こんにちは。
Orbitumの兆候は今のところないです。
以下ログです。
OTL logfile created on: 2017/04/21 12:54:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\panda\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.14393.0)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd
3.47 Gb Total Physical Memory | 1.99 Gb Available Physical Memory | 57.45% Memory free
5.72 Gb Paging File | 3.25 Gb Available in Paging File | 56.85% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.01 Gb Total Space | 410.46 Gb Free Space | 91.21% Space Free | Partition Type: NTFS
Drive D: | 14.52 Gb Total Space | 1.73 Gb Free Space | 11.93% Space Free | Partition Type: NTFS
Computer Name: LAPTOP-5RUSGJES | User Name: panda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - File not found --
PRC - [2017/04/21 12:53:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\panda\Desktop\OTL.exe
PRC - [2017/04/14 15:16:27 | 001,518,808 | ---- | M] (Microsoft Corporation) -- C:\Users\panda\AppData\Local\Microsoft\OneDrive\OneDrive.exe
PRC - [2017/03/15 13:42:58 | 001,062,392 | ---- | M] (HP Inc.) -- C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
PRC - [2017/02/06 15:20:04 | 000,630,776 | ---- | M] (HP Inc.) -- C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
PRC - [2017/02/01 11:38:43 | 000,143,144 | ---- | M] (Dropbox, Inc.) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
PRC - [2016/10/17 20:01:20 | 000,051,224 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWOW64\tbaseprovisioning.exe
PRC - [2016/10/04 17:17:06 | 001,657,880 | ---- | M] (HP Inc.) -- C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
PRC - [2016/08/05 14:42:58 | 000,843,800 | ---- | M] () -- C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartProvider.exe
PRC - [2016/08/05 14:41:58 | 000,461,848 | ---- | M] (HP Inc.) -- c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
PRC - [2016/06/03 22:08:04 | 001,031,704 | ---- | M] (HP) -- C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2017/04/14 01:11:47 | 001,161,728 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\4979591369179732bf744077fdf32393\System.Management.ni.dll
MOD - [2017/04/11 10:35:02 | 000,184,320 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\b02077014cbc9078ead7391e8ee5fbe6\UIAutomationTypes.ni.dll
MOD - [2017/04/11 10:34:34 | 000,386,048 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\dae0ac7f10d617d2fe72df6c6f23d3c5\System.Dynamic.ni.dll
MOD - [2017/04/11 10:34:33 | 001,589,760 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\1603e15bfa4813f780ef8dfb1291da1b\Microsoft.CSharp.ni.dll
MOD - [2017/04/11 10:33:52 | 000,794,624 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\7f3d8a52d4129497577159cae0ef83b7\System.Runtime.Remoting.ni.dll
MOD - [2017/04/11 10:33:47 | 007,882,752 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\79892cb4ea3329381a2fc51dad52eb6e\System.Data.ni.dll
MOD - [2017/04/11 10:33:13 | 012,992,512 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\68f0c8b24547a1eeafc998eb2b2522e0\System.Windows.Forms.ni.dll
MOD - [2017/04/11 10:32:58 | 001,626,112 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\058e016628ca385ecca0589255c71bce\System.Drawing.ni.dll
MOD - [2017/04/11 10:32:52 | 000,272,896 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\090944cdcbf7fca1c5f201bbf89b224b\System.Numerics.ni.dll
MOD - [2017/04/10 17:07:03 | 000,391,680 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\644006124f267e54cf6760ac688fbf3e\System.Xml.Linq.ni.dll
MOD - [2017/04/10 17:07:02 | 007,456,768 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\cfff018936a7c6348cb7ea98d432343a\System.Xml.ni.dll
MOD - [2017/04/10 17:06:53 | 001,878,528 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\1b30fcb579bbaad955474f384a20d978\System.Xaml.ni.dll
MOD - [2017/04/10 17:06:48 | 002,804,224 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\d5101c374cd436c6638bd68d3e681438\System.Runtime.Serialization.ni.dll
MOD - [2017/04/10 17:06:43 | 000,978,432 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\69bc7c6c084baf2d2ffd6871c726e266\System.Configuration.ni.dll
MOD - [2017/04/10 17:06:42 | 000,529,920 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\3c7b6f1459cd44f3f3f9b59e5121a867\PresentationFramework.Aero2.ni.dll
MOD - [2017/04/10 17:06:40 | 019,470,848 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\5fa817daff10898645f2a4f4514bee62\PresentationFramework.ni.dll
MOD - [2017/04/10 17:06:13 | 011,620,352 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\0e3670b79a0d3cf62dffca3403010d44\PresentationCore.ni.dll
MOD - [2017/04/10 17:05:56 | 004,063,232 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\b87bf6675b253eeea9d7a1af759d1d9b\WindowsBase.ni.dll
