FBFA859246682849A24 1144320 ----a-w- C:\Windows\Sysnative\wwanmm.dll 2014-12-06 19:02:46 A5141DD172927F04732F5B6BFBE49C15 443904 ----a-w- C:\Windows\Sysnative\wlansec.dll 2014-12-06 19:02:46 933C63C9003379F56BA4AF4149440FC8 226304 ----a-w- C:\Windows\Sysnative\SndVolSSO.dll 2014-12-06 19:02:45 B279922BCFD0E178068B159D85C5CDBE 2100736 ----a-w- C:\Windows\Sysnative\SystemSettingsAdminFlowUI.dll 2014-12-06 19:02:44 68270DE9415C8F8139242D38417B49BE 7168 ----a-w- C:\Windows\Sysnative\KBDTT102.DLL 2014-12-05 18:54:01 3D748E5558FD9A9F03182CB2330698DC 1018880 ----a-w- C:\Windows\Sysnative\termsrv.dll 2014-12-05 17:10:44 F0A117D19873FCDF801F082F33BFBB6C 1519488 ----a-w- C:\Windows\Sysnative\user32.dll 2014-12-05 17:10:39 668417ED63F9FBE7DD8D7A54B04279DA 14336 ----a-w- C:\Windows\Sysnative\winshfhc.dll 2014-12-03 19:05:31 F0CE4A653EEBA09509EAF93AE2226FA9 426496 ----a-w- C:\Windows\Sysnative\schannel.dll 2014-12-03 19:05:31 6DE50D5592C6EE18C87B0C2EEEDC1621 185856 ----a-w- C:\Windows\Sysnative\dpapisrv.dll 2014-12-03 19:05:30 622928F5A8045F8122F10561D6C35ED0 104336 ----a-w- C:\Windows\Sysnative\ncryptsslp.dll 2014-12-03 19:05:01 59EAFAE3A34B4925990A2E679CA91C5B 517528 ----a-w- C:\Windows\Sysnative\dxgi.dll 2014-12-03 19:05:01 454978FB3D24DE5C4199162D5F81FBEE 2133504 ----a-w- C:\Windows\Sysnative\dwmcore.dll 2014-12-03 19:04:20 87CEF71F9D5951C9379D2F956C07C37D 1336624 ----a-w- C:\Windows\Sysnative\gdi32.dll 2014-12-03 19:02:51 326715361A7D1C65983BFE920990E4EF 308224 ----a-w- C:\Windows\Sysnative\wusa.exe 2014-12-03 18:58:11 30293301B14D0D11D086B09831F5FE0D 920064 ----a-w- C:\Windows\Sysnative\WSShared.dll 2014-12-03 18:58:07 8A522BBE4E06586C57E5D9DC50FB88B0 6649344 ----a-w- C:\Windows\Sysnative\mstscax.dll 2014-12-03 18:58:07 1676B06421492B439A9E60C55692A921 8757760 ----a-w- C:\Windows\Sysnative\Windows.UI.Search.dll 2014-12-03 18:58:06 3014CE5846A486C624E3E2CEB8C3290C 286208 ----a-w- C:\Windows\Sysnative\SkyDriveShell.dll 2014-12-03 18:58:06 10CE7F7704E293F6CC6E0AF51DBFD95A 1106432 ----a-w- C:\Windows\Sysnative\SearchFolder.dll 2014-12-03 18:58:04 F58FBEA392B663B936E62939A877CA80 1120768 ----a-w- C:\Windows\Sysnative\SkyDrive.exe 2014-12-03 18:58:04 66CBCDDEF429E5BA83C3288EEB0771A6 717824 ----a-w- C:\Windows\Sysnative\SkyDriveTelemetry.dll 2014-12-03 18:58:04 57CA779C19C2F224BE0C5EFC40F54B60 4758528 ----a-w- C:\Windows\Sysnative\SyncEngine.dll 2014-12-03 18:58:04 37C1CBCB3F420C754E86E3EC313D436D 1112512 ----a-w- C:\Windows\Sysnative\KernelBase.dll 2014-12-03 18:58:04 2ECA23663D13100032E09062C743C70D 1507648 ----a-w- C:\Windows\Sysnative\propsys.dll 2014-12-03 18:58:04 0B1A9F6F9D2891C0F8783C0444D27DD0 1057280 ----a-w- C:\Windows\Sysnative\rdvidcrl.dll 2014-12-03 18:58:03 FD4EA8E9232ADD51DC31C295DDEF2768 287744 ----a-w- C:\Windows\Sysnative\SystemEventsBrokerServer.dll 2014-12-03 18:58:03 ACFEE9487693C2BD573DFCA71D98E17C 914432 ----a-w- C:\Windows\Sysnative\iphlpsvc.dll 2014-12-03 18:58:03 ABB028BAB78E7B4AFE374F8246F6CCB6 359424 ----a-w- C:\Windows\Sysnative\Wldap32.dll 2014-12-03 18:58:03 5053FE9043FB84D71B04EFC7D5DA13CF 1710184 ----a-w- C:\Windows\Sysnative\ntdll.dll 2014-12-03 18:58:02 E325BCD68EC0CF2E2EDD0AB7CC17C698 267776 ----a-w- C:\Windows\Sysnative\bisrv.dll 2014-12-03 18:58:02 73F269436228D5625E83A1EAF3549F58 118272 ----a-w- C:\Windows\Sysnative\httpprxm.dll 2014-12-03 18:58:02 5D4A403DAE434FBA11779496EAFBDDE8 75776 ----a-w- C:\Windows\Sysnative\adhsvc.dll 2014-12-03 18:58:02 36F977EDAE6CEE96CE6409B2B16765B4 290816 ----a-w- C:\Windows\Sysnative\ProximityService.dll 2014-12-03 18:58:02 0DD29E5328436D51517316CD6D3BACCA 286208 ----a-w- C:\Windows\Sysnative\pcsvDevice.dll 2014-12-03 17:30:04 6DBE73C09215E281F4283641144110A5 35480 ----a-w- C:\Windows\Sysnative\TsWpfWrp.exe 2014-12-03 17:29:41 00CD1254837739E310505EBCB19F7971 796672 ----a-w- C:\Windows\Sysnative\uDWM.dll 2014-12-03 17:29:40 04AE20974DF91DC7B9075FC5A126B77C 68096 ----a-w- C:\Windows\Sysnative\UXInit.dll 2014-12-03 17:29:36 62D54F4673A6208C8CC147758122B3C3 2865152 ----a-w- C:\Windows\Sysnative\actxprxy.dll 2014-12-03 17:29:35 FD7C8FAC461BED1FEEB808E477D884D4 716800 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-12-03 17:29:35 C9AB2198141844D3DF96B4552CE9D5AB 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-12-03 17:29:33 F7522B00C823794F86ABD5BE1F3D6B09 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-12-03 17:29:33 9CD8D475F462F82E6FD8BFCA7186ACD4 372736 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-12-03 17:29:33 559E084EEBE44864493B2903433F19B3 1550336 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-12-03 17:29:33 200CEA827BDC503F00C0AED0EA227D49 800768 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-12-03 17:29:32 62E2FCF45F349DE6CAFB3AA7E1D81DA4 2124288 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-12-03 17:29:31 22CBDB8810CBED0B4F5E4BE69D7E2AE8 2884096 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-12-03 17:29:30 175C139D51F99099D1BDA17794B02191 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-12-03 17:29:29 DE58DE2C6C8439B7174D6D3568AA4A80 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-12-03 17:29:29 BED4D30B7FF094E368333CE2D1CE3195 14390272 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-12-03 17:29:29 2CEACC509889A095828F27115257408D 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-12-03 17:29:28 F79E5258AF040A8AD83C7C1273A071C3 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-12-03 17:29:28 BF1FC65A307B31939ADF7F976FDE033C 2365440 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-12-03 17:29:28 BC3B7CCE855F9A8E7BC96F7062229A02 799232 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-12-03 17:29:28 079FEE6FC11A74E4309B6A10931C1CB2 6040064 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-12-03 17:29:27 6432F143CDC9D73BD2BF832CAB2EDC01 25110016 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-12-03 17:29:25 E40D3696BE4852956669C285038B37A6 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-12-03 17:29:25 46B5DD7C4B1851F59E48302185E076DF 1032704 ----a-w- C:\Windows\Sysnative\inetcomm.dll 2014-12-03 17:29:25 258C3082AD82C1AAD335DA3FE2D3EB25 580096 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-12-03 17:29:24 587DEBB59F5F14C9610966FB14A33607 633856 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-12-03 17:29:24 0D03DAD6BB183156C70F863D0F2FA55A 812544 ----a-w- C:\Windows\Sysnative\jscript.dll 2014-12-03 17:29:23 F0A53129AE95A895EC8C4DC36E1797A2 108544 ----a-w- C:\Windows\Sysnative\hlink.dll 2014-12-03 17:29:23 AF28C90094C4C50F083599C10D2DC072 145408 ----a-w- C:\Windows\Sysnative\iepeers.dll 2014-12-03 17:29:23 853BB696932E4C48EE7034BFF1209A5A 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll 2014-12-03 17:29:22 F54E1190251EB245183BF16D6C315613 237568 ----a-w- C:\Windows\Sysnative\url.dll 2014-12-03 17:29:22 DD8FD33C108F14681A410067AB21DDF3 152064 ----a-w- C:\Windows\Sysnative\occache.dll 2014-12-03 17:29:22 D66D11191B48007179B0A77DC0717267 33280 ----a-w- C:\Windows\Sysnative\licmgr10.dll 2014-12-03 17:29:22 CDC8A85EB301A8CBE55A81A1D55AF5E5 132096 ----a-w- C:\Windows\Sysnative\IEAdvpack.dll 2014-12-03 17:29:22 A7F53772ECAE2F44B455D14F71179940 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-12-03 17:29:22 A348DEFC16B6FBC88B7D61C3B861BCB1 107520 ----a-w- C:\Windows\Sysnative\inseng.dll 2014-12-03 17:29:22 8AE1AC97407CD82D8389390C21430579 111616 ----a-w- C:\Windows\Sysnative\iesysprep.dll 2014-12-03 17:29:22 85E97591864F3125C5B08FB44E0E8078 60416 ----a-w- C:\Windows\Sysnative\msfeedsbs.dll 2014-12-03 17:29:22 70576D76A11DD5AE54E719297A315F90 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-12-03 17:29:22 6096209CB47D61499C3608B9C25B073C 64512 ----a-w- C:\Windows\Sysnative\pngfilt.dll 2014-12-03 17:29:22 4B9C652BD0FD95A9E6123913C35519D6 143872 ----a-w- C:\Windows\Sysnative\wextract.exe 2014-12-03 17:29:22 3721721151DB49457B0FD35E0C04594C 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-12-03 17:29:22 2E475D2FCE0125FA0C486DB9D59E739B 417280 ----a-w- C:\Windows\Sysnative\html.iec 2014-12-03 17:29:22 1C3C54FA2D620DF3093F356A56EC5957 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-12-03 17:29:22 161BC2E883A8D8759A4DCF2A85AF9128 51200 ----a-w- C:\Windows\Sysnative\imgutil.dll 2014-12-03 17:29:22 00FB2FB8C27C834CF575BC415B80F995 87552 ----a-w- C:\Windows\Sysnative\tdc.ocx 2014-12-03 17:29:21 E99E2E88BFE584184AE92B1F8995CE93 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-12-03 17:29:21 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-12-03 17:29:21 CA2F3153EF3BCB0BD3A8984C933DF604 167424 ----a-w- C:\Windows\Sysnative\iexpress.exe 2014-12-03 17:29:21 A3871DED5ED88F59C0D1396761708F81 13824 ----a-w- C:\Windows\Sysnative\mshta.exe 2014-12-03 17:29:21 6A7F8D139610E5F3F158182778EF9275 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-12-03 17:29:21 66585D645C4E23A0FD5124BD714AE020 12800 ----a-w- C:\Windows\Sysnative\msfeedssync.exe 2014-12-03 17:28:14 F00E643D9244F31ECF5DE8A98C2C5FC6 98816 ----a-w- C:\Windows\Sysnative\aepic.dll 2014-12-03 17:28:14 D18149850795E7203610CEE9491515F1 304128 ----a-w- C:\Windows\Sysnative\generaltel.dll 2014-12-03 17:28:14 9E20A052D83A81AEC35B2EA29F32637A 391168 ----a-w- C:\Windows\Sysnative\devinv.dll 2014-12-03 17:28:14 91BB0DDA472733457072DA61178FA48E 228864 ----a-w- C:\Windows\Sysnative\aepdu.dll 2014-12-03 17:28:14 22ED46DE0E684749DA1BD703526FAA26 537088 ----a-w- C:\Windows\Sysnative\aeinv.dll 2014-12-03 17:28:11 AF33B3D7B32FE39656147E0849D987A4 321536 ----a-w- C:\Windows\Sysnative\lockscreencn.dll 2014-12-03 17:27:55 93645AEBE163230A2ED5050C14AE6603 2149376 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-12-03 17:27:51 D178F55D53B9A10FFBDC134C95517846 28320 ----a-w- C:\Windows\Sysnative\mrt100.dll 2014-12-03 17:27:51 A750229C96A406EE123F43916053F142 86688 ----a-w- C:\Windows\Sysnative\mrt_map.dll 2014-12-03 17:27:48 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\Windows\Sysnative\win32k.sys 2014-12-02 20:38:08 