Part4 Code:
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 0B 37 EE 9E AD 72 D4 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 33 00 00 00 B3 DF BC F1 C2 FF 00 85 FF 0C CF D0 1B A9 38 A4 04 AA 13 95 E1 17 14 D1 7A 6D B4 DB 1E 4B 19 A5 35 A2 11 04 9D 51 BB C5 C3 F1 F4 9A 81 F0 3F 04 BE 72 C5 02 00 00 00 0E 00 00 00 46 4F 63 50 68 52 51 37 46 6C 59 25 33 64 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.191.2: C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.191.2: C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 60.3.0 ESR\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 60.3.0 ESR\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Nightly 66.0a1\extensions\\Components: C:\PROGRAM FILES\FIREFOX NIGHTLY\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Nightly 66.0a1\extensions\\Plugins: C:\PROGRAM FILES\FIREFOX NIGHTLY\PLUGINS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Pale Moon 28.1.0\extensions\\Components: C:\PROGRAM FILES\PALE MOON\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Pale Moon 28.1.0\extensions\\Plugins: C:\PROGRAM FILES\PALE MOON\PLUGINS
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 60.3.3\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 60.3.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{6EBED4D8-13D9-4270-8D44-B57DDB7A787C}: D:\Progs\AllaSoft\Video Downloader Converter\extensions\3.16.4.6855\BVDFirefoxExt [2018.11.24 03:06:57 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Nightly 66.0a1\extensions\\Components: C:\Program Files\Firefox Nightly\components
FF - HKEY_CURRENT_USER\software\mozilla\Nightly 66.0a1\extensions\\Plugins: C:\Program Files\Firefox Nightly\plugins
[2018.11.02 22:08:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mortifer\AppData\Roaming\mozilla\Extensions
[2018.11.02 22:15:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mortifer\AppData\Roaming\mozilla\SystemExtensionsDev
========== Chrome ==========
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhancbnhabhandieicagelcddkdfgoif\3.16.4_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad\5.0_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\Mortifer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7018.903.0.0_0\
O1 HOSTS File: ([2018.11.22 12:08:57 | 000,003,907 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 0.0.0.0 a.ads1.msn.com
O1 - Hosts: 0.0.0.0 a.ads2.msads.net
O1 - Hosts: 0.0.0.0 a.ads2.msn.com
O1 - Hosts: 0.0.0.0 a.rad.msn.com
O1 - Hosts: 0.0.0.0 a-0001.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0002.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0003.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0004.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0005.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0006.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0007.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0008.a-msedge.net
O1 - Hosts: 0.0.0.0 a-0009.a-msedge.net
O1 - Hosts: 0.0.0.0 ac3.msn.com
O1 - Hosts: 0.0.0.0 ad.doubleclick.net
O1 - Hosts: 0.0.0.0 adnexus.net
O1 - Hosts: 0.0.0.0 adnxs.com
O1 - Hosts: 0.0.0.0 ads.msn.com
O1 - Hosts: 0.0.0.0 ads1.msads.net
O1 - Hosts: 0.0.0.0 ads1.msn.com
O1 - Hosts: 0.0.0.0 aidps.atdmt.com
O1 - Hosts: 0.0.0.0 aka-cdn-ns.adtech.de
O1 - Hosts: 0.0.0.0 a-msedge.net
O1 - Hosts: 0.0.0.0 az361816.vo.msecnd.net
O1 - Hosts: 0.0.0.0 az512334.vo.msecnd.net
O1 - Hosts: 71 more lines...
O2:64bit: - BHO: (Reg Error: Value error.) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - Reg Error: Value error. File not found
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.8.0_191\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre1.8.0_191\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [SecurityHealth] C:\Programme\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CCEnhancer] C:\Program Files (x86)\CCEnhancer\CCEnhancer.exe ()
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [vmware-tray.exe] D:\VMware Workstation\Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Wondershare)
O4 - HKLM..\Run: [WPSTool] C:\Program Files (x86)\TP-Link\TP-Link Wireless Adapter WPS Tool\TWCU.exe (TP-Link Technologies Co., Ltd)
O4 - HKCU..\Run: [CCleaner] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKCU..\Run: [CCleaner Smart Cleaning] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKCU..\Run: [EADM] D:\Games\Origin\Origin.exe ()
O4 - HKCU..\Run: [EpicGamesLauncher] D:\Games\Fortnite\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe (Epic Games, Inc.)
O4 - HKCU..\Run: [KeePass Password Safe 2] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKCU..\Run: [Steam] D:\Games\Steam\steam.exe ()
O4 - HKCU..\Run: [Synapse3] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe ()
O4 - HKCU..\Run: [THPanel] C:\Program Files (x86)\Thunder Master\THPanel.exe (Palit Microsystems Ltd.)
O4 - HKCU..\Run: [VeraCrypt] C:\Program Files\VeraCrypt\VeraCrypt.exe (IDRIX)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableFullTrustStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUwpStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportFullTrustStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportUwpStartupTasks = 1
O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105 File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000014 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000015 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000014 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000015 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3615a814-1cd2-4d8f-8a5c-417e21555e98}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Programme\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Programme\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Programme\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Programme\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- C:\Windows\svchost.com "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- C:\Windows\svchost.com "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- C:\Windows\svchost.com "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- C:\Windows\svchost.com "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) Part5 Code:
========== Files/Folders - Created Within 7 Days ==========
[2018.12.17 02:55:59 | 000,000,000 | ---D | C] -- C:\FRST
[2018.12.17 02:54:19 | 002,417,152 | ---- | C] (Farbar) -- C:\Users\Mortifer\Desktop\FRST64.exe
[2018.12.17 02:20:14 | 005,746,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsDesktopEngine.exe
[2018.12.17 02:20:14 | 004,529,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsDesktopEngine.exe
[2018.12.17 02:20:14 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsProxyStub.dll
[2018.12.17 02:12:57 | 000,845,488 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\Autoruns64.exe
[2018.12.17 02:12:57 | 000,743,600 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\autorunsc64.exe
[2018.12.17 02:12:57 | 000,716,968 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\Autoruns.exe
[2018.12.17 02:12:57 | 000,629,928 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\autorunsc.exe
[2018.12.17 02:07:11 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mortifer\Desktop\OTL.exe
[2018.12.17 02:04:35 | 000,063,768 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
[2018.12.17 02:04:31 | 000,119,136 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\farflt.sys
[2018.12.17 02:04:30 | 000,111,152 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mwac.sys
[2018.12.17 01:28:24 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\backups
[2018.12.17 01:20:04 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Mortifer\Desktop\HijackThis.exe
[2018.12.17 01:10:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2018.12.17 01:10:07 | 000,032,168 | ---- | C] (Safer-Networking Ltd.) -- C:\Windows\SysNative\sdnclean64.exe
[2018.12.17 01:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2018.12.17 01:10:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2018.12.17 00:49:55 | 000,260,480 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018.12.17 00:47:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2018.12.17 00:46:54 | 007,321,808 | ---- | C] (Malwarebytes) -- C:\Users\Mortifer\Desktop\adwcleaner_7.2.5.0.exe
[2018.12.17 00:30:12 | 000,198,000 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\MbamChameleon.sys
[2018.12.17 00:25:57 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Visual Studio 2017
[2018.12.17 00:25:46 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Python Scripts
[2018.12.17 00:25:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)
[2018.12.17 00:14:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.6
[2018.12.17 00:14:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Package Cache
[2018.12.17 00:14:11 | 000,000,000 | ---D | C] -- C:\Program Files\IIS
[2018.12.17 00:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS
[2018.12.17 00:13:59 | 000,000,000 | ---D | C] -- C:\Program Files\VS2012Schemas
[2018.12.17 00:13:59 | 000,000,000 | ---D | C] -- C:\Program Files\VS2010Schemas
[2018.12.17 00:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\dftmp
[2018.12.17 00:13:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Azure
[2018.12.17 00:13:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2018.12.17 00:13:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Phone Kits
[2018.12.17 00:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
[2018.12.17 00:01:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2018.12.17 00:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows App Certification Kit
[2018.12.17 00:00:35 | 000,000,000 | ---D | C] -- C:\Program Files\Application Verifier
[2018.12.17 00:00:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Verifier
[2018.12.16 23:55:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTML Help Workshop
[2018.12.16 23:55:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
[2018.12.16 23:55:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2018.12.16 23:55:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Kits
[2018.12.16 23:48:23 | 017,871,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXCaptureReplay.dll
[2018.12.16 23:48:23 | 014,058,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXCaptureReplay.dll
[2018.12.16 23:48:23 | 004,858,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsRemoteEngine.exe