MOD - [2017/04/10 17:05:51 | 007,464,448 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\561bcb2835dc3d4de610397aebd07edc\System.Core.ni.dll
MOD - [2017/04/10 17:05:40 | 010,266,112 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System\6d712bf5f07ce74d9e2d31a443dea9c2\System.ni.dll
MOD - [2017/01/24 11:27:50 | 019,611,824 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\f06d35cdb58e63c8a25f1658f23fd20d\mscorlib.ni.dll
MOD - [2016/08/05 14:42:58 | 000,843,800 | ---- | M] () -- C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartProvider.exe
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV - [2017/04/07 04:53:16 | 000,033,640 | ---- | M] (HP Inc.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2017/03/28 15:21:33 | 003,318,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2017/03/28 14:32:32 | 000,298,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Windows.Internal.Management.dll -- (DmEnrollmentSvc)
SRV - [2017/03/28 13:48:06 | 000,483,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\CoreMessaging.dll -- (CoreMessagingRegistrar)
SRV - [2017/03/04 15:16:20 | 000,968,704 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Windows\SysWOW64\Unistore.dll -- (UnistoreSvc)
SRV - [2017/02/06 15:20:04 | 000,630,776 | ---- | M] (HP Inc.) [Auto | Running] -- C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe -- (HPWMISVC)
SRV - [2017/02/01 11:38:43 | 000,143,144 | ---- | M] (Dropbox, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe -- (dbupdatem)
SRV - [2017/02/01 11:38:43 | 000,143,144 | ---- | M] (Dropbox, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe -- (dbupdate)
SRV - [2016/11/11 16:05:12 | 003,370,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\Windows.StateRepository.dll -- (StateRepository)
SRV - [2016/10/17 20:01:20 | 000,051,224 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\tbaseprovisioning.exe -- (tbaseprovisioning)
SRV - [2016/08/06 12:33:24 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2016/08/05 14:41:58 | 000,461,848 | ---- | M] (HP Inc.) [Auto | Running] -- c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe -- (HPJumpStartBridge)
SRV - [2016/07/29 21:38:24 | 000,507,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2016/07/29 21:38:24 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2016/07/29 21:38:24 | 000,057,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2016/06/03 22:08:04 | 001,031,704 | ---- | M] (HP) [On_Demand | Running] -- C:\Program Files (x86)\HP\Shared\hpqwmiex.exe -- (hpqcaslwmiex)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2016/10/17 20:01:45 | 026,565,648 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\windows\System32\DriverStore\FileRepository\c0307840.inf_amd64_2d7ce5e36533f4c7\atikmdag.sys -- (amdkmdag)
DRV - [2016/10/17 20:01:45 | 000,527,264 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\windows\System32\DriverStore\FileRepository\c0307840.inf_amd64_2d7ce5e36533f4c7\atikmpag.sys -- (amdkmdap)
DRV - [2016/07/16 20:41:50 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys -- (CompositeBus)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=PRHPC1&src=IE11TR&pc=HCTE
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://hp17win10.msn.com/?pc=HCTE
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = F2 36 5F 3B E7 7D D2 01 [binary data]
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 25 00 00 00 A8 B2 63 FB A3 52 1C D1 58 39 B2 52 ED 52 50 3A 85 49 0C 89 D1 BB BE E4 E8 B6 BA FC 5E 8A CF FB 4D CA 2F 16 36 02 00 00 00 0E 00 00 00 59 39 64 44 36 48 66 32 4F 53 30 25 33 64 [binary data]
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=PRHPC1&src=IE11TR&pc=HCTE
IE - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\tmbepff@trendmicro.com: C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\firefoxextension [2017/02/07 13:38:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2017/02/03 15:12:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{c2056674-a37f-4b29-9300-2004759d74fe}: C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension\ [2017/02/07 13:40:06 | 000,000,000 | ---D | M]
[color=#E56717]========== Chrome ==========[/color]
CHR - homepage: 16F71CAEB31B58536A7FAD9222639228C47175F9F7AEA84C77F137572D9A3891
O1 HOSTS File: ([2016/07/16 20:45:37 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (トレンドマイクロセキュリティツールバーヘルパー) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (トレンドマイクロネットワークフィルタプラグイン) - {959A5673-7971-48e6-AF54-58F745AC4ABC} - C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1307\2.7.1067\TmopIEPlg32.dll (Trend Micro Inc.)