D92FB5770CBDE049A4732B76A77F6864 103374192 ----a-w- C:\Windows\Sysnative\MRT.exe 2014-12-02 20:23:51 E09BF40AA766B183F0F385C96B37D9E5 299520 ----a-w- C:\Windows\Sysnative\WSDMon.dll 2014-12-02 20:23:51 DA947D89F64B72A40F678AAAE76F7564 205824 ----a-w- C:\Windows\Sysnative\tcpmon.dll 2014-12-02 20:18:26 C1E44A99F7CF8C3A08CD5ADDF451636C 2125344 ----a-w- C:\Windows\Sysnative\d3d9.dll 2014-12-02 20:18:24 EA432A85ABF371E14FB364D5F4405897 403968 ----a-w- C:\Windows\Sysnative\vpnike.dll 2014-12-02 20:18:24 98D0985521BF8F7086EA9C860898A1EE 721408 ----a-w- C:\Windows\Sysnative\fveapi.dll 2014-12-02 20:18:24 05DE04005CE0D84D0E6AD21CAEB369C6 353280 ----a-w- C:\Windows\Sysnative\dhcpcore.dll 2014-12-02 20:18:23 E07C80468D0C599BFF01D9D4EC7AEDC3 339456 ----a-w- C:\Windows\Sysnative\bdesvc.dll 2014-12-02 20:18:23 6B374D279DC423FE69DB8DD1401E84FC 301056 ----a-w- C:\Windows\Sysnative\framedynos.dll 2014-12-02 20:18:23 10AC9494ECE22A2362E4E4D98C528D01 271872 ----a-w- C:\Windows\Sysnative\dhcpcore6.dll 2014-12-02 20:18:22 FBB1841434072FFA76E4AD287448E34A 262656 ----a-w- C:\Windows\Sysnative\framedyn.dll 2014-12-02 20:18:22 2616E8E9C8B66A67CFB6197E9517A2F2 123392 ----a-w- C:\Windows\Sysnative\Robocopy.exe 2014-12-02 20:18:22 20FB137ADDE1255F15F265A7BD9579BE 827392 ----a-w- C:\Windows\Sysnative\BFE.DLL 2014-12-02 20:18:22 1824052F17B12B5D7B21445B869EE9F2 71168 ----a-w- C:\Windows\Sysnative\ncobjapi.dll 2014-12-02 20:18:21 DEA76F90F9777E3427D70E380222B23B 1063424 ----a-w- C:\Windows\Sysnative\IKEEXT.DLL 2014-12-02 20:18:21 D3883FBCA97D10C8A39632D6CDDC6E85 65024 ----a-w- C:\Windows\Sysnative\dhcpcsvc6.dll 2014-12-02 20:18:21 7E1EBDB3424337ABB553F249A7811D94 87552 ----a-w- C:\Windows\Sysnative\dhcpcsvc.dll 2014-12-02 20:18:20 B7CC32E00C5C5152D221DF182827F58E 50745 ----a-w- C:\Windows\Sysnative\srms.dat 2014-12-02 20:18:20 71BAEAFD05B3040173F5BBEA2CFE9607 997888 ----a-w- C:\Windows\Sysnative\reseteng.dll 2014-12-02 20:17:48 AEDD44FDB8B521D443A07146F5CA3A53 7173120 ----a-w- C:\Windows\Sysnative\Windows.Data.Pdf.dll 2014-12-02 20:17:43 7FB9EC74ADFB2353B7782C3EF833F5B7 765408 ----a-w- C:\Windows\Sysnative\mfmpeg2srcsnk.dll 2014-12-02 20:17:42 A1CD5194ACC156A852136B303F087260 491744 ----a-w- C:\Windows\Sysnative\mfsvr.dll 2014-12-02 20:17:42 9ED0E72966FB08F7E6DB15E5519AF8D1 1379064 ----a-w- C:\Windows\Sysnative\wmpmde.dll 2014-12-02 20:17:42 411DBFCD6ABAB75B6F7950677AEEFB7D 1403856 ----a-w- C:\Windows\Sysnative\winmde.dll 2014-12-02 20:17:42 067CB90C277DB4A737D5DEABA3055972 407016 ----a-w- C:\Windows\Sysnative\services.exe 2014-12-02 20:17:41 EEC46BC17F28C528AB7FAC20AFDF69E3 462336 ----a-w- C:\Windows\Sysnative\XpsGdiConverter.dll 2014-12-02 20:17:41 98A184F6EC43B178901FCD5D4E2EC43B 1222656 ----a-w- C:\Windows\Sysnative\Windows.Media.Streaming.dll 2014-12-02 20:17:41 626D19F1771E1AE72208AE9A8F3082F7 491520 ----a-w- C:\Windows\Sysnative\GeofenceMonitorService.dll 2014-12-02 20:17:41 0BDD786156C820F49EEF5D348B4ACFF4 335872 ----a-w- C:\Windows\Sysnative\MDEServer.exe 2014-12-02 20:17:40 BAF51BE2DEB387BD99CAC4E3B7850FEC 250368 ----a-w- C:\Windows\Sysnative\rdpencom.dll 2014-12-02 20:17:40 95471DDCB3B3FF70015FD9AA13404F44 281600 ----a-w- C:\Windows\Sysnative\resutils.dll 2014-12-02 20:17:40 87CF824E47489DD972FB4FB9FC4EDD0A 324888 ----a-w- C:\Windows\Sysnative\MFCaptureEngine.dll 2014-12-02 20:17:40 850EBB87584484DC16F917E7B6F4A304 718336 ----a-w- C:\Windows\Sysnative\swprv.dll 2014-12-02 20:17:40 7B12172CCE581F76C9335D7A47E0AD50 130144 ----a-w- C:\Windows\Sysnative\gpapi.dll 2014-12-02 20:17:40 315502228EB37F36E86EF75CB1DA1D44 201920 ----a-w- C:\Windows\Sysnative\MSVideoDSP.dll 2014-12-02 20:17:40 1697E09CDA4DD8741B8276F48A8514DE 32600 ----a-w- C:\Windows\Sysnative\ploptin.dll 2014-12-02 20:17:39 E369C59F2C0852DDD090C07E0DDE0051 1436160 ----a-w- C:\Windows\Sysnative\VSSVC.exe 2014-12-02 20:17:39 9654DE19551093CD73874281E1573C94 135168 ----a-w- C:\Windows\Sysnative\wscsvc.dll 2014-12-02 20:17:39 2A4177EE5446877BD24DD72504105603 191488 ----a-w- C:\Windows\Sysnative\rpchttp.dll 2014-12-02 20:17:38 AE2B9504C975B529D92D9E6603F6D33F 609448 ----a-w- C:\Windows\Sysnative\mf.dll 2014-12-02 20:17:37 88ACBA95BB55B8226D52117462B76CD4 307304 ----a-w- C:\Windows\Sysnative\wintrust.dll 2014-12-02 20:17:37 64B2A2630C964BF135A84A52FB2EEF9A 47616 ----a-w- C:\Windows\Sysnative\tlscsp.dll 2014-12-02 20:17:37 5EE916C3272A19B459717A8D2397B07A 55296 ----a-w- C:\Windows\Sysnative\energyprov.dll 2014-12-02 20:17:37 414B81DE6CE46022ED43051C09EDB00B 467968 ----a-w- C:\Windows\Sysnative\srcore.dll 2014-12-02 20:17:37 072A99F351C505A45C9FDA32E7324602 28408 ----a-w- C:\Windows\Sysnative\mfpmp.exe 2014-12-02 20:17:36 B24960B79BDE7D5ED1EA638027F9E8F0 143872 ----a-w- C:\Windows\Sysnative\BootMenuUX.dll 2014-12-02 20:17:34 F587513213947A4C7EF47B660DAAFBC5 271872 ----a-w- C:\Windows\Sysnative\rstrui.exe 2014-12-02 20:17:34 B6BD22DDEDDD8665080D664749ACFEF5 64512 ----a-w- C:\Windows\Sysnative\tsgqec.dll 2014-12-02 20:17:34 9465F8E72887AC6CCDD97F738A5AB6B6 70656 ----a-w- C:\Windows\Sysnative\srclient.dll 2014-12-02 20:17:34 82FE5F302FD7C7EF0E41465BB873EFC7 11264 ----a-w- C:\Windows\Sysnative\wlanhlp.dll 2014-12-02 20:08:36 C4306ADC38939CAC60EA38AAD9F170C0 13424128 ----a-w- C:\Windows\Sysnative\twinui.dll 2014-12-02 20:08:36 8CBF1E2761816CFD9D32F8B32531D0FB 118272 ----a-w- C:\Windows\Sysnative\winbici.dll 2014-12-02 20:08:35 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 ----a-w- C:\Windows\Sysnative\BulkOperationHost.exe 2014-12-02 20:08:35 C88B63FE96DB4BCED65DD442BC8E77F5 1053184 ----a-w- C:\Windows\Sysnative\localspl.dll 2014-12-02 20:08:35 BCE66E78D388875B87286CA091E7075F 7484224 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2014-12-02 20:08:35 A92EF73B02686B7E6F070B486512DB88 389176 ----a-w- C:\Windows\Sysnative\ApnDatabase.xml 2014-12-02 20:08:35 34B5290B8770A2FC578E3FEAD3FD7462 921600 ----a-w- C:\Windows\Sysnative\MrmCoreR.dll 2014-12-02 20:08:35 1907823D5ACFD75D1D8C0D4318299726 2714112 ----a-w- C:\Windows\Sysnative\SettingsHandlers.dll 2014-12-02 20:08:34 1D303CE5BCBD5B80BBA08321F28A3F86 21197152 ----a-w- C:\Windows\Sysnative\shell32.dll 2014-12-02 20:08:31 CA729FCE295895515A09BD6FF7903DC8 836176 ----a-w- C:\Windows\Sysnative\mfmp4srcsnk.dll 2014-12-02 20:08:31 A208498C5CD750A1743C1AC8162A810F 941568 ----a-w- C:\Windows\Sysnative\MFMediaEngine.dll 2014-12-02 20:08:30 9CE162EB9057CF079736F4DD00FC0D6C 2480128 ----a-w- C:\Windows\Sysnative\WsmSvc.dll 2014-12-02 20:08:30 5416C603B6C85CF0698E8A2A1D28BAA2 448512 ----a-w- C:\Windows\Sysnative\puiobj.dll 2014-12-02 20:08:30 50E96089F9BE352621997143A56C8E76 822272 ----a-w- C:\Windows\Sysnative\win32spl.dll 2014-12-02 20:08:30 12C0733F955E15C3C37DD24C9C7D796A 263680 ----a-w- C:\Windows\Sysnative\DafPrintProvider.dll 2014-12-02 20:08:30 118A11C89FAD244A2B85DA7EDC3E9683 215552 ----a-w- C:\Windows\Sysnative\prnntfy.dll 2014-12-02 20:08:29 A8732AFE4DB47114355ABB285ED776D2 187392 ----a-w- C:\Windows\Sysnative\puiapi.dll 2014-12-02 20:08:29 9C55CE9707B3CA29A6505BCDCC546390 275968 ----a-w- C:\Windows\Sysnative\FXSAPI.dll 2014-12-02 20:08:29 8758F5DEBD2B950B2D56ED11F9E0B38F 545792 ----a-w- C:\Windows\Sysnative\untfs.dll 2014-12-02 20:08:29 6C118AEDD15FDBEAECC0E85C64B5B86B 615424 ----a-w- C:\Windows\Sysnative\FXSCOMEX.dll 2014-12-02 20:08:29 6317C9DB4282CEAA3BAB131BC3839B2A 308736 ----a-w- C:\Windows\Sysnative\compstui.dll 2014-12-02 19:59:55 EF745B98D81B8C462DB99FC8B5C4322A 3320320 ----a-w- C:\Windows\Sysnative\msi.dll 2014-12-02 19:59:55 D5B41A0C38408814A3E9BAC8C82B2E5B 2773504 ----a-w- C:\Windows\Sysnative\authui.dll 2014-12-02 19:59:52 D1A2E993DB1867C79177CCC9DB6337D0 116032 ----a-w- C:\Windows\Sysnative\consent.exe 2014-12-02 19:59:52 D0C15BC83B3D0AF4F9B1D70216D91794 428032 ----a-w- C:\Windows\Sysnative\msihnd.dll 2014-12-02 19:59:52 034ED41F13D9C1845C1E081F05B640DB 110080 ----a-w- C:\Windows\Sysnative\appinfo.dll 2014-12-02 19:53:47 84549E8C8BF76B293A7E625A98D4BCF9 81408 ----a-w- C:\Windows\Sysnative\packager.dll 2014-12-02 19:43:27 1BB9CC78C91536CBA7B04B61ED0F85C4 1273184 ----a-w- C:\Windows\Sysnative\rpcrt4.dll 2014-12-02 19:42:34 9A642F163F1FB12DE395A6010A9AD687 189920 ----a-w- C:\Windows\Sysnative\mfevtps.exe 2014-12-02 19:39:09 3DF281C1553A6124DEF875C19D46AC0D 190976 ----a-w- C:\Windows\Sysnative\storewuauth.dll 2014-12-02 19:39:06 68CB2B575F0C67BB14590D1471285287 201728 ----a-w- C:\Windows\Sysnative\ubpm.dll 2014-12-02 19:37:59 949E590B76018E4523FC71CE510ED9ED 1441792 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2014-12-02 19:37:58 D7B23B3154508256C9F434EF9B65B91D 131584 ----a-w- C:\Windows\Sysnative\rdpudd.dll 2014-12-02 19:37:58 A8484FB640E044858BA19FB4F13DD4CE 154112 ----a-w- C:\Windows\Sysnative\msaudite.dll 2014-12-02 19:37:58 91E59FCB3B32DD84E5DCDA2EA1583807 736768 ----a-w- C:\Windows\Sysnative\adtschema.dll 2014-12-02 19:37:58 488CEA4F1B4D2446FFB7A94E3CB385FE 445440 ----a-w- C:\Windows\Sysnative\certcli.dll 2014-12-02 19:37:58 3D2D2EA099D98FE6B94C7D8C7992C08C 40448 ----a-w- C:\Windows\Sysnative\rfxvmt.dll 2014-12-02 19:37:58 1D25CC0A9C480C5D56A5A6CF2B5DEB99 3547648 ----a-w- C:\Windows\Sysnative\rdpcorets.dll 2014-12-02 19:37:44 E7DE316FEEFC79327CFAD8F527979CC0 3118080 ----a-w- C:\Windows\Sysnative\Wpc.dll 2014-12-02 19:37:44 E2F4125BFAC99244088324A1841C0B83 3048880 ----a-w- C:\Windows\Sysnative\WpcMon.exe 2014-12-02 19:37:44 6BC31FB4E24A962C98801D3687A984C0 2861056 ----a-w- C:\Windows\Sysnative\WpcWebSync.dll 2014-12-02 19:37:22 D3AE5DB16EAF913860EC28654CE00E6B 1212928 ----a-w- C:\Windows\Sysnative\schedsvc.dll 2014-12-02 19:37:04 25EE65F2FA154EDED0E87354311FB1E2 590336 ----a-w- C:\Windows\Sysnative\rastls.dll 2014-12-02 19:37:03 EA2DF5520D3623F353F43809A2F88086 55776 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2014-12-02 19:37:03 E67B019D23320AA0C5F1E6DE5D30546A 407552 ----a-w- C:\Windows\Sysnative\WUSettingsProvider.dll 2014-12-02 19:37:03 DCD090318EC800CF6275C6835900B0C6 3557376 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2014-12-02 19:37:03 