[2018.12.16 23:48:23 | 003,632,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsRemoteEngine.exe
[2018.12.16 23:48:23 | 002,818,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d12SDKLayers.dll
[2018.12.16 23:48:23 | 002,249,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d12SDKLayers.dll
[2018.12.16 23:48:23 | 002,000,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsOfflineAnalysis.dll
[2018.12.16 23:48:23 | 001,500,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsOfflineAnalysis.dll
[2018.12.16 23:48:23 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11_3SDKLayers.dll
[2018.12.16 23:48:23 | 001,178,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXCap.exe
[2018.12.16 23:48:23 | 001,100,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11_3SDKLayers.dll
[2018.12.16 23:48:23 | 000,921,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXCap.exe
[2018.12.16 23:48:23 | 000,539,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1debug3.dll
[2018.12.16 23:48:23 | 000,466,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1debug3.dll
[2018.12.16 23:48:23 | 000,402,944 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\DXCpl.exe
[2018.12.16 23:48:23 | 000,380,416 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysWow64\DXCpl.exe
[2018.12.16 23:48:23 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perf_gputiming.dll
[2018.12.16 23:48:23 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXGIDebug.dll
[2018.12.16 23:48:23 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsExperiment.dll
[2018.12.16 23:48:23 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perf_gputiming.dll
[2018.12.16 23:48:23 | 000,238,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXGIDebug.dll
[2018.12.16 23:48:23 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsExperiment.dll
[2018.12.16 23:48:23 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsMonitor.dll
[2018.12.16 23:48:23 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsReporting.dll
[2018.12.16 23:48:23 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsCapture.dll
[2018.12.16 23:48:23 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsMonitor.dll
[2018.12.16 23:48:23 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsCapture.dll
[2018.12.16 23:48:23 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsReporting.dll
[2018.12.16 23:48:23 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DxToolsReportGenerator.dll
[2018.12.16 23:48:23 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DxToolsReportGenerator.dll
[2018.12.16 23:48:23 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VSD3DWARPDebug.dll
[2018.12.16 23:48:23 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VSD3DWARPDebug.dll
[2018.12.16 23:48:23 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsProxyStub.dll
[2018.12.16 23:45:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Web Tools
[2018.12.16 23:42:54 | 000,000,000 | ---D | C] -- C:\Program Files\IIS Express
[2018.12.16 23:42:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS Express
[2018.12.16 23:42:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ASP.NET Core Runtime Package Store
[2018.12.16 23:42:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NuGet
[2018.12.16 23:41:50 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.dotnet
[2018.12.16 23:41:06 | 000,000,000 | ---D | C] -- C:\Program Files\dotnet
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\3082
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\3082
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\2052
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\2052
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1055
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1055
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1049
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1049
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1046
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1046
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1045
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1045
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1042
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1042
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1041
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1041
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1040
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1040
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1036
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1036
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1031
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1031
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1029
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1029
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1028
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1028
[2018.12.16 23:38:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Entity Framework Tools
[2018.12.16 23:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2018.12.16 23:35:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2018.12.16 23:34:59 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Kits
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Designer
[2018.12.16 23:34:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\vstelemetry
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Visual Studio Setup
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\ServiceHub
[2018.12.16 23:18:25 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Microsoft Visual Studio
[2018.12.16 23:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2018.12.16 23:17:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Visual Studio
[2018.12.16 23:16:27 | 001,281,536 | ---- | C] (Microsoft Corporation) -- C:\Users\Mortifer\Documents\vs_community.exe
[2018.12.16 21:26:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Netflix Checker Pack Moataz
[2018.12.16 21:21:03 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\All-in-One Checker
[2018.12.16 21:18:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Mail-Checker-2.0.0.1_1
[2018.12.16 14:55:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nmap
[2018.12.16 14:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Npcap
[2018.12.16 14:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Npcap
[2018.12.16 14:53:40 | 000,000,000 | ---D | C] -- C:\Program Files\Npcap
[2018.12.16 14:52:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nmap
[2018.12.16 07:03:13 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\BlackBullet
[2018.12.16 03:43:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\olly
[2018.12.16 01:07:02 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.pylint.d
[2018.12.16 01:00:32 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Python
[2018.12.16 01:00:24 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\pip
[2018.12.16 00:58:39 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.idlerc
[2018.12.16 00:18:00 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\AVAST Software
[2018.12.16 00:17:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVAST Software
[2018.12.16 00:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2018.12.15 12:11:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\assembly
[2018.12.15 11:18:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Deployment
[2018.12.15 11:18:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Apps
[2018.12.15 02:43:48 | 000,000,000 | ---D | C] -- C:\Python35
[2018.12.14 17:41:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2018.12.14 10:01:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Thunderbird
[2018.12.14 10:01:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Thunderbird
[2018.12.12 10:20:24 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2018.12.12 04:12:16 | 007,520,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Protection.PlayReady.dll
[2018.12.12 04:12:16 | 006,569,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Protection.PlayReady.dll
[2018.12.12 04:12:14 | 025,855,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgehtml.dll
[2018.12.12 04:12:07 | 022,016,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgehtml.dll
[2018.12.12 04:12:06 | 009,084,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2018.12.12 04:12:06 | 007,436,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\windows.storage.dll
[2018.12.12 04:12:06 | 001,213,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ClipUp.exe
[2018.12.12 04:12:05 | 007,573,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Chakra.dll
[2018.12.12 04:12:05 | 005,625,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StartTileData.dll
[2018.12.12 04:12:05 | 001,616,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll
[2018.12.12 04:12:04 | 006,043,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\windows.storage.dll
[2018.12.12 04:12:04 | 004,710,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdp.dll
[2018.12.12 04:12:04 | 003,396,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2018.12.12 04:12:03 | 013,572,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2018.12.12 04:12:03 | 012,500,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2018.12.12 04:12:02 | 007,057,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mos.dll
[2018.12.12 04:12:02 | 005,775,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Chakra.dll
[2018.12.12 04:12:02 | 001,017,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2adec.dll
[2018.12.12 04:12:01 | 004,866,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2018.12.12 04:12:01 | 004,708,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.pcshell.dll
[2018.12.12 04:12:01 | 004,384,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeContent.dll
[2018.12.12 04:12:01 | 002,371,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2018.12.12 04:12:01 | 002,331,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll
[2018.12.12 04:12:01 | 000,861,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2adec.dll
[2018.12.12 04:12:00 | 006,586,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2018.12.12 04:12:00 | 003,649,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kfull.sys
[2018.12.12 04:12:00 | 003,392,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2018.12.12 04:11:59 | 006,032,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2018.12.12 04:11:59 | 003,090,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2018.12.12 04:11:59 | 002,739,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2018.12.12 04:11:59 | 002,364,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OpcServices.dll