O2 - BHO: (トレンドマイクロIEプロテクション) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (HP Inc.)
O3 - HKLM\..\Toolbar: (Trend ツールバー) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O4 - HKLM..\Run: [HPMessageService] C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe (HP Inc.)
O4 - HKLM..\Run: [HPRadioMgr] C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe (HP)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3673358526-2580756353-2659711011-1001..\Run: [OneDrive] C:\Users\panda\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (HP Inc.)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (HP Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8c40deb9-8fb4-4c33-97d8-1ed09d650d0c}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmop {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\5.0.1307\2.7.1067\TmopIEPlg32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {71A5A636-652F-3BE0-BC14-02545E9F5EC7} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2017/04/21 12:49:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\panda\Desktop\OTL.exe
[2017/04/19 22:52:22 | 000,000,000 | -H-D | C] -- C:\OneDriveTemp
[2017/04/19 13:30:22 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2017/04/19 13:28:59 | 000,000,000 | ---D | C] -- C:\Users\panda\AppData\Roaming\Malwarebytes
[2017/04/19 13:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2017/04/19 13:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2017/04/19 13:28:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2017/04/19 13:27:39 | 000,000,000 | ---D | C] -- C:\Users\panda\AppData\Local\Programs
[2017/04/19 13:25:24 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\panda\Desktop\mbam-setup-1.75.0.1300.exe
[2017/04/19 12:09:56 | 000,000,000 | ---D | C] -- C:\Users\panda\AppData\Local\Diagnostics
[2017/04/18 14:07:39 | 000,000,000 | ---D | C] -- C:\Users\panda\Desktop\geek
[2017/04/17 12:39:16 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\panda\Desktop\HijackThis.exe
[2017/04/14 14:16:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2017/04/14 14:10:44 | 000,000,000 | ---D | C] -- C:\Users\panda\AppData\Local\Google
[2017/04/14 14:10:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2017/04/13 14:05:42 | 000,000,000 | ---D | C] -- C:\Users\panda\AppData\Local\Orbitum
[2017/04/13 09:23:35 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WebcamUi.dll
[2017/04/13 09:23:35 | 000,255,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\unimdm.tsp
[2017/04/13 09:23:34 | 007,468,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mstscax.dll
[2017/04/13 09:23:33 | 001,255,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AzureSettingSyncProvider.dll
[2017/04/13 09:23:33 | 000,299,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\RADCUI.dll
[2017/04/13 09:23:33 | 000,237,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SyncSettings.dll
[2017/04/13 09:23:27 | 002,682,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netshell.dll
[2017/04/13 09:23:27 | 000,769,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ipsecsnp.dll
[2017/04/13 09:23:27 | 000,436,736 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ipsmsnap.dll
[2017/04/13 09:23:19 | 000,306,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieproxy.dll
[2017/04/13 09:23:18 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieapfltr.dll
[2017/04/13 09:23:16 | 002,026,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl
[2017/04/13 09:23:12 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\apds.dll
[2017/04/13 09:23:10 | 005,685,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Data.Pdf.dll
[2017/04/13 09:23:04 | 000,306,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.MediaControl.dll
[2017/04/13 09:23:01 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Speech.dll
[2017/04/13 09:23:01 | 000,263,472 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Storage.ApplicationData.dll
[2017/04/13 09:23:01 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.StateRepositoryClient.dll
[2017/04/13 09:23:01 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.System.UserDeviceAssociation.dll
[2017/04/13 09:23:00 | 001,656,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Perception.dll
[2017/04/13 09:23:00 | 001,243,136 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.FaceAnalysis.dll
[2017/04/13 09:23:00 | 000,747,520 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Ocr.dll
[2017/04/13 09:23:00 | 000,516,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wlidcli.dll
[2017/04/13 09:23:00 | 000,392,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Gaming.Input.dll
[2017/04/13 09:23:00 | 000,315,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Gaming.XboxLive.Storage.dll
[2017/04/13 09:23:00 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WinRtTracing.dll
[2017/04/13 09:22:59 | 000,819,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AppContracts.dll
[2017/04/13 09:22:59 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.dll
[2017/04/13 09:22:59 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.Core.dll
[2017/04/13 09:22:59 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
[2017/04/13 09:22:58 | 006,667,520 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Protection.PlayReady.dll
[2017/04/13 09:22:55 | 003,520,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\xpsrchvw.exe
[2017/04/13 09:22:55 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XblAuthTokenBrokerExt.dll