CCE7F88AD038494253B485EC1B144EB3 60416 ----a-w- C:\Windows\Sysnative\wups.dll 2014-12-02 19:37:03 BCC10D47920E83EAC8F2E7E2D414692E 894976 ----a-w- C:\Windows\Sysnative\wuapi.dll 2014-12-02 19:37:03 70AC0FA699C9420CB282CCF72993C2E1 51712 ----a-w- C:\Windows\Sysnative\wups2.dll 2014-12-02 19:37:03 5D67074419BBFDCA587C2E2A93743E8A 140288 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2014-12-02 19:37:03 4D94560FD4982BB52C1FE64AE38E1A9F 35840 ----a-w- C:\Windows\Sysnative\wuapp.exe 2014-12-02 19:37:03 4A112AD7D9C7289FE9945D05E97019D0 17408 ----a-w- C:\Windows\Sysnative\wuaext.dll 2014-12-02 19:37:03 2E66E7D4F1E39F7048A231AA60FD2532 95744 ----a-w- C:\Windows\Sysnative\wudriver.dll 2014-12-02 19:37:03 2585412FC573F298FCBFD6759F8C4C0F 1714176 ----a-w- C:\Windows\Sysnative\wucltux.dll 2014-12-02 19:36:40 9A108C0A3092110F4651B3AFB9CC7B3D 789184 ----a-w- C:\Windows\Sysnative\oleaut32.dll 2014-12-02 19:34:29 DFDFDE2EA4B5CD0606BA6E56ECEE502D 272248 ----a-w- C:\Windows\Sysnative\audiodg.exe 2014-12-02 19:34:29 C0484CA5C7F87E38909746B63C7FC868 911360 ----a-w- C:\Windows\Sysnative\audiosrv.dll 2014-12-02 19:34:29 BB93DAAAE9006598935192B9CB65E475 108432 ----a-w- C:\Windows\Sysnative\EncDump.dll 2014-12-02 19:34:29 BB7F878413AD3C2E7E89C96193D405DF 57856 ----a-w- C:\Windows\Sysnative\drvcfg.exe 2014-12-02 19:34:29 9F87516BF76C40B41D831F7D729A6044 482872 ----a-w- C:\Windows\Sysnative\AudioEng.dll 2014-12-02 19:34:29 9C88C9397B44B76E5C9A44B8E2CE53A1 500016 ----a-w- C:\Windows\Sysnative\AudioSes.dll 2014-12-02 19:34:29 8E472AA2E916417B55BC1E6727957453 110592 ----a-w- C:\Windows\Sysnative\drvinst.exe 2014-12-02 19:34:29 8085F95BB18A171E7221D2831BC08BC2 394120 ----a-w- C:\Windows\Sysnative\AUDIOKSE.dll 2014-12-02 19:34:29 7F70B1044272982AAEA7C16E83424770 226304 ----a-w- C:\Windows\Sysnative\AudioEndpointBuilder.dll 2014-12-02 19:34:28 CC8E86B9C18BCA38D3C467CFD661A466 1975296 ----a-w- C:\Windows\Sysnative\DWrite.dll 2014-12-02 19:34:28 3FA6DC6B29717E32E211C1FD821F2C75 1345536 ----a-w- C:\Windows\Sysnative\FntCache.dll 2014-12-02 19:34:22 E87F8EC00FEEF700E61F6989D88A8BC2 991232 ----a-w- C:\Windows\Sysnative\kerberos.dll 2014-12-02 19:34:22 788C7D910267DDCD675DF4AB01961265 259584 ----a-w- C:\Windows\Sysnative\pku2u.dll 2014-12-02 19:33:57 8BB7548307EE6147137993A410D64387 869544 ----a-w- C:\Windows\Sysnative\msvcr120_clr0400.dll 2014-12-02 19:33:33 B312E157D20E727F30EAB3A250441B6F 284672 ----a-w- C:\Windows\Sysnative\WUDFHost.exe 2014-12-02 19:33:33 9CDC2059A23E3C9B57696178508777E7 99840 ----a-w- C:\Windows\Sysnative\WUDFSvc.dll 2014-12-02 19:33:33 42D257559F97B30A94A027EB4555C62F 323584 ----a-w- C:\Windows\Sysnative\DaOtpCredentialProvider.dll 2014-12-02 19:33:33 1A54E3DF2CBB8DBE8A17C87BB07E3A7E 209408 ----a-w- C:\Windows\Sysnative\WUDFPlatform.dll 2014-12-02 19:33:33 08DCA300264238F9AE941302321F3D54 423768 ----a-w- C:\Windows\Sysnative\hal.dll 2014-12-02 19:33:01 78FC2B2BA0E5E1C9249E3157D4EE9BC7 586240 ----a-w- C:\Windows\Sysnative\qedit.dll 2014-12-02 19:32:56 FD3638782572A8281BCF12520F6579F4 79872 ----a-w- C:\Windows\Sysnative\WSReset.exe 2014-12-02 19:32:56 CCC6D7250D01DA7E5499B0722CF6CAE3 1054208 ----a-w- C:\Windows\Sysnative\twinui.appcore.dll 2014-12-02 19:32:56 9FA466A42109F408AC6C2848E851C38A 555736 ----a-w- C:\Windows\Sysnative\twinapi.appcore.dll 2014-12-02 19:32:47 52E94AE3C9FF1E18A1EA125C4FFB0EEC 2834944 ----a-w- C:\Windows\Sysnative\wpccpl.dll 2014-12-02 19:32:44 F381B380B7B2704EA4C0F8D8C49C1C50 623616 ----a-w- C:\Windows\Sysnative\MDMAgent.exe 2014-12-01 19:00:25 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Windows\Sysnative\HP_ActiveX_Patch_NOT_DETECTED.txt ====== C:\Windows\Sysnative\drivers ===== 2014-12-06 19:03:24 6416E79A58A8FCC33A447A4DDDD3BF04 412160 ----a-w- C:\Windows\Sysnative\drivers\srv.sys 2014-12-06 19:03:22 038C77D577900EE39410662478BB0D50 2009920 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys 2014-12-06 19:03:21 5BED3AB69797C8786EF70AEA8C33748B 674816 ----a-w- C:\Windows\Sysnative\drivers\srv2.sys 2014-12-06 19:03:17 FF78D053A05E5A394F4E3C1816CC65A8 143680 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-12-06 19:03:12 240C5C3793206725AA05665851E8C214 412992 ----a-w- C:\Windows\Sysnative\drivers\spaceport.sys 2014-12-06 19:03:09 64CA2B4A49A8EAF495E435623ECCE7DB 310080 ----a-w- C:\Windows\Sysnative\drivers\volsnap.sys 2014-12-06 19:03:08 D047CD668E6277FD80F0C613946F034C 246272 ----a-w- C:\Windows\Sysnative\drivers\srvnet.sys 2014-12-06 19:03:08 26ACA481FAFEC59FE311D719E3027BBA 446976 ----a-w- C:\Windows\Sysnative\drivers\nwifi.sys 2014-12-06 19:03:08 1DD05F4857C2188744B9E864658949DD 295424 ----a-w- C:\Windows\Sysnative\drivers\ks.sys 2014-12-06 19:03:07 FEF0BC107812B36849741C3211BA6B60 419648 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-12-06 19:03:04 9C096BF5E10CA8BFA56F32522A89FAF1 79872 ----a-w- C:\Windows\Sysnative\drivers\IPMIDrv.sys 2014-12-06 19:03:03 E4B4BE2D7750849C07589DA0B0AABA01 1118040 ----a-w- C:\Windows\Sysnative\drivers\ndis.sys 2014-12-06 19:03:02 D4B7ED39C7900384D9E5C1283F1E7926 76800 ----a-w- C:\Windows\Sysnative\drivers\hdaudbus.sys 2014-12-06 19:03:02 C910E5D18958914A66F0E45689D0B40A 206848 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys 2014-12-06 19:03:02 B1AA3B19A2E596A59224F893E01A5A75 126464 ----a-w- C:\Windows\Sysnative\drivers\NdisImPlatform.sys 2014-12-06 19:02:58 91ED124E261EA8FAA1C0FFDF2A71B0C4 280384 ----a-w- C:\Windows\Sysnative\drivers\pci.sys 2014-12-06 19:02:47 25BB93167DEF270188072603F92A1EF5 118272 ----a-w- C:\Windows\Sysnative\drivers\bthpan.sys 2014-12-05 17:10:46 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\Sysnative\drivers\WdNisDrv.sys 2014-12-05 17:10:46 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\Sysnative\drivers\WdBoot.sys 2014-12-05 17:10:45 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\Sysnative\drivers\WdFilter.sys 2014-12-03 19:05:01 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\Windows\Sysnative\drivers\dxgkrnl.sys 2014-12-03 18:58:10 97B9076611291AE4C4C107BC915BD026 1200640 ----a-w- C:\Windows\Sysnative\drivers\bthport.sys 2014-12-03 18:58:05 65392F3F3F65E4C6CC82A0F4F8A0B051 468288 ----a-w- C:\Windows\Sysnative\drivers\USBHUB3.SYS 2014-12-03 18:58:02 E0927EFA25D473367C3341B9F5969779 115712 ----a-w- C:\Windows\Sysnative\drivers\bridge.sys 2014-12-03 17:30:45 374E27295F0A9DCAA8FC96370F9BEEA5 563200 ----a-w- C:\Windows\Sysnative\drivers\afd.sys 2014-12-02 20:23:47 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\Windows\Sysnative\drivers\msgpioclx.sys 2014-12-02 20:18:23 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys 2014-12-02 20:18:22 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\Windows\Sysnative\drivers\agilevpn.sys 2014-12-02 20:18:22 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\Windows\Sysnative\drivers\vwifimp.sys 2014-12-02 20:18:21 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\Windows\Sysnative\drivers\vwififlt.sys 2014-12-02 20:17:40 F152D55E497E12256290C43B31C7D0CE 589656 ----a-w- C:\Windows\Sysnative\drivers\fvevol.sys 2014-12-02 20:17:40 D90AB68D0FAC9F357F663670FDBB511E 275800 ----a-w- C:\Windows\Sysnative\drivers\msiscsi.sys 2014-12-02 20:17:40 CADCE0D6C30427F70A4BFA426256F68C 337240 ----a-w- C:\Windows\Sysnative\drivers\Classpnp.sys 2014-12-02 20:17:39 4C1E71E37B56C768900B1FCF81205027 372568 ----a-w- C:\Windows\Sysnative\drivers\storport.sys 2014-12-02 20:17:38 6592D192E2823C043EDBC010E7774053 360792 ----a-w- C:\Windows\Sysnative\drivers\fltMgr.sys 2014-12-02 20:08:34 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys 2014-12-02 20:08:34 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS 2014-12-02 20:08:30 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\Sysnative\drivers\netio.sys 2014-12-02 20:08:30 66732C13628BDB1AB0D6FD46027327C2 148800 ----a-w- C:\Windows\Sysnative\drivers\USBSTOR.SYS 2014-12-02 20:01:25 947EA0AFF75E3E70D5BE9F88F6325F30 2641 ----a-w- C:\Windows\Sysnative\drivers\mfencrk.inf 2014-12-02 20:01:25 628DC155C32875B286B2742D10D196C2 5442 ----a-w- C:\Windows\Sysnative\drivers\mfencbdc.inf 2014-12-02 20:01:14 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\Sysnative\drivers\HipShieldK.sys 2014-12-02 19:37:58 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys 2014-12-02 19:37:58 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2014-12-02 19:37:58 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\Sysnative\drivers\cng.sys 2014-12-02 19:33:33 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-12-02 19:33:33 D79920BE4E6683D3AB50F71457A4F6C6 27480 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-12-02 19:33:33 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\Windows\Sysnative\drivers\WUDFPf.sys 2014-12-02 19:33:33 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\Windows\Sysnative\drivers\WUDFRd.sys 2014-12-02 19:33:33 48BA326A3DBA5B5BEB5F2777F4618696 89944 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-12-02 19:33:33 064260B3A5868AC894A4943543BC7AB7 37376 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-12-02 19:32:47 182561A14F2E93E81E66FE3700D17A5A 55328 ----a-w- C:\Windows\Sysnative\drivers\wpcfltr.sys 2014-11-22 16:51:47 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_LocationProvider_01_11_00.Wdf ====== C:\Windows\Tasks ====== 2014-12-05 22:52:32 0C48652875FC4C0AE9DB9595EB7E8F00 3552 ----a-w- C:\Windows\Sysnative\Tasks\CreateChoiceProcessTask 2014-12-05 19:25:56 630D23B2A8467C861B81067B35BAFF34 3160 ----a-w- C:\Windows\Sysnative\Tasks\Update Service YourFileDownloader 2014-11-22 15:26:53 D69C05DE89B5849540D4B19B83D99C3A 3598 ----a-w- C:\Windows\Sysnative\Tasks\Optimize Start Menu Cache Files-S-1-5-21-760243043-4025452639-3987015220-1001 2014-11-22 15:22:02 786DF583A76A279F39F0328375C9BA90 3962 ----a-w- C:\Windows\Sysnative\Tasks\User_Feed_Synchronization-{BFF192A3-4087-46DB-AEA0-FAEE1411F5E6} 2014-11-22 15:03:59 -------- d-----w- C:\Windows\Sysnative\Tasks\WPD ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-06 