[2018.12.12 04:11:58 | 004,789,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2018.12.12 04:11:58 | 004,404,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2018.12.12 04:11:58 | 001,826,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.CloudStore.dll
[2018.12.12 04:11:58 | 001,379,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll
[2018.12.12 04:11:58 | 001,221,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvix64.exe
[2018.12.12 04:11:57 | 009,084,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BingMaps.dll
[2018.12.12 04:11:57 | 004,491,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xpsrchvw.exe
[2018.12.12 04:11:57 | 002,368,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WebRuntimeManager.dll
[2018.12.12 04:11:57 | 002,307,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2018.12.12 04:11:57 | 001,457,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dosvc.dll
[2018.12.12 04:11:57 | 001,040,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ApplyTrustOffline.exe
[2018.12.12 04:11:56 | 005,657,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2018.12.12 04:11:56 | 003,179,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2018.12.12 04:11:56 | 002,966,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdp.dll
[2018.12.12 04:11:56 | 002,892,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32kfull.sys
[2018.12.12 04:11:56 | 002,571,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2018.12.12 04:11:56 | 002,394,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVCORE.DLL
[2018.12.12 04:11:55 | 008,623,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2018.12.12 04:11:55 | 005,883,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mos.dll
[2018.12.12 04:11:55 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll
[2018.12.12 04:11:55 | 002,126,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFramework.dll
[2018.12.12 04:11:55 | 001,030,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvax64.exe
[2018.12.12 04:11:54 | 002,700,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2018.12.12 04:11:54 | 001,613,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3D12.dll
[2018.12.12 04:11:53 | 002,900,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll
[2018.12.12 04:11:53 | 002,224,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kbase.sys
[2018.12.12 04:11:53 | 001,943,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2018.12.12 04:11:53 | 001,786,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntVirtualization.dll
[2018.12.12 04:11:53 | 001,627,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\enterprisecsps.dll
[2018.12.12 04:11:53 | 001,364,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpasvc.dll
[2018.12.12 04:11:53 | 001,188,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2018.12.12 04:11:53 | 000,943,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BingOnlineServices.dll
[2018.12.12 04:11:53 | 000,457,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAudDecMFT.dll
[2018.12.12 04:11:52 | 002,825,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapGeocoder.dll
[2018.12.12 04:11:52 | 002,417,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2018.12.12 04:11:52 | 002,258,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2018.12.12 04:11:52 | 001,487,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InstallService.dll
[2018.12.12 04:11:52 | 001,254,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettings.Handlers.dll
[2018.12.12 04:11:52 | 000,949,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2018.12.12 04:11:52 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2018.12.12 04:11:52 | 000,808,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeManager.dll
[2018.12.12 04:11:52 | 000,704,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2018.12.12 04:11:52 | 000,416,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAudDecMFT.dll
[2018.12.12 04:11:51 | 006,647,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BingMaps.dll
[2018.12.12 04:11:51 | 003,381,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapRouter.dll
[2018.12.12 04:11:51 | 002,173,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.onecore.dll
[2018.12.12 04:11:51 | 002,161,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfsrcsnk.dll
[2018.12.12 04:11:51 | 001,935,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2018.12.12 04:11:51 | 001,454,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdi32full.dll
[2018.12.12 04:11:51 | 001,364,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcastdvruserservice.dll
[2018.12.12 04:11:51 | 001,209,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2018.12.12 04:11:51 | 001,032,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\modernexecserver.dll
[2018.12.12 04:11:51 | 001,023,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ShareHost.dll
[2018.12.12 04:11:51 | 000,884,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapControlCore.dll
[2018.12.12 04:11:50 | 007,987,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2018.12.12 04:11:50 | 002,062,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfsrcsnk.dll
[2018.12.12 04:11:50 | 001,634,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32full.dll
[2018.12.12 04:11:50 | 001,469,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll
[2018.12.12 04:11:50 | 001,299,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3D12.dll
[2018.12.12 04:11:50 | 001,264,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JpMapControl.dll
[2018.12.12 04:11:50 | 001,048,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Internal.Shell.Broker.dll
[2018.12.12 04:11:50 | 000,894,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webplatstorageserver.dll
[2018.12.12 04:11:50 | 000,884,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NMAA.dll
[2018.12.12 04:11:50 | 000,623,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PsmServiceExtHost.dll
[2018.12.12 04:11:50 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\daxexec.dll
[2018.12.12 04:11:50 | 000,491,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2018.12.12 04:11:49 | 003,397,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xpsrchvw.exe
[2018.12.12 04:11:49 | 002,449,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapRouter.dll
[2018.12.12 04:11:49 | 001,661,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GdiPlus.dll
[2018.12.12 04:11:49 | 001,457,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2018.12.12 04:11:49 | 001,257,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2018.12.12 04:11:49 | 001,225,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapsStore.dll
[2018.12.12 04:11:49 | 001,110,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InstallService.dll
[2018.12.12 04:11:49 | 000,930,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WWAHost.exe
[2018.12.12 04:11:49 | 000,823,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.appcore.dll
[2018.12.12 04:11:49 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2018.12.12 04:11:49 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BingOnlineServices.dll
[2018.12.12 04:11:49 | 000,684,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEndpointBuilder.dll
[2018.12.12 04:11:49 | 000,669,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2018.12.12 04:11:49 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EdgeManager.dll
[2018.12.12 04:11:49 | 000,594,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2018.12.12 04:11:49 | 000,577,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SppExtComObj.Exe
[2018.12.12 04:11:49 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BthAvctpSvc.dll
[2018.12.12 04:11:48 | 001,551,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.desktop.dll
[2018.12.12 04:11:48 | 001,422,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntSubsystemController.dll
[2018.12.12 04:11:48 | 001,328,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpx.dll
[2018.12.12 04:11:48 | 001,140,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2018.12.12 04:11:48 | 001,069,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Streaming.dll
[2018.12.12 04:11:48 | 001,038,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVPolicy.dll
[2018.12.12 04:11:48 | 000,982,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2018.12.12 04:11:48 | 000,829,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WWAHost.exe
[2018.12.12 04:11:48 | 000,795,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2018.12.12 04:11:48 | 000,777,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2018.12.12 04:11:48 | 000,766,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2018.12.12 04:11:48 | 000,723,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2018.12.12 04:11:48 | 000,550,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2018.12.12 04:11:48 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2018.12.12 04:11:48 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BTAGService.dll
[2018.12.12 04:11:48 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgeIso.dll
[2018.12.12 04:11:48 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll
[2018.12.12 04:11:47 | 001,986,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapGeocoder.dll
[2018.12.12 04:11:47 | 001,627,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVIntegration.dll
[2018.12.12 04:11:47 | 001,535,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2018.12.12 04:11:47 | 001,063,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecConfig.efi
[2018.12.12 04:11:47 | 000,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JpMapControl.dll
[2018.12.12 04:11:47 | 000,848,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ShareHost.dll
[2018.12.12 04:11:47 | 000,830,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVOrchestration.dll
[2018.12.12 04:11:47 | 000,793,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms2.sys
[2018.12.12 04:11:47 | 000,750,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVReporting.dll
[2018.12.12 04:11:47 | 000,693,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.Connectivity.dll