[2017/04/13 09:22:55 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XblAuthManagerProxy.dll
[2017/04/13 09:22:54 | 002,646,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CertEnroll.dll
[2017/04/13 09:22:54 | 000,620,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.dll
[2017/04/13 09:22:53 | 002,994,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\win32kfull.sys
[2017/04/13 09:22:53 | 000,598,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Web.dll
[2017/04/13 09:22:52 | 001,013,248 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Web.Http.dll
[2017/04/13 09:22:50 | 000,426,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.Wallet.dll
[2017/04/13 09:22:50 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WwaApi.dll
[2017/04/13 09:22:49 | 001,004,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Input.Inking.dll
[2017/04/13 09:22:49 | 000,711,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wuapi.dll
[2017/04/13 09:22:49 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Web.Diagnostics.dll
[2017/04/13 09:22:48 | 000,557,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\StoreAgent.dll
[2017/04/13 09:22:48 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\InstallAgentUserBroker.exe
[2017/04/13 09:22:48 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\InstallAgent.exe
[2017/04/13 09:22:48 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Scanners.dll
[2017/04/13 09:22:47 | 001,232,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Xaml.Maps.dll
[2017/04/13 09:22:47 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Xaml.Phone.dll
[2017/04/13 09:22:47 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UIRibbonRes.dll
[2017/04/13 09:22:47 | 000,468,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Xaml.InkControls.dll
[2017/04/13 09:22:47 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserDeviceRegistration.dll
[2017/04/13 09:22:47 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserDataTimeUtil.dll
[2017/04/13 09:22:47 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\updatepolicy.dll
[2017/04/13 09:22:47 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\usoapi.dll
[2017/04/13 09:22:46 | 000,975,744 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\twinapi.appcore.dll
[2017/04/13 09:22:46 | 000,827,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\twinui.appcore.dll
[2017/04/13 09:22:46 | 000,299,520 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserDataAccountApis.dll
[2017/04/13 09:22:46 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ExSMime.dll
[2017/04/13 09:22:46 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AppointmentActivation.dll
[2017/04/13 09:22:45 | 003,106,304 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mstsc.exe
[2017/04/13 09:22:45 | 000,783,360 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TSWorkspace.dll
[2017/04/13 09:22:45 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.System.SystemManagement.dll
[2017/04/13 09:22:44 | 001,431,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.Store.dll
[2017/04/13 09:22:44 | 000,861,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\LicenseManager.dll
[2017/04/13 09:22:44 | 000,787,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\sbe.dll
[2017/04/13 09:22:41 | 000,862,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SettingSyncCore.dll
[2017/04/13 09:22:41 | 000,691,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TokenBroker.dll
[2017/04/13 09:22:41 | 000,589,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Sensors.dll
[2017/04/13 09:22:41 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Security.Authentication.Web.Core.dll
[2017/04/13 09:22:41 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\vaultcli.dll
[2017/04/13 09:22:41 | 000,167,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wscapi.dll
[2017/04/13 09:22:41 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TokenBrokerUI.dll
[2017/04/13 09:22:40 | 006,045,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Chakra.dll
[2017/04/13 09:22:40 | 000,886,272 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\aadtb.dll
[2017/04/13 09:22:40 | 000,431,616 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\efswrt.dll
[2017/04/13 09:22:39 | 001,196,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wscui.cpl
[2017/04/13 09:22:39 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Security.Authentication.Identity.Provider.dll
[2017/04/13 09:22:38 | 004,614,656 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.dll
[2017/04/13 09:22:38 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\RTMediaFrame.dll
[2017/04/13 09:22:37 | 001,077,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Editing.dll
[2017/04/13 09:22:36 | 001,534,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Graphics.Printing.3D.dll
[2017/04/13 09:22:36 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Graphics.Printing.dll
[2017/04/13 09:22:35 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wpnapps.dll
[2017/04/13 09:22:35 | 000,661,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WpcWebFilter.dll
[2017/04/13 09:22:35 | 000,400,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PlayToManager.dll
[2017/04/13 09:22:35 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PlayToDevice.dll
[2017/04/13 09:22:35 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PlayToReceiver.dll
[2017/04/13 09:22:34 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AuthBroker.dll