18:22:20 -------- d-----w- C:\Program Files\trend micro 2014-12-02 20:19:57 -------- d-----w- C:\Program Files\Microsoft Office 15 ======= C:\PROGRA~2 ===== 2014-12-05 23:27:15 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2014-12-05 23:27:14 -------- d-----r- C:\PROGRA~2\Skype 2014-12-05 20:02:42 -------- d-----w- C:\PROGRA~2\COMMON~1\Wise Installation Wizard 2014-12-05 19:27:07 -------- d-----w- C:\PROGRA~2\STab 2014-12-05 19:27:02 -------- d-----w- C:\PROGRA~2\Box Rock 2014-12-05 19:25:56 -------- d-----w- C:\PROGRA~2\YourFileDownloaderUpdater 2014-12-02 20:25:52 -------- d-----w- C:\PROGRA~2\COMMON~1\DESIGNER 2014-12-02 20:02:13 32371688 ----a-w- C:\PROGRA~2\COMMON~1\lpuninstall.exe 2014-12-02 20:00:56 -------- d-----w- C:\PROGRA~2\SafeKey ======= C: ===== 2014-12-05 20:24:02 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ====== C:\Users\Tjorven\AppData\Roaming ====== 2014-12-06 19:12:00 -------- d-sh--w- C:\Users\Tjorven\AppData\Local\EmieBrowserModeList 2014-12-06 17:27:34 -------- d-sh--w- C:\Users\Tjorven\AppData\Locallow\EmieBrowserModeList 2014-12-06 11:48:47 -------- d-----w- C:\Users\Tjorven\AppData\Local\Apps 2014-12-06 11:48:46 -------- d-----w- C:\Users\Tjorven\AppData\Local\Deployment 2014-12-06 11:45:19 -------- d-----w- C:\Users\Tjorven\AppData\Local\Skype 2014-12-06 11:45:05 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\Skype 2014-12-05 20:07:58 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\CyberLink 2014-12-05 19:27:24 -------- d-s---w- C:\Windows\sysWoW64\config\systemprofile\AppData\Locallow\Microsoft 2014-12-03 18:01:06 -------- d-----w- C:\Users\Tjorven\AppData\Local\Microsoft Help 2014-12-02 20:01:38 -------- d-----w- C:\Users\Tjorven\AppData\Locallow\SafeKeytmp 2014-12-02 20:01:38 -------- d-----w- C:\Users\Tjorven\AppData\Locallow\SafeKeylang 2014-12-02 20:01:03 -------- d-----w- C:\Users\Tjorven\AppData\Locallow\SafeKey 2014-12-02 19:50:40 -------- d-s---w- C:\Windows\serviceprofiles\networkservice\AppData\Locallow\Microsoft 2014-12-02 19:35:25 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\CrashDumps 2014-12-02 19:28:46 -------- d-----w- C:\Users\Tjorven\AppData\Local\Diagnostics 2014-12-01 19:28:28 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\PnrpSqm 2014-11-23 18:18:12 -------- d-----w- C:\Users\Tjorven\AppData\Local\CrashDumps 2014-11-22 15:24:35 -------- d-sh--w- C:\Users\Tjorven\AppData\Locallow\EmieUserList 2014-11-22 15:24:31 -------- d-sh--w- C:\Users\Tjorven\AppData\Local\EmieUserList 2014-11-22 15:24:31 -------- d-sh--w- C:\Users\Tjorven\AppData\Local\EmieSiteList 2014-11-22 15:24:27 -------- d-sh--w- C:\Users\Tjorven\AppData\Locallow\EmieSiteList 2014-11-22 15:24:24 -------- d-s---w- C:\Windows\serviceprofiles\Localservice\AppData\Locallow\Microsoft 2014-11-22 15:23:50 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking 2014-11-22 15:07:15 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\Hewlett-Packard 2014-11-22 15:04:48 -------- d-----w- C:\Users\Tjorven\AppData\Local\CyberLink 2014-11-22 15:04:06 -------- d-----w- C:\Users\Tjorven\AppData\Local\Hewlett-Packard 2014-11-22 15:03:39 -------- d-----r- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-11-22 15:03:39 -------- d-----r- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-11-22 15:03:33 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\Adobe 2014-11-22 15:03:33 -------- d-----w- C:\Users\Tjorven\AppData\Local\VirtualStore 2014-11-22 15:03:08 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\Synaptics 2014-11-22 15:03:05 -------- d-----w- C:\Users\Tjorven\AppData\Local\Packages 2014-11-22 15:02:44 -------- d-s---w- C:\Users\Tjorven\AppData\Locallow\Microsoft 2014-11-22 15:02:16 -------- d-s---w- C:\Users\Tjorven\AppData\Roaming\Microsoft 2014-11-22 15:02:16 -------- d-----w- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-22 15:02:16 -------- d-----w- C:\Users\Tjorven\AppData\Local\Temp 2014-11-22 15:02:16 -------- d-----w- C:\Users\Tjorven\AppData\Local\Pokki 2014-11-22 15:02:16 -------- d-----w- C:\Users\Tjorven\AppData\Local\Microsoft 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility ====== C:\Users\Tjorven ====== 2014-12-06 18:11:11 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Tjorven\Downloads\RSITx64.exe 2014-12-05 23:27:15 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-12-05 23:26:58 -------- d-----w- C:\ProgramData\Skype 2014-12-05 23:00:31 02C1EE40968BAA67C3A785CDA9807125 262 --sha-r- C:\ProgramData\ntuser.pol 2014-12-02 20:20:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-11-22 15:21:49 -------- d---a-w- C:\Users\Tjorven\OneDrive 2014-11-22 15:03:39 -------- d-----r- C:\Users\Tjorven\Searches 2014-11-22 15:03:38 -------- d-----r- C:\Users\Tjorven\Contacts 2014-11-22 15:03:13 -------- d-sh--w- C:\Users\Tjorven\IntelGraphicsProfiles 2014-11-22 15:02:43 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Tjorven\ntuser.ini 2014-11-22 15:02:16 -------- d--h--w- C:\Users\Tjorven\AppData 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Videos 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Saved Games 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Pictures 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Music 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Links 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Favorites 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Downloads 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Documents 2014-11-22 15:02:16 -------- d-----r- C:\Users\Tjorven\Desktop 2014-11-22 12:56:05 -------- d--h--r- C:\Users\Public\AccountPictures ====== C: exe-files == 2014-12-07 14:42:29 EED9A25909B9DE034D79E02624F60496 1786600 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BOASPRT.exe 2014-12-07 14:42:29 2D462877816CDB6EA1E36A04CF237F10 1791208 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BOAS.exe 2014-12-07 14:42:19 A73229B8CD150A277ADF3F3D9CC77F6E 98536 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BrowserAdapter.exe 2014-12-07 14:42:19 061DCD9BA44BB0A580E064938181F13D 114920 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BrowserAdapter64.exe 2014-12-07 14:35:55 B04598F3977B8FC3331917ECC0965ECE 1649896 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BOASHelper.exe 2014-12-06 19:03:19 C273B81224D445026E743BCB0C1B3B5B 2096128 ----a-w- C:\Program Files\Windows Journal\Journal.exe 2014-12-06 19:03:18 42FEA9E0BA9761D9E65A4F167D91515B 795136 ----a-w- C:\Windows\System32\spoolsv.exe 2014-12-06 19:03:10 70696A95F26778CFCB106ECEAA40F4D9 1519560 ----a-w- C:\Windows\System32\winload.exe 2014-12-06 19:03:10 70696A95F26778CFCB106ECEAA40F4D9 1519560 ----a-w- C:\Windows\System32\Boot\winload.exe 2014-12-06 19:03:09 3663F0BB881A16A689F33A21C1A3C76B 1356840 ----a-w- C:\Windows\System32\winresume.exe 2014-12-06 19:03:07 EA10272605422080EE2FAB142A75120D 356864 ----a-w- C:\Windows\System32\conhost.exe 2014-12-06 19:03:05 9A3AF816758D144B097AE477D99F7D79 834560 ----a-w- C:\Windows\System32\osk.exe 2014-12-06 19:03:05 02FE7859AD2DEAD7E9E3C7BF5F484204 211216 ----a-w- C:\Windows\System32\SndVol.exe 2014-12-06 19:02:58 D9ABDEC0BDCD1FE7391EF756A2A9107B 180208 ----a-w- C:\Windows\SysWOW64\SndVol.exe 2014-12-06 19:02:56 0AB5085FE30F8F6942A2126BCFC1A606 263400 ----a-w- C:\Windows\System32\SystemSettingsAdminFlows.exe 2014-12-06 19:02:54 1CD80290AEB1DA851B6AA9B9822F25F2 779264 ----a-w- C:\Windows\SysWOW64\osk.exe 2014-12-06 19:02:51 EB2BB6EC7AEBBDD04FAB8E8D6FCEDAA6 183808 ----a-w- C:\Windows\System32\Defrag.exe 2014-12-06 18:22:22 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Tjorven.exe 2014-12-06 18:11:11 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Tjorven\Downloads\RSITx64.exe 2014-12-06 11:49:05 3316B3B20D84E6AA0F01C3D89CB958B9 868640 ----a-w- C:\Users\Tjorven\AppData\Local\Apps\2.0\N5HY1VRJ.EHE\X9PQ7A8K.ELV\offi..etup_31bf3856ad364e35_0001.0000_none_50bc361121a85e7b\Office365DesktopSetup.exe 2014-12-06 11:49:05 3316B3B20D84E6AA0F01C3D89CB958B9 868640 ----a-w- C:\Users\Tjorven\AppData\Local\Apps\2.0\N5HY1VRJ.EHE\X9PQ7A8K.ELV\offi...app_c3bce3770c238a49_0001.0000_c9f9cb17c2686035\Office365DesktopSetup.exe 2014-12-06 11:49:05 0F3E62B3C6B4852C156E9B7D558FECEF 16160 ----a-w- C:\Users\Tjorven\AppData\Local\Apps\2.0\N5HY1VRJ.EHE\X9PQ7A8K.ELV\offi..vate_31bf3856ad364e35_0001.0000_none_0e54896ba10c728f\Office365DesktopSetupElevate.exe 2014-12-06 11:49:05 0F3E62B3C6B4852C156E9B7D558FECEF 16160 ----a-w- C:\Users\Tjorven\AppData\Local\Apps\2.0\N5HY1VRJ.EHE\X9PQ7A8K.ELV\offi...app_c3bce3770c238a49_0001.0000_c9f9cb17c2686035\Office365DesktopSetupElevate.exe 2014-12-06 11:48:40 6209E57DC8D08C7F4E16EC525C6BF853 489248 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\CYVAIAER\setup_nl.exe 2014-12-05 23:10:14 D4A2A59FABF967B23F746445D3A57205 84041160 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\oct2A1A.tmp.exe 2014-12-05 22:40:46 B18F87B3C283054035AD0ABEF6296355 714208 ----a-w- C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-12-05 20:02:07 5973A242277FB7B19D46BB73178246FC 47329360 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\SHSetup.exe 2014-12-05 20:01:59 7873B8294E75160D32CB07A83AD73857 728960 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\CYVAIAER\SpyHunter-installer.exe 2014-12-05 19:33:36 98E4853DE17732B446DCA790366E16C4 101608 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.expext.exe 2014-12-05 19:29:34 7A10B635441065EB07643694F1419128 61112 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\CYVAIAER\Validate[1].exe 2014-12-05 19:26:35 4B0666FD4A8B70889D81CBF3693A47F3 304848 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_64.exe 2014-12-05 19:26:18 821C4D8963A02B55569ECD8B22406577 298496 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\sdf2F4E.exe 2014-12-05 19:26:18 821C4D8963A02B55569ECD8B22406577 298496 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\GCT6BWCA\OfferInstaller[1].exe 2014-12-05 