[2018.12.12 04:11:47 | 000,665,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2018.12.12 04:11:47 | 000,645,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2018.12.12 04:11:47 | 000,604,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\securekernel.exe
[2018.12.12 04:11:47 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcblaunch.exe
[2018.12.12 04:11:47 | 000,561,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2018.12.12 04:11:47 | 000,549,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppResolver.dll
[2018.12.12 04:11:47 | 000,537,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2018.12.12 04:11:47 | 000,419,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eeprov.dll
[2018.12.12 04:11:47 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\daxexec.dll
[2018.12.12 04:11:47 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.System.Diagnostics.dll
[2018.12.12 04:11:47 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ninput.dll
[2018.12.12 04:11:47 | 000,268,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserbroker.dll
[2018.12.12 04:11:47 | 000,260,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2018.12.12 04:11:47 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll
[2018.12.12 04:11:46 | 001,348,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OpcServices.dll
[2018.12.12 04:11:46 | 001,150,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVP9DEC.dll
[2018.12.12 04:11:46 | 000,954,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVManifest.dll
[2018.12.12 04:11:46 | 000,895,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Security.Authentication.OnlineId.dll
[2018.12.12 04:11:46 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NMAA.dll
[2018.12.12 04:11:46 | 000,705,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapControlCore.dll
[2018.12.12 04:11:46 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.appcore.dll
[2018.12.12 04:11:46 | 000,670,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVCatalog.dll
[2018.12.12 04:11:46 | 000,573,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2018.12.12 04:11:46 | 000,565,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS
[2018.12.12 04:11:46 | 000,530,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapConfiguration.dll
[2018.12.12 04:11:46 | 000,527,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2018.12.12 04:11:46 | 000,495,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TransportDSA.dll
[2018.12.12 04:11:46 | 000,444,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppResolver.dll
[2018.12.12 04:11:46 | 000,399,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVScripting.dll
[2018.12.12 04:11:46 | 000,368,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2018.12.12 04:11:46 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wc_storage.dll
[2018.12.12 04:11:46 | 000,272,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SgrmEnclave.dll
[2018.12.12 04:11:46 | 000,269,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SgrmEnclave_secure.dll
[2018.12.12 04:11:46 | 000,158,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vertdll.dll
[2018.12.12 04:11:46 | 000,130,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rmclient.dll
[2018.12.12 04:11:46 | 000,129,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2018.12.12 04:11:46 | 000,092,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bindflt.sys
[2018.12.12 04:11:45 | 002,590,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2018.12.12 04:11:45 | 001,397,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVP9DEC.dll
[2018.12.12 04:11:45 | 001,308,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVPXENC.dll
[2018.12.12 04:11:45 | 001,295,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVPXENC.dll
[2018.12.12 04:11:45 | 000,825,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntStreamingManager.dll
[2018.12.12 04:11:45 | 000,796,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2018.12.12 04:11:45 | 000,652,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVPublishing.dll
[2018.12.12 04:11:45 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webplatstorageserver.dll
[2018.12.12 04:11:45 | 000,567,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CoreMessaging.dll
[2018.12.12 04:11:45 | 000,555,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.Connectivity.dll
[2018.12.12 04:11:45 | 000,471,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AcSpecfc.dll
[2018.12.12 04:11:45 | 000,421,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xbgmengine.dll
[2018.12.12 04:11:45 | 000,413,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2018.12.12 04:11:45 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dusmsvc.dll
[2018.12.12 04:11:45 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgeIso.dll
[2018.12.12 04:11:45 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ninput.dll
[2018.12.12 04:11:45 | 000,304,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mssecflt.sys
[2018.12.12 04:11:45 | 000,249,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\weretw.dll
[2018.12.12 04:11:45 | 000,231,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVShNotify.exe
[2018.12.12 04:11:45 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appsruprov.dll
[2018.12.12 04:11:45 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvloader.dll
[2018.12.12 04:11:45 | 000,128,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tm.sys
[2018.12.12 04:11:45 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rmclient.dll
[2018.12.12 04:11:45 | 000,076,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hvservice.sys
[2018.12.12 04:11:45 | 000,058,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\iorate.sys
[2018.12.12 04:11:44 | 001,708,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSPhotography.dll
[2018.12.12 04:11:44 | 001,018,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ClipSp.sys
[2018.12.12 04:11:44 | 000,885,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CoreMessaging.dll
[2018.12.12 04:11:44 | 000,873,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Streaming.dll
[2018.12.12 04:11:44 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2018.12.12 04:11:44 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcext.dll
[2018.12.12 04:11:44 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2018.12.12 04:11:44 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdedit.exe
[2018.12.12 04:11:44 | 000,413,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2018.12.12 04:11:44 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2018.12.12 04:11:44 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Search.ProtocolHandler.MAPI2.dll
[2018.12.12 04:11:44 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapConfiguration.dll
[2018.12.12 04:11:44 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bcryptprimitives.dll
[2018.12.12 04:11:44 | 000,335,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\moshostcore.dll
[2018.12.12 04:11:44 | 000,311,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.System.Diagnostics.dll
[2018.12.12 04:11:44 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Search.ProtocolHandler.MAPI2.dll
[2018.12.12 04:11:44 | 000,258,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVFileSystemMetadata.dll
[2018.12.12 04:11:44 | 000,228,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVStreamMap.dll
[2018.12.12 04:11:44 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2018.12.12 04:11:44 | 000,201,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVStreamingUX.dll
[2018.12.12 04:11:44 | 000,180,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVDllSurrogate.exe
[2018.12.12 04:11:44 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2018.12.12 04:11:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2018.12.12 04:11:44 | 000,173,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVNice.exe
[2018.12.12 04:11:44 | 000,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\energyprov.dll
[2018.12.12 04:11:44 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2018.12.12 04:11:44 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserDataTimeUtil.dll
[2018.12.12 04:11:44 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bthhfenum.sys
[2018.12.12 04:11:44 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSoftwareInstallationClient.dll
[2018.12.12 04:11:44 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UserDataTimeUtil.dll
[2018.12.12 04:11:44 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wcnfs.sys
[2018.12.12 04:11:44 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\offreg.dll
[2018.12.12 04:11:44 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdBth.dll
[2018.12.12 04:11:44 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\offreg.dll
[2018.12.12 04:11:44 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdBth.dll
[2018.12.12 04:11:44 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browser_broker.exe
[2018.12.12 04:11:44 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mmcss.sys
[2018.12.12 04:11:44 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpnsruprov.dll
[2018.12.12 04:11:44 | 000,022,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hvsicontainerservice.dll
[2018.12.12 04:11:43 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2018.12.12 04:11:43 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storqosflt.sys
[2018.12.12 04:11:42 | 001,361,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSPhotography.dll
[2018.12.12 04:11:42 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2018.12.12 04:11:42 | 000,358,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DataUsageHandlers.dll
[2018.12.12 04:11:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\domgmt.dll
[2018.12.12 04:11:42 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msIso.dll
[2018.12.12 04:11:42 | 000,209,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXApplicabilityBlob.dll
[2018.12.12 04:11:42 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InstallServiceTasks.dll
[2018.12.12 04:11:42 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Chakradiag.dll
[2018.12.12 04:11:42 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMapi.dll
[2018.12.12 04:11:42 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InstallServiceTasks.dll
[2018.12.12 04:11:42 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Internal.Management.SecureAssessment.dll
[2018.12.12 04:11:42 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DataUsageLiveTileTask.exe