[2017/04/13 09:22:32 | 000,675,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Networking.dll
[2017/04/13 09:22:32 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Networking.HostName.dll
[2017/04/13 09:22:32 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Networking.ServiceDiscovery.Dnssd.dll
[2017/04/13 09:22:30 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Networking.Connectivity.dll
[2017/04/13 09:22:29 | 006,474,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mspaint.exe
[2017/04/13 09:22:29 | 000,795,648 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MiracastReceiver.dll
[2017/04/13 09:22:29 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Networking.BackgroundTransfer.dll
[2017/04/13 09:22:28 | 001,851,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfmp4srcsnk.dll
[2017/04/13 09:22:28 | 001,360,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfnetsrc.dll
[2017/04/13 09:22:28 | 001,344,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfsrcsnk.dll
[2017/04/13 09:22:28 | 001,202,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfmpeg2srcsnk.dll
[2017/04/13 09:22:28 | 000,981,888 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfnetcore.dll
[2017/04/13 09:22:28 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfmjpegdec.dll
[2017/04/13 09:22:27 | 004,023,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfcore.dll
[2017/04/13 09:22:27 | 001,277,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfasfsrcsnk.dll
[2017/04/13 09:22:27 | 001,221,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Audio.dll
[2017/04/13 09:22:27 | 000,895,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Streaming.dll
[2017/04/13 09:22:27 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MCRecvSrc.dll
[2017/04/13 09:22:27 | 000,609,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Import.dll
[2017/04/13 09:22:27 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.Devices.dll
[2017/04/13 09:22:26 | 006,109,696 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mos.dll
[2017/04/13 09:22:26 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\odbcconf.dll
[2017/04/13 09:22:25 | 005,721,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\windows.storage.dll
[2017/04/13 09:22:24 | 003,307,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MFMediaEngine.dll
[2017/04/13 09:22:24 | 000,654,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MbaeApiPublic.dll
[2017/04/13 09:22:24 | 000,498,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mbsmsapi.dll
[2017/04/13 09:22:24 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AboveLockAppHost.dll
[2017/04/13 09:22:18 | 002,138,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\InputService.dll
[2017/04/13 09:22:18 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Internal.Bluetooth.dll
[2017/04/13 09:22:13 | 018,364,928 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\edgehtml.dll
[2017/04/13 09:22:13 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2017/04/13 09:22:04 | 001,247,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Globalization.dll
[2017/04/13 09:22:03 | 001,414,728 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\gdi32full.dll
[2017/04/13 09:22:03 | 000,576,408 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wer.dll
[2017/04/13 09:22:03 | 000,545,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\fontdrvhost.exe
[2017/04/13 09:22:03 | 000,395,264 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dmenrollengine.dll
[2017/04/13 09:22:03 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Geolocation.dll
[2017/04/13 09:22:03 | 000,315,744 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysWow64\atmfd.dll
[2017/04/13 09:22:03 | 000,157,696 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\enrollmentapi.dll
[2017/04/13 09:22:03 | 000,037,376 | ---- | C] (Adobe Systems) -- C:\windows\SysWow64\atmlib.dll
[2017/04/13 09:22:02 | 003,733,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\D3DCompiler_47.dll
[2017/04/13 09:22:02 | 000,298,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Internal.Management.dll
[2017/04/13 09:22:02 | 000,138,240 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\DisplayManager.dll
[2017/04/13 09:22:01 | 001,564,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\quartz.dll
[2017/04/13 09:22:01 | 000,901,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Bluetooth.dll
[2017/04/13 09:22:01 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.WiFiDirect.dll
[2017/04/13 09:22:01 | 000,374,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.LowLevel.dll
[2017/04/13 09:22:01 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Midi.dll
[2017/04/13 09:22:01 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Usb.dll
[2017/04/13 09:22:01 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.WiFi.dll
[2017/04/13 09:22:01 | 000,141,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Radios.dll
[2017/04/13 09:22:01 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dialclient.dll
[2017/04/13 09:22:01 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Lights.dll
[2017/04/13 09:22:00 | 000,670,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.PointOfService.dll
[2017/04/13 09:22:00 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.SmartCards.dll
[2017/04/13 09:22:00 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CryptoWinRT.dll
[2017/04/13 09:22:00 | 000,262,144 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.Picker.dll