19:26:17 859B2571598147FC05A25A3F9AEA378E 212520 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\F2iNEfHEJL.exe 2014-12-05 19:26:12 28F987C71E90CE932F69F341F8809E1F 583376 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\ivX8lVqmUU.exe 2014-12-05 19:26:06 6DC70518A987E7615E3C673B7FEEE68E 309872 ----a-w- C:\Users\Tjorven\AppData\Local\Temp\QESQjr7cip.exe 2014-12-05 19:24:57 D8B275F4A2F4FEF2D8973E953A7E0ACF 3927032 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\CYVAIAER\minecraft_launcher_1.8.2_keinett_downloader.exe 2014-12-03 19:02:51 326715361A7D1C65983BFE920990E4EF 308224 ----a-w- C:\Windows\System32\wusa.exe 2014-12-03 19:02:51 1DEC681B79501A714F0D3FA2787183C3 305152 ----a-w- C:\Windows\SysWOW64\wusa.exe 2014-12-03 18:58:04 F58FBEA392B663B936E62939A877CA80 1120768 ----a-w- C:\Windows\System32\SkyDrive.exe 2014-12-03 17:39:07 FD73CE6356B85AD817E1F3F45DFA2F09 1461408 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\appvcleaner.exe 2014-12-03 17:30:04 6DBE73C09215E281F4283641144110A5 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe 2014-12-03 17:30:04 38045850ACB96313A1983A8803302906 35480 ----a-w- C:\Windows\SysWOW64\TsWpfWrp.exe 2014-12-03 17:29:40 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\Windows\explorer.exe 2014-12-03 17:29:40 195822ACCDAA2B4815DD01BAFC335595 2084520 ----a-w- C:\Windows\SysWOW64\explorer.exe 2014-12-03 17:29:35 FD7C8FAC461BED1FEEB808E477D884D4 716800 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-12-03 17:29:33 5F1B1148C830C0F149A476A58CE0D09D 815248 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-12-03 17:29:32 5AC6DB399DE418E3955F0CA4567BDD37 813712 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-12-03 17:29:25 E40D3696BE4852956669C285038B37A6 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-12-03 17:29:23 8D7C6EE90630126F79275BAC5FE16E51 468992 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-12-03 17:29:23 8CFC152DF5D4FCFD621EF3E231999D03 484352 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-12-03 17:29:22 ED5A4451A1A2777C6C5DB4238FD09078 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-12-03 17:29:22 CFB15ED916904B30D32DFDE29B67CDCC 25600 ----a-w- C:\Program Files (x86)\Internet Explorer\ExtExport.exe 2014-12-03 17:29:22 A66A88FFE53BBB9DDAACE0110A8232EC 137728 ----a-w- C:\Windows\SysWOW64\wextract.exe 2014-12-03 17:29:22 4B9C652BD0FD95A9E6123913C35519D6 143872 ----a-w- C:\Windows\System32\wextract.exe 2014-12-03 17:29:22 1C3C54FA2D620DF3093F356A56EC5957 144384 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-12-03 17:29:22 159199095C9959BE75E61C0FF947708F 152064 ----a-w- C:\Windows\SysWOW64\iexpress.exe 2014-12-03 17:29:21 CC5C5634FA72689449B4BF7960AC1AD5 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-12-03 17:29:21 CA2F3153EF3BCB0BD3A8984C933DF604 167424 ----a-w- C:\Windows\System32\iexpress.exe 2014-12-03 17:29:21 A3871DED5ED88F59C0D1396761708F81 13824 ----a-w- C:\Windows\System32\mshta.exe 2014-12-03 17:29:21 6A16741182E4C1E83636053C81CE344E 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-12-03 17:29:21 66585D645C4E23A0FD5124BD714AE020 12800 ----a-w- C:\Windows\System32\msfeedssync.exe 2014-12-03 17:29:21 3FA76B67F25D84B3C2A4E8A8C0919E6E 12800 ----a-w- C:\Windows\SysWOW64\mshta.exe 2014-12-03 17:29:21 1BD4CD20A25B4A3A5F7BAAC25E9D9202 11264 ----a-w- C:\Windows\SysWOW64\msfeedssync.exe 2014-12-03 17:28:14 D43F34B4901C499FE13798149879DCD8 161960 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe 2014-12-03 17:28:14 679A800CFFBB8EA970506887045F2E41 46752 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2014-12-03 17:27:49 35687E363B171A26E1D96C9E98DA7312 369640 ----a-w- C:\Windows\vpnplugins\juniper\JunosPulseVpn.exe 2014-12-02 20:38:08 D92FB5770CBDE049A4732B76A77F6864 103374192 ----a-w- C:\Windows\System32\MRT.exe 2014-12-02 20:22:04 FDB0560C147FFB6E1FFC79ABBCCF48D3 590536 ----a-w- C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe 2014-12-02 20:22:03 98A2C1C05D59593050C67B739CA6C0B0 217760 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2014-12-02 20:22:01 A0025CFA1A6FEE1D5F53D31F8AA8242D 28296 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\Common.DBConnection64.exe 2014-12-02 20:22:01 1CFBCB7748780D39C7209EFC929B126B 842440 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2014-12-02 20:21:56 FE9C0029E1AF26350D9985D00520E5C8 5132888 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 2014-12-02 20:21:56 66EDCE45573F8673DF9379F119CFE343 90720 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\MSOHTMED.EXE 2014-12-02 20:21:55 BE9C758721B33A78BC656C46C319AEE6 15968 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Smart Tag\SmartTagInstall.exe 2014-12-02 20:21:54 2661516FC0165AFDA792B6148FA4DB79 95184 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\110\SQLDumper.exe 2014-12-02 20:21:54 106021B1146952B8EC9FCBFEA7A7F277 705184 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\SPREADSHEETCOMPARE.EXE 2014-12-02 20:21:52 0CF56A130CB5DA4FF6D16B3461074400 14928 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\Common.ShowHelp.exe 2014-12-02 20:21:48 20BC802CA54ACFD48435C9176441C13A 7764184 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2014-12-02 20:21:45 A789DDA5192980D81DBB01D55811DEA9 49848 ----a-w- C:\Program Files\Microsoft Office 15\root\flattener\Flattener.exe 2014-12-02 20:21:45 9A80F562E89B3D98EBBE7EDD9E75FFAC 39576 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\AppSharingHookController64.exe 2014-12-02 20:21:43 6877C98E14A0356DBEFC11AD7C30AB1D 28784 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\Common.DBConnection.exe 2014-12-02 20:21:36 EDC36AE43B7FB8CE366540E729E342AA 281760 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\DATABASECOMPARE.EXE 2014-12-02 20:21:36 28F928C86873B30E508C3D4C976495AE 199760 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\DCF\filecompare.exe 2014-12-02 20:21:31 6447C60B47195C983BBBDAD6A2C22A99 474336 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2014-12-02 20:21:28 8D7A1204CC0086FDE7C3C3A08D1840C9 6014120 ----a-w- C:\Program Files\Microsoft Office 15\root\Integration\OneDriveSetup.exe 2014-12-02 20:21:23 3C283C1BFA1D88C2D4D52148CE62A7C7 543360 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\EQUATION\EQNEDT32.EXE 2014-12-02 20:21:18 30B5F9FB0C35AE6B4A0851D24CE2EE8B 150600 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source Engine\OSE.EXE 2014-12-02 20:21:03 FDB0560C147FFB6E1FFC79ABBCCF48D3 590536 ----a-w- C:\Program Files\Microsoft Office 15\root\Integration\Integrator.exe 2014-12-02 20:21:03 8D03F2858035926F6B1E6EC34A0C0595 145056 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate64.exe 2014-12-02 20:21:03 27DB723A68AE52CF0BCBA8708A44E0CA 311544 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVLP.exe 2014-12-02 20:21:03 098CA18BC23278B53C76C9F0D6BD7238 124064 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate32.exe 2014-12-02 20:20:21 A0597F9C38BFADA73C0062874761A43C 550584 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOSQM.EXE 2014-12-02 20:20:21 4F417B68A6EB97998C4E9156D053900A 1092816 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2014-12-02 20:20:21 1B7AF1B851A7A8763103FA63E8514CD6 207016 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2014-12-02 20:20:20 D40360ABC2BB38EE202F145CAF204E99 614568 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOICONS.EXE 2014-12-02 20:20:20 CC5C101D61539A7379AA9BC3282FD408 5680856 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2014-12-02 20:20:20 1A46825F604C22732FC882D06A70D473 150704 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\FLTLDR.EXE 2014-12-02 20:20:20 175B3D01AD19B310238B5C29846D2891 81640 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 2014-12-02 20:20:15 E80F15DCA53E1ECD433CFE042400DF97 40672 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SCANPST.EXE 2014-12-02 20:20:15 A8DC5CC29AD3B5608C4028A2FC64B8FD 3015336 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WORDICON.EXE 2014-12-02 20:20:15 A26A02BE800686B88F69B76BE5EC7326 3509416 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PPTICO.EXE 2014-12-02 20:20:15 8A59C5C5747DCDB8EA2B77C981E62AA7 665240 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\UcMapi.exe 2014-12-02 20:20:15 89FCD7CB454386CEDEB5DFF98637830A 50392 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SETLANG.EXE 2014-12-02 20:20:15 7EB78DC7EEAAFE9ECD788D1CCBC8EFAB 22592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Wordconv.exe 2014-12-02 20:20:15 7BA52235E256DC309D5E808B6C358FDE 3685544 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\XLICONS.EXE 2014-12-02 20:20:15 6CCAF0A53351077CA8E5EE0499ADB576 1846952 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\POWERPNT.EXE 2014-12-02 20:20:15 4BCE37BACBAB333187BB6E0F0B9F4C43 9597096 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PDFREFLOW.EXE 2014-12-02 20:20:15 36995A650174CC354F6E4C417C6D5625 1923224 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE 2014-12-02 20:20:15 33022E733887D50D1F796135A4C4E7C3 873648 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2014-12-02 20:20:15 1F9754F230A2BA24A961A7502135120E 480976 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2014-12-02 20:20:15 1A72E641E2C77131030DA60B7B71F66C 528576 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2014-12-02 20:20:15 14EC450D656FCCA98383830B711DAB89 18947744 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2014-12-02 20:20:14 F4C40708FC1C59FB5EB10B10AE23D348 33960 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msoev.exe 2014-12-02 20:20:14 F45A0DF110AAA1C48D1FA3009A671871 449208 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE 2014-12-02 20:20:14 F2C596D99EFF8F337BF4A428767F10EA 497848 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE 2014-12-02 20:20:14 DE43B2666E374279165FEAD586A4BA2C 33968 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msotd.exe 2014-12-02 20:20:14 