[2018.12.12 04:11:42 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\utcutil.dll
[2018.12.12 04:11:42 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winhttpcom.dll
[2018.12.12 04:11:42 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tzautoupdate.dll
[2018.12.12 04:11:42 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFrameworkInternalPS.dll
[2018.12.12 04:11:42 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winhttpcom.dll
[2018.12.12 04:11:42 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dtdump.exe
[2018.12.12 04:11:42 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iemigplugin.dll
[2018.12.12 04:11:42 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2018.12.12 04:11:42 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\werdiagcontroller.dll
[2018.12.11 20:41:37 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\ProtonVPN
[2018.12.11 20:41:31 | 000,000,000 | ---D | C] -- C:\ProgramData\ProtonVPN
[2018.12.11 20:41:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProtonVPN
[2018.12.11 20:41:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Proton Technologies
[2018.12.11 20:41:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\ProtonVPN AG
[2018.12.11 09:46:39 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\gtk-2.0
[2018.12.11 08:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Claws Mail
[2018.12.11 08:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Claws Mail
[2018.12.11 08:22:25 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\claws Mail
[2018.12.11 08:18:34 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Claws-mail
[2018.12.11 06:12:00 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\PyBitmessage
[2018.12.11 04:51:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\kleopatra
[2018.12.11 04:46:10 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\gnupg
[2018.12.11 04:46:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GnuPG
[2018.12.11 04:45:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gpg4win
[2018.12.11 04:29:35 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\PGP
[2018.12.10 23:10:54 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Bishop_Fox
[2018.12.10 23:09:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bishop Fox
[2018.12.10 23:09:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bishop Fox
[2018.12.10 15:20:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2018.12.10 15:19:52 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Sun
[2018.12.10 15:19:42 | 000,110,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2018.12.10 15:19:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Oracle
[2018.12.10 15:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2018.12.10 15:19:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2018.12.10 15:19:24 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2018.12.10 15:10:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\ValidateCreditCard Part5 Code:
========== Files/Folders - Created Within 7 Days ==========
[2018.12.17 02:55:59 | 000,000,000 | ---D | C] -- C:\FRST
[2018.12.17 02:54:19 | 002,417,152 | ---- | C] (Farbar) -- C:\Users\Mortifer\Desktop\FRST64.exe
[2018.12.17 02:20:14 | 005,746,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsDesktopEngine.exe
[2018.12.17 02:20:14 | 004,529,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsDesktopEngine.exe
[2018.12.17 02:20:14 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsProxyStub.dll
[2018.12.17 02:12:57 | 000,845,488 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\Autoruns64.exe
[2018.12.17 02:12:57 | 000,743,600 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\autorunsc64.exe
[2018.12.17 02:12:57 | 000,716,968 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\Autoruns.exe
[2018.12.17 02:12:57 | 000,629,928 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mortifer\Desktop\autorunsc.exe
[2018.12.17 02:07:11 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mortifer\Desktop\OTL.exe
[2018.12.17 02:04:35 | 000,063,768 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
[2018.12.17 02:04:31 | 000,119,136 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\farflt.sys
[2018.12.17 02:04:30 | 000,111,152 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mwac.sys
[2018.12.17 01:28:24 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\backups
[2018.12.17 01:20:04 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Mortifer\Desktop\HijackThis.exe
[2018.12.17 01:10:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2018.12.17 01:10:07 | 000,032,168 | ---- | C] (Safer-Networking Ltd.) -- C:\Windows\SysNative\sdnclean64.exe
[2018.12.17 01:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2018.12.17 01:10:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2018.12.17 00:49:55 | 000,260,480 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018.12.17 00:47:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2018.12.17 00:46:54 | 007,321,808 | ---- | C] (Malwarebytes) -- C:\Users\Mortifer\Desktop\adwcleaner_7.2.5.0.exe
[2018.12.17 00:30:12 | 000,198,000 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\MbamChameleon.sys
[2018.12.17 00:25:57 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Visual Studio 2017
[2018.12.17 00:25:46 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Python Scripts
[2018.12.17 00:25:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anaconda3 (64-bit)
[2018.12.17 00:14:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.6
[2018.12.17 00:14:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Package Cache
[2018.12.17 00:14:11 | 000,000,000 | ---D | C] -- C:\Program Files\IIS
[2018.12.17 00:14:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS
[2018.12.17 00:13:59 | 000,000,000 | ---D | C] -- C:\Program Files\VS2012Schemas
[2018.12.17 00:13:59 | 000,000,000 | ---D | C] -- C:\Program Files\VS2010Schemas
[2018.12.17 00:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\dftmp
[2018.12.17 00:13:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Azure
[2018.12.17 00:13:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2018.12.17 00:13:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Phone Kits
[2018.12.17 00:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
[2018.12.17 00:01:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2018.12.17 00:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows App Certification Kit
[2018.12.17 00:00:35 | 000,000,000 | ---D | C] -- C:\Program Files\Application Verifier
[2018.12.17 00:00:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Verifier
[2018.12.16 23:55:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTML Help Workshop
[2018.12.16 23:55:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
[2018.12.16 23:55:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2018.12.16 23:55:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Kits
[2018.12.16 23:48:23 | 017,871,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXCaptureReplay.dll
[2018.12.16 23:48:23 | 014,058,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXCaptureReplay.dll
[2018.12.16 23:48:23 | 004,858,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsRemoteEngine.exe
[2018.12.16 23:48:23 | 003,632,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsRemoteEngine.exe
[2018.12.16 23:48:23 | 002,818,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d12SDKLayers.dll
[2018.12.16 23:48:23 | 002,249,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d12SDKLayers.dll
[2018.12.16 23:48:23 | 002,000,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsOfflineAnalysis.dll
[2018.12.16 23:48:23 | 001,500,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsOfflineAnalysis.dll
[2018.12.16 23:48:23 | 001,359,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11_3SDKLayers.dll
[2018.12.16 23:48:23 | 001,178,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXCap.exe
[2018.12.16 23:48:23 | 001,100,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11_3SDKLayers.dll
[2018.12.16 23:48:23 | 000,921,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXCap.exe
[2018.12.16 23:48:23 | 000,539,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1debug3.dll
[2018.12.16 23:48:23 | 000,466,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1debug3.dll
[2018.12.16 23:48:23 | 000,402,944 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\DXCpl.exe
[2018.12.16 23:48:23 | 000,380,416 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysWow64\DXCpl.exe
[2018.12.16 23:48:23 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perf_gputiming.dll
[2018.12.16 23:48:23 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXGIDebug.dll
[2018.12.16 23:48:23 | 000,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsExperiment.dll
[2018.12.16 23:48:23 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perf_gputiming.dll
[2018.12.16 23:48:23 | 000,238,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXGIDebug.dll
[2018.12.16 23:48:23 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsExperiment.dll
[2018.12.16 23:48:23 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsMonitor.dll
[2018.12.16 23:48:23 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DXToolsReporting.dll
[2018.12.16 23:48:23 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VsGraphicsCapture.dll
[2018.12.16 23:48:23 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsMonitor.dll
[2018.12.16 23:48:23 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsCapture.dll
[2018.12.16 23:48:23 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DXToolsReporting.dll
[2018.12.16 23:48:23 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DxToolsReportGenerator.dll
[2018.12.16 23:48:23 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DxToolsReportGenerator.dll
[2018.12.16 23:48:23 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VSD3DWARPDebug.dll
[2018.12.16 23:48:23 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VSD3DWARPDebug.dll
[2018.12.16 23:48:23 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VsGraphicsProxyStub.dll
[2018.12.16 23:45:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Web Tools
[2018.12.16 23:42:54 | 000,000,000 | ---D | C] -- C:\Program Files\IIS Express
[2018.12.16 23:42:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS Express
[2018.12.16 23:42:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ASP.NET Core Runtime Package Store
[2018.12.16 23:42:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NuGet
[2018.12.16 23:41:50 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.dotnet
[2018.12.16 23:41:06 | 000,000,000 | ---D | C] -- C:\Program Files\dotnet
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\3082
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\3082
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\2052
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\2052
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1055
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1055
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1049
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1049
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1046
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1046
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1045
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1045
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1042
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1042
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1041
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1041
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1040
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1040
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1036
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1036
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1031
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1031
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1029
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1029
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1028
[2018.12.16 23:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1028
[2018.12.16 23:38:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Entity Framework Tools
[2018.12.16 23:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2018.12.16 23:35:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2018.12.16 23:34:59 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Kits
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
[2018.12.16 23:34:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Designer
[2018.12.16 23:34:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\vstelemetry
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Visual Studio Setup
[2018.12.16 23:18:26 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\ServiceHub
[2018.12.16 23:18:25 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Microsoft Visual Studio
[2018.12.16 23:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2018.12.16 23:17:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Visual Studio
[2018.12.16 23:16:27 | 001,281,536 | ---- | C] (Microsoft Corporation) -- C:\Users\Mortifer\Documents\vs_community.exe
[2018.12.16 21:26:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Netflix Checker Pack Moataz
[2018.12.16 21:21:03 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\All-in-One Checker
[2018.12.16 21:18:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\Mail-Checker-2.0.0.1_1
[2018.12.16 14:55:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nmap
[2018.12.16 14:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Npcap
[2018.12.16 14:53:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Npcap
[2018.12.16 14:53:40 | 000,000,000 | ---D | C] -- C:\Program Files\Npcap
[2018.12.16 14:52:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nmap
[2018.12.16 07:03:13 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Documents\BlackBullet
[2018.12.16 03:43:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\olly
[2018.12.16 01:07:02 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.pylint.d
[2018.12.16 01:00:32 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Python
[2018.12.16 01:00:24 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\pip
[2018.12.16 00:58:39 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\.idlerc
[2018.12.16 00:18:00 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\AVAST Software
[2018.12.16 00:17:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVAST Software
[2018.12.16 00:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2018.12.15 12:11:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\assembly
[2018.12.15 11:18:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Deployment
[2018.12.15 11:18:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Apps
[2018.12.15 02:43:48 | 000,000,000 | ---D | C] -- C:\Python35
[2018.12.14 17:41:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2018.12.14 10:01:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Thunderbird
[2018.12.14 10:01:09 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Thunderbird
[2018.12.12 10:20:24 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2018.12.12 04:12:16 | 007,520,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Protection.PlayReady.dll
[2018.12.12 04:12:16 | 006,569,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Protection.PlayReady.dll
[2018.12.12 04:12:14 | 025,855,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgehtml.dll
[2018.12.12 04:12:07 | 022,016,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgehtml.dll
[2018.12.12 04:12:06 | 009,084,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2018.12.12 04:12:06 | 007,436,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\windows.storage.dll
[2018.12.12 04:12:06 | 001,213,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ClipUp.exe
[2018.12.12 04:12:05 | 007,573,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Chakra.dll
[2018.12.12 04:12:05 | 005,625,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StartTileData.dll
[2018.12.12 04:12:05 | 001,616,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll
[2018.12.12 04:12:04 | 006,043,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\windows.storage.dll
[2018.12.12 04:12:04 | 004,710,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdp.dll
[2018.12.12 04:12:04 | 003,396,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2018.12.12 04:12:03 | 013,572,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2018.12.12 04:12:03 | 012,500,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2018.12.12 04:12:02 | 007,057,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mos.dll
[2018.12.12 04:12:02 | 005,775,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Chakra.dll
[2018.12.12 04:12:02 | 001,017,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2adec.dll
[2018.12.12 04:12:01 | 004,866,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2018.12.12 04:12:01 | 004,708,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.pcshell.dll
[2018.12.12 04:12:01 | 004,384,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeContent.dll
[2018.12.12 04:12:01 | 002,371,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2018.12.12 04:12:01 | 002,331,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll
[2018.12.12 04:12:01 | 000,861,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2adec.dll
[2018.12.12 04:12:00 | 006,586,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2018.12.12 04:12:00 | 003,649,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kfull.sys
[2018.12.12 04:12:00 | 003,392,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2018.12.12 04:11:59 | 006,032,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2018.12.12 04:11:59 | 003,090,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2018.12.12 04:11:59 | 002,739,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2018.12.12 04:11:59 | 002,364,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OpcServices.dll
[2018.12.12 04:11:58 | 004,789,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2018.12.12 04:11:58 | 004,404,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2018.12.12 04:11:58 | 001,826,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.CloudStore.dll
[2018.12.12 04:11:58 | 001,379,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll
[2018.12.12 04:11:58 | 001,221,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvix64.exe
[2018.12.12 04:11:57 | 009,084,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BingMaps.dll
[2018.12.12 04:11:57 | 004,491,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xpsrchvw.exe
[2018.12.12 04:11:57 | 002,368,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WebRuntimeManager.dll
[2018.12.12 04:11:57 | 002,307,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2018.12.12 04:11:57 | 001,457,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dosvc.dll
[2018.12.12 04:11:57 | 001,040,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ApplyTrustOffline.exe
[2018.12.12 04:11:56 | 005,657,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2018.12.12 04:11:56 | 003,179,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2018.12.12 04:11:56 | 002,966,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdp.dll
[2018.12.12 04:11:56 | 002,892,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32kfull.sys
[2018.12.12 04:11:56 | 002,571,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2018.12.12 04:11:56 | 002,394,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVCORE.DLL
[2018.12.12 04:11:55 | 008,623,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2018.12.12 04:11:55 | 005,883,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mos.dll
[2018.12.12 04:11:55 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll
[2018.12.12 04:11:55 | 002,126,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFramework.dll
[2018.12.12 04:11:55 | 001,030,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvax64.exe
[2018.12.12 04:11:54 | 002,700,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2018.12.12 04:11:54 | 001,613,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3D12.dll
[2018.12.12 04:11:53 | 002,900,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll
[2018.12.12 04:11:53 | 002,224,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32kbase.sys
[2018.12.12 04:11:53 | 001,943,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2018.12.12 04:11:53 | 001,786,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntVirtualization.dll
[2018.12.12 04:11:53 | 001,627,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\enterprisecsps.dll
[2018.12.12 04:11:53 | 001,364,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpasvc.dll