D7E4EB3AA8CEEBB14DCA08D3B7AE41BD 87232 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\NAMECONTROLSERVER.EXE 2014-12-02 20:20:14 CD86464906551942F410AEA5B735D762 8686264 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE 2014-12-02 20:20:14 B6B52C83F878E9F6BBB25FDC1B718B76 25643168 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2014-12-02 20:20:14 A5A4E6BD8383533C82BFD99BAAD0B35D 10771104 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSPUB.EXE 2014-12-02 20:20:14 9D8ED241EDD0EF87E4EA33E8536F3668 21934232 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2014-12-02 20:20:14 9C9524FBE43E9593437BE11472872B0A 1783968 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\INFOPATH.EXE 2014-12-02 20:20:14 95F05B316E114B7B299DD0D57B1224F6 6484640 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\lynchtmlconv.exe 2014-12-02 20:20:14 80C830207A104F6C1BDE91D0D86D8685 195240 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE 2014-12-02 20:20:14 69439A00309B451605EBB90AB5B0E7E2 15518880 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSACCESS.EXE 2014-12-02 20:20:14 5EDC8FCE400CA9CDA27EFFC4AF4D7275 1765024 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE 2014-12-02 20:20:14 50C11D73A9DB8543B2FA25B9563D3F2D 283312 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msoia.exe 2014-12-02 20:20:14 4C3B97A5E937EA214096F4DF33D34FE3 700064 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSQRY32.EXE 2014-12-02 20:20:14 49B2D14B7D2F986BC83666851FD7C1C2 4522680 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GRAPH.EXE 2014-12-02 20:20:14 3A2C7CE18457029CC91BDE20281FA9CD 1026728 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\misc.exe 2014-12-02 20:20:14 2A057DD0B0AA74B7B9B1FC94E8EB82C9 569584 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2014-12-02 20:20:14 203718811BE4463ACE59C09A7DDFF4E8 517352 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2014-12-02 20:20:14 182315495531E8395EDA537739C87460 72384 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOHTMED.EXE 2014-12-02 20:20:14 149A96C02F566E0D38026B409D9CDDBA 1296072 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OcPubMgr.exe 2014-12-02 20:20:14 1265BCCDCD1C4585948DCA39AD78CF1A 991904 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE 2014-12-02 20:20:14 05CFC10D672D10CB2F9096B642441D22 19051160 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\lync.exe 2014-12-02 20:20:13 BAEA09EE9DEFB8A3935DB5EE0CF4A0F0 3748008 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ACCICONS.EXE 2014-12-02 20:20:13 98D3A7B6EC8360577B8E5FBD413FA713 153248 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CNFNOT32.EXE 2014-12-02 20:20:13 4085A1C1A6B05EDCE72BE2837BEAFD7A 229048 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CLVIEW.EXE 2014-12-02 20:20:13 12482D31B8FA8DF122F78A138926A8A1 33432 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\AppSharingHookController.exe 2014-12-02 20:19:59 F9362E1DBABA93E104B0ECDA6D5C7012 90280 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\perfboost.exe 2014-12-02 20:19:59 D567C3DF56AC248EE82039DC0AF6D9E1 205472 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\AppVShNotify.exe 2014-12-02 20:19:59 288BD9FFEA8FB0D2176F22751E0D9F92 248992 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\mavinject32.exe 2014-12-02 20:19:57 E9C4FE59345E50CFCC544B051FBDDE0D 2443960 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe 2014-12-02 20:19:57 C99D036BC17F05418E1CC8596A2EDE03 850656 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe 2014-12-02 20:19:57 5BB3AAB02A83D551AA6EFE3278DAD102 868552 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officec2rclient.exe 2014-12-02 20:19:51 5A9F31621CBE341BF9BC5E7C388AA501 1060024 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\BLC70EWX\Setup.X86.nl-nl_O365ProPlusRetail_2934d677-d42a-4396-864b-120ff884864d_TX_PR_.exe 2014-12-02 20:18:22 A83FCE24AE4103F9DA32E8707C4B4C43 124928 ----a-w- C:\Windows\SysWOW64\wbem\WMIADAP.exe 2014-12-02 20:18:22 34215162FF8440E3342071D5A7FDCB3C 1192280 ----a-w- C:\Windows\Boot\PCAT\memtest.exe 2014-12-02 20:18:22 2616E8E9C8B66A67CFB6197E9517A2F2 123392 ----a-w- C:\Windows\System32\Robocopy.exe 2014-12-02 20:18:22 1064CF2438DC44A13EFD13551915586D 321024 ----a-w- C:\Windows\System32\IME\SHARED\ImeBroker.exe 2014-12-02 20:18:21 4E07710A2C9EA43E7509BF7D0452430E 106496 ----a-w- C:\Windows\SysWOW64\Robocopy.exe 2014-12-02 20:18:20 A09657B30C532DCF848F2B33404EF190 166400 ----a-w- C:\Windows\System32\wbem\WMIADAP.exe 2014-12-02 20:17:42 067CB90C277DB4A737D5DEABA3055972 407016 ----a-w- C:\Windows\System32\services.exe 2014-12-02 20:17:41 0BDD786156C820F49EEF5D348B4ACFF4 335872 ----a-w- C:\Windows\System32\MDEServer.exe 2014-12-02 20:17:39 E369C59F2C0852DDD090C07E0DDE0051 1436160 ----a-w- C:\Windows\System32\VSSVC.exe 2014-12-02 20:17:37 072A99F351C505A45C9FDA32E7324602 28408 ----a-w- C:\Windows\System32\mfpmp.exe 2014-12-02 20:17:36 83AFE0227F4446876FDAADE6B9142F1C 175616 ----a-w- C:\Windows\System32\inetsrv\iissetup.exe 2014-12-02 20:17:36 6E92176D95905D93906E3D8237873354 148480 ----a-w- C:\Windows\SysWOW64\inetsrv\iissetup.exe 2014-12-02 20:17:34 F587513213947A4C7EF47B660DAAFBC5 271872 ----a-w- C:\Windows\System32\rstrui.exe 2014-12-02 20:17:34 B194DFF0C303121926CF5AAC3D5165ED 70656 ----a-w- C:\Windows\System32\InputMethod\SHARED\ChxPropertyUI.exe 2014-12-02 20:08:35 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 ----a-w- C:\Windows\System32\BulkOperationHost.exe 2014-12-02 20:08:35 BCE66E78D388875B87286CA091E7075F 7484224 ----a-w- C:\Windows\System32\ntoskrnl.exe 2014-12-02 20:08:35 00027BEFE4F0106DEC51901872EEDB85 86784 ----a-w- C:\Windows\ImmersiveControlPanel\SystemSettings.exe 2014-12-02 20:08:32 FEF22922E4FA075C6C1FFF4385D74A95 99136 ----a-w- C:\Windows\FileManager\FileManager.exe 2014-12-02 20:08:32 743DE31CDA4A16551F4F5F8A006E7295 1408472 ----a-w- C:\Windows\Camera\Camera.exe 2014-12-02 20:08:32 0C8AF6461266A72BE61552BB42BC13D8 361496 ----a-w- C:\Windows\FileManager\PhotosApp.exe 2014-12-02 20:02:13 5EF57DE612B34D877A287A516655F426 32371688 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe 2014-12-02 20:01:59 F9807320B9E9E8399D013F37EAC7A035 7300152 ----a-w- C:\Users\Tjorven\AppData\Local\Packages\windows_ie_ac_001\AC\SafeKey\LastPassBroker.exe 2014-12-02 20:01:58 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Tjorven\AppData\Local\Packages\windows_ie_ac_001\AC\SafeKey\find_bluetooth.exe 2014-12-02 20:01:31 F9807320B9E9E8399D013F37EAC7A035 7300152 ----a-w- C:\Program Files (x86)\SafeKey\LastPassBroker.exe 2014-12-02 20:01:30 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Program Files (x86)\SafeKey\find_bluetooth.exe 2014-12-02 20:01:20 F9807320B9E9E8399D013F37EAC7A035 7300152 ----a-w- C:\Users\Tjorven\AppData\LocalLow\SafeKey\LastPassBroker.exe 2014-12-02 20:01:17 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Tjorven\AppData\LocalLow\SafeKey\find_bluetooth.exe 2014-12-02 20:01:11 5EF57DE612B34D877A287A516655F426 32371688 ----a-w- C:\Program Files (x86)\SafeKey\safekey.exe 2014-12-02 19:59:52 D1A2E993DB1867C79177CCC9DB6337D0 116032 ----a-w- C:\Windows\System32\consent.exe 2014-12-02 19:42:34 9A642F163F1FB12DE395A6010A9AD687 189920 ----a-w- C:\Windows\System32\mfevtps.exe 2014-12-02 19:37:44 E2F4125BFAC99244088324A1841C0B83 3048880 ----a-w- C:\Windows\System32\WpcMon.exe 2014-12-02 19:37:43 642F850B5D94E08AB6CFF997BE09C688 86816 ----a-w- C:\Windows\BrowserChoice\browserchoice.exe 2014-12-02 19:37:03 EA2DF5520D3623F353F43809A2F88086 55776 ----a-w- C:\Windows\System32\wuauclt.exe 2014-12-02 19:37:03 514AEA6CF4B70FAA30A2BC4B4CC10A39 29696 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2014-12-02 19:37:03 4D94560FD4982BB52C1FE64AE38E1A9F 35840 ----a-w- C:\Windows\System32\wuapp.exe 2014-12-02 19:34:29 DFDFDE2EA4B5CD0606BA6E56ECEE502D 272248 ----a-w- C:\Windows\System32\audiodg.exe 2014-12-02 19:34:29 BB7F878413AD3C2E7E89C96193D405DF 57856 ----a-w- C:\Windows\System32\drvcfg.exe 2014-12-02 19:34:29 8E472AA2E916417B55BC1E6727957453 110592 ----a-w- C:\Windows\System32\drvinst.exe 2014-12-02 19:34:29 61F5222289E052C40274ECD182A8AA99 98816 ----a-w- C:\Windows\SysWOW64\drvinst.exe 2014-12-02 19:33:33 B312E157D20E727F30EAB3A250441B6F 284672 ----a-w- C:\Windows\System32\WUDFHost.exe 2014-12-02 19:32:56 FD3638782572A8281BCF12520F6579F4 79872 ----a-w- C:\Windows\System32\WSReset.exe 2014-12-02 19:32:56 BE1FAE2B208F1E0B38FD4EF353D067C8 25304 ----a-w- C:\Windows\WinStore\WSHost.exe 2014-12-02 19:32:44 F381B380B7B2704EA4C0F8D8C49C1C50 623616 ----a-w- C:\Windows\System32\MDMAgent.exe 2014-12-01 19:00:25 3E4DFCC923D0174878C3151FEF99195D 4608 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Quick Start\HPQuickstart.exe 2014-12-01 18:59:06 FFD052D0F464ADC243C24E71D15C9990 12344 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe 2014-12-01 18:59:06 DDE93A9FB974B6DCDEE299AF055CFFF1 59608 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\WarrantyObjectChecker.exe 2014-12-01 18:59:06 DD79A6B15C2F28DE98DF4852AAF6B13B 21720 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe 2014-12-01 18:59:05 C498AF98935393E92EF92665DA708CD3 119096 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil7.exe 2014-12-01 18:59:05 B524A0FAB59C208895913DC82FB3D090 40200 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSACommander.exe 2014-12-01 18:59:05 4FFD25FF66948F6868C9028D4F136940 154424 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil.exe 2014-12-01 18:59:04 F9EDD8A064F0FEDEAF812CF5B5EF5E9B 33496 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_AfterUpgradingToWin81.exe 2014-12-01 18:59:04 F57DB2F9AD648E513E97B5BCA2F14F46 44760 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_SmartFriendAwareness_Ex.exe 2014-12-01 18:59:04 F1B90C9C79298025DB64669CD7F93D1A 28888 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_US.exe 2014-12-01 18:59:04 E71B3AB9DDB8A4561F3FC2FB5C80DEB2 28888 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowMemory.exe 2014-12-01 18:59:04 DF2AC1055C406AA66869C95C2FD84A21 17464 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSACIPDetection4.exe 2014-12-01 18:59:04 D90FC3A92A8429784FE3119D83A60AB4 31448 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_Darwin_EMEA.exe 2014-12-01 18:59:04 C4476BF09DBF8FF6B1A19E1C7692659F 26624 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_Ex_US.exe 2014-12-01 18:59:04 C23490916152CA356B4BDA4A87974B45 35032 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_SmartFriendAwareness.exe 2014-12-01 18:59:04 AF0D919701B5BE372A276800084E6661 30936 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_BackupPasswordReminder.exe 2014-12-01 18:59:04 AC70A4D490D4D2CD6A0E63E0C66F6D04 27864 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_BackupPasswordReminder_NSPOS.exe 2014-12-01 18:59:04 A024CEA792E4CD161D664116A81821A8 27352 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_WindowsOLD.exe 2014-12-01 18:59:04 9E847E73C40EDFF3966C94EF4B64C94B 29400 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_Darwin_US.exe 2014-12-01 18:59:04 8409673B856C3F2AF634B135EF805F50 29912 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_GettingStartedwithWindows8.exe 2014-12-01 18:59:04 7C4B1D7284CE08D53C531651EA59444E 27352 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_NSPOS.exe 2014-12-01 18:59:04 7A1DC920D662880F6EF8A34E21E010B0 30424 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_BackupYourImportantData_US.exe 2014-12-01 18:59:04 698BA1D64B2C178B7069B2D1E0F35A7D 29400 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_BackupYourImportantData_EMEA.exe 2014-12-01 18:59:04 5BCB7F57FBA7E896E165864B7D6A0539 35128 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_CoolSense.exe 2014-12-01 18:59:04 58D87CD3D31B52C204A40F19FEF6BF3D 27352 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_EMEA.exe 2014-12-01 18:59:04 5606EFA83C850AB210C38A1C3AE886AE 28888 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_BeforeUpgradingToWin81.exe 2014-12-01 18:59:04 50B1464EC23D89CCEC8D089965246AB9 32056 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPResignFileLoader.exe 2014-12-01 18:59:04 3EBC8C7D0478D32A6D191793743458FA 28888 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_EMEA.exe 2014-12-01 18:59:04 1921F0BD86B21AF080F0A260565E2833 28888 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_NSPOS.exe 2014-12-01 18:59:04 10A2EB7A9BF4A8094E95C3148DF4BDF1 31448 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_RecoveryDisc_Darwin_NSPOS.exe 2014-12-01 18:59:04 06D9888F172A8AC47959DA5DF68270DE 29400 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_LowDiskSpace_US.exe 2014-12-01 18:59:04 01712BD0F1885AB648065FCBF57A0FDD 28376 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detect_SystemRestore.exe 2014-12-01 18:59:03 5288FEC36ADB27C8A24623F6DB8858B8 72920 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_toastNotify.exe 2014-12-01 18:59:03 2DA14CADC35E8CAEC6D0FD7D3A5844C2 21208 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\Detection_GuestAccount.exe === C: other files == 2014-12-07 14:42:29 A8EAEDD4633DF4B306C386109FF6847F 2411763 ----a-w- C:\Program Files (x86)\Box Rock\bin\BoxRock.BOAS.zip 2014-12-06 19:03:24 6416E79A58A8FCC33A447A4DDDD3BF04 412160 ----a-w- C:\Windows\System32\drivers\srv.sys 2014-12-06 19:03:22 038C77D577900EE39410662478BB0D50 2009920 ----a-w- C:\Windows\System32\drivers\ntfs.sys 2014-12-06 19:03:21 5BED3AB69797C8786EF70AEA8C33748B 674816 ----a-w- C:\Windows\System32\drivers\srv2.sys 2014-12-06 19:03:17 FF78D053A05E5A394F4E3C1816CC65A8 143680 ----a-w- C:\Windows\System32\drivers\usbccgp.sys 2014-12-06 19:03:12 240C5C3793206725AA05665851E8C214 412992 ----a-w- C:\Windows\System32\drivers\spaceport.sys 2014-12-06 19:03:09 64CA2B4A49A8EAF495E435623ECCE7DB 310080 ----a-w- C:\Windows\System32\drivers\volsnap.sys 2014-12-06 19:03:08 D047CD668E6277FD80F0C613946F034C 246272 ----a-w- C:\Windows\System32\drivers\srvnet.sys 2014-12-06 19:03:08 26ACA481FAFEC59FE311D719E3027BBA 446976 ----a-w- C:\Windows\System32\drivers\nwifi.sys 2014-12-06 19:03:08 1DD05F4857C2188744B9E864658949DD 295424 ----a-w- C:\Windows\System32\drivers\ks.sys 2014-12-06 19:03:07 FEF0BC107812B36849741C3211BA6B60 419648 ----a-w- C:\Windows\System32\drivers\usbhub.sys 2014-12-06 19:03:04 9C096BF5E10CA8BFA56F32522A89FAF1 79872 ----a-w- C:\Windows\System32\drivers\IPMIDrv.sys 2014-12-06 19:03:03 E4B4BE2D7750849C07589DA0B0AABA01 1118040 ----a-w- C:\Windows\System32\drivers\ndis.sys 2014-12-06 19:03:02 D4B7ED39C7900384D9E5C1283F1E7926 76800 ----a-w- C:\Windows\System32\drivers\hdaudbus.sys 2014-12-06 19:03:02 C910E5D18958914A66F0E45689D0B40A 206848 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2014-12-06 19:03:02 B1AA3B19A2E596A59224F893E01A5A75 126464 ----a-w- C:\Windows\System32\drivers\NdisImPlatform.sys 2014-12-06 19:02:58 91ED124E261EA8FAA1C0FFDF2A71B0C4 280384 ----a-w- C:\Windows\System32\drivers\pci.sys 2014-12-06 19:02:47 25BB93167DEF270188072603F92A1EF5 118272 ----a-w- C:\Windows\System32\drivers\bthpan.sys 2014-12-05 20:24:02 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-12-05 19:26:46 DECA2632FD5C3B218B2AE4A5A5BE0DE8 2782092 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\CYVAIAER\2[1].zip 2014-12-05 19:26:22 3F8FFCA0E270F3D497ECA03FC5938B54 2140351 ----a-w- C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\BLC70EWX\1[1].zip 2014-12-05 17:10:46 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\System32\drivers\WdNisDrv.sys 2014-12-05 17:10:46 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\System32\drivers\WdBoot.sys 2014-12-05 17:10:45 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\System32\drivers\WdFilter.sys 2014-12-03 19:05:01 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2014-12-03 18:58:10 97B9076611291AE4C4C107BC915BD026 1200640 ----a-w- C:\Windows\System32\drivers\bthport.sys 2014-12-03 18:58:05 65392F3F3F65E4C6CC82A0F4F8A0B051 468288 ----a-w- C:\Windows\System32\drivers\USBHUB3.SYS 2014-12-03 18:58:02 E0927EFA25D473367C3341B9F5969779 115712 ----a-w- C:\Windows\System32\drivers\bridge.sys 2014-12-03 17:30:45 374E27295F0A9DCAA8FC96370F9BEEA5 563200 ----a-w- C:\Windows\System32\drivers\afd.sys 2014-12-03 17:27:48 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\Windows\System32\win32k.sys 2014-12-02 20:23:47 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\Windows\System32\drivers\msgpioclx.sys 2014-12-02 20:20:15 B23995F0EBBD2EA8936CD30C3D33AF90 11528 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\System.Windows.Controls.Theming.Toolkit.zip 2014-12-02 20:20:14 66E7D4318253AD7EB4C5807F8F8F1DC3 86440 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Ocomprivate.zip 2014-12-02 20:20:14 59634C7CA5ED0E9021EA004B00AE0C00 70525 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Microsoft.Lync.Utilities.zip 2014-12-02 20:20:14 4F51304540C11D43F8EDEF3B7E2D6AE3 85318 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Microsoft.Lync.Model.zip 2014-12-02 20:20:14 2125F8133833C5EE7B5AEBBEAE2DFCCC 28804 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Microsoft.Lync.Utilities.Controls.zip 2014-12-02 20:18:23 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2014-12-02 20:18:22 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\Windows\System32\drivers\agilevpn.sys 2014-12-02 20:18:22 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\Windows\System32\drivers\vwifimp.sys 2014-12-02 20:18:21 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\Windows\System32\drivers\vwififlt.sys 2014-12-02 20:17:40 F152D55E497E12256290C43B31C7D0CE 589656 ----a-w- C:\Windows\System32\drivers\fvevol.sys 2014-12-02 20:17:40 D90AB68D0FAC9F357F663670FDBB511E 275800 ----a-w- C:\Windows\System32\drivers\msiscsi.sys 2014-12-02 20:17:40 CADCE0D6C30427F70A4BFA426256F68C 337240 ----a-w- C:\Windows\System32\drivers\Classpnp.sys 2014-12-02 20:17:39 4C1E71E37B56C768900B1FCF81205027 372568 ----a-w- C:\Windows\System32\drivers\storport.sys 2014-12-02 20:17:38 6592D192E2823C043EDBC010E7774053 360792 ----a-w- C:\Windows\System32\drivers\fltMgr.sys 2014-12-02 20:08:34 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2014-12-02 20:08:34 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2014-12-02 20:08:30 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\System32\drivers\netio.sys 2014-12-02 20:08:30 66732C13628BDB1AB0D6FD46027327C2 148800 ----a-w- C:\Windows\System32\drivers\USBSTOR.SYS 2014-12-02 20:02:16 1033B75BC9EBAED8F368B28E2B20B59C 1908839 ----a-w- C:\Program Files (x86)\SafeKey\lpchrome.crx 2014-12-02 20:01:14 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\System32\drivers\HipShieldK.sys 2014-12-02 20:00:31 B330B4A4F5E41462AB334A26897856BD 70608 ----a-w- C:\Windows\ELAMBKUP\mfeelamk.sys 2014-12-02 19:37:58 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys 2014-12-02 19:37:58 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2014-12-02 19:37:58 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\System32\drivers\cng.sys 2014-12-02 19:33:33 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 ----a-w- C:\Windows\System32\drivers\usbport.sys 2014-12-02 19:33:33 D79920BE4E6683D3AB50F71457A4F6C6 27480 ----a-w- C:\Windows\System32\drivers\usbd.sys 2014-12-02 19:33:33 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys 2014-12-02 19:33:33 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys 2014-12-02 19:33:33 48BA326A3DBA5B5BEB5F2777F4618696 89944 ----a-w- C:\Windows\System32\drivers\usbehci.sys 2014-12-02 19:33:33 064260B3A5868AC894A4943543BC7AB7 37376 ----a-w- C:\Windows\System32\drivers\usbuhci.sys 2014-12-02 19:32:47 182561A14F2E93E81E66FE3700D17A5A 55328 ----a-w- C:\Windows\System32\drivers\wpcfltr.sys 2014-12-01 18:59:43 43E552E573CBC302A2C6639CB43886FD 132376 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\resources\nl-NL\hcsolutions.zip 2014-12-01 18:59:33 A61D473456A479A2810245D04FE446B1 1184831 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\resources\guidAcheck.zip 2014-12-01 18:59:11 D0576CFEABF745A1D3724AA0B4871C12 2101901 ----a-w- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\resources\guid.