[2018.12.12 04:11:53 | 001,188,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2018.12.12 04:11:53 | 000,943,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BingOnlineServices.dll
[2018.12.12 04:11:53 | 000,457,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAudDecMFT.dll
[2018.12.12 04:11:52 | 002,825,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapGeocoder.dll
[2018.12.12 04:11:52 | 002,417,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2018.12.12 04:11:52 | 002,258,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2018.12.12 04:11:52 | 001,487,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InstallService.dll
[2018.12.12 04:11:52 | 001,254,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemSettings.Handlers.dll
[2018.12.12 04:11:52 | 000,949,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2018.12.12 04:11:52 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2018.12.12 04:11:52 | 000,808,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EdgeManager.dll
[2018.12.12 04:11:52 | 000,704,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2018.12.12 04:11:52 | 000,416,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAudDecMFT.dll
[2018.12.12 04:11:51 | 006,647,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BingMaps.dll
[2018.12.12 04:11:51 | 003,381,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapRouter.dll
[2018.12.12 04:11:51 | 002,173,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.onecore.dll
[2018.12.12 04:11:51 | 002,161,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfsrcsnk.dll
[2018.12.12 04:11:51 | 001,935,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2018.12.12 04:11:51 | 001,454,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdi32full.dll
[2018.12.12 04:11:51 | 001,364,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcastdvruserservice.dll
[2018.12.12 04:11:51 | 001,209,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2018.12.12 04:11:51 | 001,032,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\modernexecserver.dll
[2018.12.12 04:11:51 | 001,023,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ShareHost.dll
[2018.12.12 04:11:51 | 000,884,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapControlCore.dll
[2018.12.12 04:11:50 | 007,987,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2018.12.12 04:11:50 | 002,062,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfsrcsnk.dll
[2018.12.12 04:11:50 | 001,634,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32full.dll
[2018.12.12 04:11:50 | 001,469,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll
[2018.12.12 04:11:50 | 001,299,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3D12.dll
[2018.12.12 04:11:50 | 001,264,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JpMapControl.dll
[2018.12.12 04:11:50 | 001,048,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Internal.Shell.Broker.dll
[2018.12.12 04:11:50 | 000,894,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webplatstorageserver.dll
[2018.12.12 04:11:50 | 000,884,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NMAA.dll
[2018.12.12 04:11:50 | 000,623,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PsmServiceExtHost.dll
[2018.12.12 04:11:50 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\daxexec.dll
[2018.12.12 04:11:50 | 000,491,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2018.12.12 04:11:49 | 003,397,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xpsrchvw.exe
[2018.12.12 04:11:49 | 002,449,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapRouter.dll
[2018.12.12 04:11:49 | 001,661,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GdiPlus.dll
[2018.12.12 04:11:49 | 001,457,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2018.12.12 04:11:49 | 001,257,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2018.12.12 04:11:49 | 001,225,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapsStore.dll
[2018.12.12 04:11:49 | 001,110,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InstallService.dll
[2018.12.12 04:11:49 | 000,930,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WWAHost.exe
[2018.12.12 04:11:49 | 000,823,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.appcore.dll
[2018.12.12 04:11:49 | 000,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2018.12.12 04:11:49 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BingOnlineServices.dll
[2018.12.12 04:11:49 | 000,684,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEndpointBuilder.dll
[2018.12.12 04:11:49 | 000,669,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2018.12.12 04:11:49 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EdgeManager.dll
[2018.12.12 04:11:49 | 000,594,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2018.12.12 04:11:49 | 000,577,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SppExtComObj.Exe
[2018.12.12 04:11:49 | 000,399,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BthAvctpSvc.dll
[2018.12.12 04:11:48 | 001,551,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.desktop.dll
[2018.12.12 04:11:48 | 001,422,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntSubsystemController.dll
[2018.12.12 04:11:48 | 001,328,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpx.dll
[2018.12.12 04:11:48 | 001,140,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2018.12.12 04:11:48 | 001,069,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Streaming.dll
[2018.12.12 04:11:48 | 001,038,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVPolicy.dll
[2018.12.12 04:11:48 | 000,982,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2018.12.12 04:11:48 | 000,829,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WWAHost.exe
[2018.12.12 04:11:48 | 000,795,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2018.12.12 04:11:48 | 000,777,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2018.12.12 04:11:48 | 000,766,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2018.12.12 04:11:48 | 000,723,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2018.12.12 04:11:48 | 000,550,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2018.12.12 04:11:48 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2018.12.12 04:11:48 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BTAGService.dll
[2018.12.12 04:11:48 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\edgeIso.dll
[2018.12.12 04:11:48 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll
[2018.12.12 04:11:47 | 001,986,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapGeocoder.dll
[2018.12.12 04:11:47 | 001,627,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVIntegration.dll
[2018.12.12 04:11:47 | 001,535,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2018.12.12 04:11:47 | 001,063,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SecConfig.efi
[2018.12.12 04:11:47 | 000,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JpMapControl.dll
[2018.12.12 04:11:47 | 000,848,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ShareHost.dll
[2018.12.12 04:11:47 | 000,830,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVOrchestration.dll
[2018.12.12 04:11:47 | 000,793,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms2.sys
[2018.12.12 04:11:47 | 000,750,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVReporting.dll
[2018.12.12 04:11:47 | 000,693,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.Connectivity.dll
[2018.12.12 04:11:47 | 000,665,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2018.12.12 04:11:47 | 000,645,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2018.12.12 04:11:47 | 000,604,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\securekernel.exe
[2018.12.12 04:11:47 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcblaunch.exe
[2018.12.12 04:11:47 | 000,561,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2018.12.12 04:11:47 | 000,549,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppResolver.dll
[2018.12.12 04:11:47 | 000,537,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2018.12.12 04:11:47 | 000,419,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eeprov.dll
[2018.12.12 04:11:47 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\daxexec.dll
[2018.12.12 04:11:47 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.System.Diagnostics.dll
[2018.12.12 04:11:47 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ninput.dll
[2018.12.12 04:11:47 | 000,268,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserbroker.dll
[2018.12.12 04:11:47 | 000,260,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2018.12.12 04:11:47 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll
[2018.12.12 04:11:46 | 001,348,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OpcServices.dll
[2018.12.12 04:11:46 | 001,150,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVP9DEC.dll
[2018.12.12 04:11:46 | 000,954,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVManifest.dll
[2018.12.12 04:11:46 | 000,895,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Security.Authentication.OnlineId.dll
[2018.12.12 04:11:46 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NMAA.dll
[2018.12.12 04:11:46 | 000,705,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapControlCore.dll
[2018.12.12 04:11:46 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.appcore.dll
[2018.12.12 04:11:46 | 000,670,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVCatalog.dll
[2018.12.12 04:11:46 | 000,573,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2018.12.12 04:11:46 | 000,565,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS
[2018.12.12 04:11:46 | 000,530,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MapConfiguration.dll
[2018.12.12 04:11:46 | 000,527,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2018.12.12 04:11:46 | 000,495,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TransportDSA.dll
[2018.12.12 04:11:46 | 000,444,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppResolver.dll
[2018.12.12 04:11:46 | 000,399,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVScripting.dll
[2018.12.12 04:11:46 | 000,368,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2018.12.12 04:11:46 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wc_storage.dll
[2018.12.12 04:11:46 | 000,272,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SgrmEnclave.dll
[2018.12.12 04:11:46 | 000,269,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SgrmEnclave_secure.dll
[2018.12.12 04:11:46 | 000,158,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vertdll.dll
[2018.12.12 04:11:46 | 000,130,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rmclient.dll
[2018.12.12 04:11:46 | 000,129,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2018.12.12 04:11:46 | 000,092,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bindflt.sys
[2018.12.12 04:11:45 | 002,590,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2018.12.12 04:11:45 | 001,397,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVP9DEC.dll
[2018.12.12 04:11:45 | 001,308,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVPXENC.dll
[2018.12.12 04:11:45 | 001,295,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVPXENC.dll
[2018.12.12 04:11:45 | 000,825,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVEntStreamingManager.dll
[2018.12.12 04:11:45 | 000,796,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2018.12.12 04:11:45 | 000,652,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVPublishing.dll
[2018.12.12 04:11:45 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webplatstorageserver.dll
[2018.12.12 04:11:45 | 000,567,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CoreMessaging.dll
[2018.12.12 04:11:45 | 000,555,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.Connectivity.dll
[2018.12.12 04:11:45 | 000,471,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AcSpecfc.dll
[2018.12.12 04:11:45 | 000,421,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xbgmengine.dll
[2018.12.12 04:11:45 | 000,413,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2018.12.12 04:11:45 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dusmsvc.dll
[2018.12.12 04:11:45 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\edgeIso.dll
[2018.12.12 04:11:45 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ninput.dll
[2018.12.12 04:11:45 | 000,304,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mssecflt.sys
[2018.12.12 04:11:45 | 000,249,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\weretw.dll
[2018.12.12 04:11:45 | 000,231,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVShNotify.exe
[2018.12.12 04:11:45 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appsruprov.dll
[2018.12.12 04:11:45 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hvloader.dll
[2018.12.12 04:11:45 | 000,128,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tm.sys
[2018.12.12 04:11:45 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rmclient.dll
[2018.12.12 04:11:45 | 000,076,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hvservice.sys
[2018.12.12 04:11:45 | 000,058,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\iorate.sys
[2018.12.12 04:11:44 | 001,708,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSPhotography.dll
[2018.12.12 04:11:44 | 001,018,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ClipSp.sys
[2018.12.12 04:11:44 | 000,885,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CoreMessaging.dll
[2018.12.12 04:11:44 | 000,873,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Streaming.dll
[2018.12.12 04:11:44 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2018.12.12 04:11:44 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcext.dll
[2018.12.12 04:11:44 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2018.12.12 04:11:44 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcdedit.exe
[2018.12.12 04:11:44 | 000,413,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2018.12.12 04:11:44 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2018.12.12 04:11:44 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Search.ProtocolHandler.MAPI2.dll
[2018.12.12 04:11:44 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MapConfiguration.dll
[2018.12.12 04:11:44 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bcryptprimitives.dll
[2018.12.12 04:11:44 | 000,335,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\moshostcore.dll
[2018.12.12 04:11:44 | 000,311,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.System.Diagnostics.dll
[2018.12.12 04:11:44 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Search.ProtocolHandler.MAPI2.dll
[2018.12.12 04:11:44 | 000,258,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVFileSystemMetadata.dll
[2018.12.12 04:11:44 | 000,228,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVStreamMap.dll
[2018.12.12 04:11:44 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2018.12.12 04:11:44 | 000,201,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVStreamingUX.dll
[2018.12.12 04:11:44 | 000,180,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVDllSurrogate.exe
[2018.12.12 04:11:44 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2018.12.12 04:11:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2018.12.12 04:11:44 | 000,173,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppVNice.exe
[2018.12.12 04:11:44 | 000,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\energyprov.dll
[2018.12.12 04:11:44 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2018.12.12 04:11:44 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UserDataTimeUtil.dll
[2018.12.12 04:11:44 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\bthhfenum.sys
[2018.12.12 04:11:44 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSoftwareInstallationClient.dll
[2018.12.12 04:11:44 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UserDataTimeUtil.dll
[2018.12.12 04:11:44 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wcnfs.sys
[2018.12.12 04:11:44 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\offreg.dll
[2018.12.12 04:11:44 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdBth.dll
[2018.12.12 04:11:44 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\offreg.dll
[2018.12.12 04:11:44 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdBth.dll
[2018.12.12 04:11:44 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browser_broker.exe
[2018.12.12 04:11:44 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mmcss.sys
[2018.12.12 04:11:44 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpnsruprov.dll
[2018.12.12 04:11:44 | 000,022,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hvsicontainerservice.dll
[2018.12.12 04:11:43 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2018.12.12 04:11:43 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storqosflt.sys
[2018.12.12 04:11:42 | 001,361,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSPhotography.dll
[2018.12.12 04:11:42 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2018.12.12 04:11:42 | 000,358,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DataUsageHandlers.dll
[2018.12.12 04:11:42 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\domgmt.dll
[2018.12.12 04:11:42 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msIso.dll
[2018.12.12 04:11:42 | 000,209,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXApplicabilityBlob.dll
[2018.12.12 04:11:42 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InstallServiceTasks.dll
[2018.12.12 04:11:42 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Chakradiag.dll
[2018.12.12 04:11:42 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMapi.dll
[2018.12.12 04:11:42 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InstallServiceTasks.dll
[2018.12.12 04:11:42 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Internal.Management.SecureAssessment.dll
[2018.12.12 04:11:42 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DataUsageLiveTileTask.exe
[2018.12.12 04:11:42 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\utcutil.dll
[2018.12.12 04:11:42 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winhttpcom.dll
[2018.12.12 04:11:42 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tzautoupdate.dll
[2018.12.12 04:11:42 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationFrameworkInternalPS.dll
[2018.12.12 04:11:42 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winhttpcom.dll
[2018.12.12 04:11:42 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dtdump.exe
[2018.12.12 04:11:42 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iemigplugin.dll
[2018.12.12 04:11:42 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2018.12.12 04:11:42 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\werdiagcontroller.dll
[2018.12.11 20:41:37 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\ProtonVPN
[2018.12.11 20:41:31 | 000,000,000 | ---D | C] -- C:\ProgramData\ProtonVPN
[2018.12.11 20:41:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProtonVPN
[2018.12.11 20:41:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Proton Technologies
[2018.12.11 20:41:05 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\ProtonVPN AG
[2018.12.11 09:46:39 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\gtk-2.0
[2018.12.11 08:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Claws Mail
[2018.12.11 08:35:20 | 000,000,000 | ---D | C] -- C:\Program Files\Claws Mail
[2018.12.11 08:22:25 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\claws Mail
[2018.12.11 08:18:34 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Claws-mail
[2018.12.11 06:12:00 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\PyBitmessage
[2018.12.11 04:51:20 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\kleopatra
[2018.12.11 04:46:10 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\gnupg
[2018.12.11 04:46:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GnuPG
[2018.12.11 04:45:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gpg4win
[2018.12.11 04:29:35 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\PGP
[2018.12.10 23:10:54 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Local\Bishop_Fox
[2018.12.10 23:09:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bishop Fox
[2018.12.10 23:09:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bishop Fox
[2018.12.10 15:20:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2018.12.10 15:19:52 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\AppData\Roaming\Sun
[2018.12.10 15:19:42 | 000,110,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2018.12.10 15:19:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Oracle
[2018.12.10 15:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2018.12.10 15:19:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2018.12.10 15:19:24 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2018.12.10 15:10:28 | 000,000,000 | ---D | C] -- C:\Users\Mortifer\Desktop\ValidateCreditCard |