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-760243043-4025452639-3987015220-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AccelerometerSysTrayApplet"="C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe" "HPMessageService"="C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe" "mcpltui_exe"="C:\Program Files\Common~1\McAfee\Platform\mcuicnt.exe /platui /runkey" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "SimplePass"="C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe /hideui" "OPBHOBroker"="C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe" "OPBHOBrokerDesktop"="C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Startup Folders ====================== 2014-12-02 20:02:16 2161 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install SafeKey IE RunOnce.lnk 2014-08-05 10:51:23 2077 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\Windows\SysNative\tasks\Update Service YourFileDownloader" [C:\Program Files (x86)\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{BFF192A3-4087-46DB-AEA0-FAEE1411F5E6}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\YCMServiceAgent" [C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon" [C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [03/12/2014 16:16] ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[30/10/2014 14:36] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://istart.webssearches.com/?type=hp&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://istart.webssearches.com/web/?type=ds&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE&q={searchTerms}" "Default_Page_URL"="http://istart.webssearches.com/?type=hp&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE" "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://istart.webssearches.com/web/?type=ds&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE&q={searchTerms}" "Default_Page_URL"="http://istart.webssearches.com/?type=hp&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE" "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE&q={searchTerms}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== shortcuts on Users Desktops ====================== C:\Users\Tjorven\Desktop\RSITx64.exe - Snelkoppeling.lnk - C:\Users\Tjorven\Downloads\RSITx64.exe C:\Users\Tjorven\Desktop\zoek.exe - Snelkoppeling.lnk - C:\Users\Tjorven\Downloads\zoek.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Connected Music.lnk - C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe C:\system.sav\util\HPCM\HPCMDesktopIcon.exe C:\Users\Public\Desktop\Connected Photo.lnk - C:\system.sav\util\HPCPDesktopIcon.exe C:\Users\Public\Desktop\Evernote.lnk - C:\Program Files (x86)\Evernote\Evernote\Evernote.exe C:\Users\Public\Desktop\McAfee LiveSafe – Internet Security.lnk - C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe C:\Users\Public\Desktop\WildTangent Games App - hp.lnk - C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe /src desktop /dp hpcnb2c14 ==== shortcuts in Users Start Menu ====================== C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Get Lucky.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Help.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Uninstall.lnk - C:\Program Files (x86)\LuckyTab\LuckyTab.exe -uninstall C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FarmVille 2.lnk - C:\Users\Tjorven\AppData\Local\Pokki\Engine\HostAppService.exe /OPEN"34e8f5c0c9e5744bf2cdb514283762dd0524776b" C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee\McAfee LiveSafe – Internet Security.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Access 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSACCESS.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Excel 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\EXCEL.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\InfoPath Designer 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\INFOPATH.EXE /design C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\InfoPath Filler 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\INFOPATH.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Lync 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\OneDrive voor Bedrijven 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\GROOVE.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\OneNote 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\ONENOTE.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Outlook 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\PowerPoint 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\POWERPNT.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Publisher 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSPUB.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Verzenden naar OneNote 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\ONENOTEM.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Word 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\WINWORD.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Database Compare 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\client\AppVLP.exe "C:\Program Files\Microsoft Office 15\Root\Office15\DCF\DATABASECOMPARE.EXE" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Lync opnamebeheer.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\OcPubMgr.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Office 2013 Upload Center.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSOUC.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Spreadsheet Compare 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\client\AppVLP.exe "C:\Program Files\Microsoft Office 15\Root\Office15\DCF\SPREADSHEETCOMPARE.EXE" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Taalvoorkeuren voor Office 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\SETLANG.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Telemetriedashboard voor Office 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\msotd.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Telemetrielogboek voor Office 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\msoev.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype voor bureaublad.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\Install SafeKey IE RunOnce.lnk - C:\Program Files (x86)\Common Files\lpuninstall.exe -p -name=SafeKey -ffuuid {072844D3-7DEE-45F6-A406-E87F76302E4B} ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CyberLink Media Suite.lnk - C:\Program Files (x86)\CyberLink\Media Suite\PS.exe C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CyberLink YouCam 5.lnk - C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HP Utility Center.lnk - C:\Program Files\Hewlett-Packard\HP Utility Center\HPUC.exe C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1417807595&from=exp&uid=ST500LT012-1DG142_S3PCK3DE ==== shortcuts After Repair ====================== C:\Users\Tjorven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Tjorven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Update Service YourFileDownloader deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\YourFileDownloader deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll O2 - BHO: McAfee SafeKey Vault - {9DB059B3-DD36-4a55-846C-59BE42A1202A} - C:\Program Files (x86)\SafeKey\LPToolbar.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: McAfee SafeKey - {61D700C1-7D8D-43c5-9C13-4FF85157CFE6} - C:\Program Files (x86)\SafeKey\LPToolbar.dll O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\Common~1\McAfee\Platform\mcuicnt.exe" /platui /runkey O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun O4 - Global Startup: Install SafeKey IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe O4 - Global Startup: ISCTSystray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: SafeKey - file://C:\Users\Tjorven\AppData\LocalLow\SafeKey\context.html?cmd=lastpass O8 - Extra context menu item: SafeKey Fill Forms - file://C:\Users\Tjorven\AppData\LocalLow\SafeKey\context.html?cmd=fillforms O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra button: McAfee SafeKey - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\SafeKey\LPToolbar.dll O9 - Extra 'Tools' menuitem: McAfee SafeKey - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\SafeKey\LPToolbar.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @oem24.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing) O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: @oem23.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing) O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing) O23 - Service: IHProtect Service - Unknown owner - C:\Program Files (x86)\STab\ProtectService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\61Q7WA0Z will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=9813 folders=257 513542749 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Tjorven\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Tjorven\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Tjorven\AppData\Local\Pokki\analytics.db" not found "C:\Users\Tjorven\AppData\Local\Pokki\engine_update.db" not found "C:\Program Files (x86)\STab\msvcr110.dll" not found "C:\Users\Tjorven\AppData\Local\Pokki\analytics.db" not found "C:\Users\Tjorven\AppData\Local\Pokki\engine_update.db" not found "C:\Program Files (x86)\Box Rock" not found "C:\Users\Tjorven\AppData\Local\Pokki" not found "C:\Program Files (x86)\STab" not found "C:\PROGRA~2\YourFileDownloaderUpdater" not found "C:\Users\Tjorven\AppData\Local\Pokki" not found "C:\PROGRA~2\Box Rock" not found "C:\Users\Tjorven\AppData\Local\Microsoft\Windows\INetCache\IE\61Q7WA0Z" not found ==== EOF on zo 07/12/2014 at 15:50:08,16 ======================