[2017/04/13 09:22:00 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.HumanInterfaceDevice.dll
[2017/04/13 09:22:00 | 000,129,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.SerialCommunication.dll
[2017/04/13 09:21:59 | 003,198,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cdp.dll
[2017/04/13 09:21:59 | 000,846,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WinTypes.dll
[2017/04/13 09:21:59 | 000,746,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msdtcprx.dll
[2017/04/13 09:21:59 | 000,390,656 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CredProvDataModel.dll
[2017/04/13 09:21:59 | 000,034,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CompPkgSup.dll
[2017/04/13 09:21:58 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Devices.AllJoyn.dll
[2017/04/13 09:21:58 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AppXDeploymentClient.dll
[2017/04/13 09:21:58 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\apprepsync.dll
[2017/04/13 09:21:58 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\apprepapi.dll
[2017/04/13 09:21:57 | 000,653,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.AccountsControl.dll
[2017/04/13 09:21:56 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ShareHost.dll
[2017/04/13 09:21:56 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CoreMessaging.dll
[2017/04/13 09:21:56 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\deviceaccess.dll
[2017/04/13 09:21:56 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dlnashext.dll
[2017/04/13 09:21:56 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.LockScreen.dll
[2017/04/13 09:21:56 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserMgrProxy.dll
[2017/04/13 09:21:56 | 000,136,032 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CloudExperienceHostUser.dll
[2017/04/13 09:21:56 | 000,116,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CloudExperienceHostCommon.dll
[2017/04/13 09:21:55 | 000,505,856 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\bcastdvr.exe
[2017/04/13 09:21:55 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ErrorDetails.dll
[2017/04/13 09:08:39 | 000,975,872 | ---- | C] (Microsoft Corporation) -- C:\windows\HelpPane.exe
[2017/04/05 15:09:34 | 001,456,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\GdiPlus.dll
[2017/04/05 15:09:28 | 002,458,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\themecpl.dll
[2017/04/05 15:09:28 | 001,228,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\usercpl.dll
[2017/04/05 15:09:28 | 000,965,472 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ReAgent.dll
[2017/04/05 15:09:28 | 000,560,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserLanguagesCpl.dll
[2017/04/05 15:09:28 | 000,368,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wlanui.dll
[2017/04/05 15:09:28 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\input.dll
[2017/04/05 15:09:28 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mscandui.dll
[2017/04/05 15:09:27 | 000,632,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\sud.dll
[2017/04/05 15:09:27 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msutb.dll
[2017/04/05 15:09:27 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\scksp.dll
[2017/04/05 15:09:27 | 000,173,408 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\basecsp.dll
[2017/04/05 15:09:27 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msctfui.dll
[2017/04/05 15:09:27 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msctfp.dll
[2017/04/05 15:09:26 | 000,444,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SettingSync.dll
[2017/04/05 15:09:23 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\rasgcw.dll
[2017/04/05 15:09:23 | 000,762,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mprddm.dll
[2017/04/05 15:09:23 | 000,510,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PhotoScreensaver.scr
[2017/04/05 15:09:19 | 000,631,296 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\main.cpl
[2017/04/05 15:09:18 | 001,543,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mmc.exe
[2017/04/05 15:09:18 | 000,700,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Storage.Search.dll
[2017/04/05 15:09:09 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\hgcpl.dll
[2017/04/05 15:09:08 | 000,570,368 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\clusapi.dll
[2017/04/05 15:09:08 | 000,506,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\DevicePairing.dll
[2017/04/05 15:09:08 | 000,298,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\resutils.dll
[2017/04/05 15:09:05 | 000,259,584 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msdtcuiu.dll
[2017/04/05 15:09:04 | 001,320,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\comsvcs.dll
[2017/04/05 15:09:04 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mtxclu.dll
[2017/04/05 15:09:04 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\BrowserSettingSync.dll
[2017/04/05 15:09:03 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PCPTpm12.dll
[2017/04/05 15:09:02 | 000,760,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\appwiz.cpl
[2017/04/05 15:09:02 | 000,336,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\azroleui.dll
[2017/04/05 15:09:00 | 000,798,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\authui.dll
[2017/04/05 15:08:59 | 002,643,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tquery.dll
[2017/04/05 15:08:59 | 001,988,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mssrch.dll
[2017/04/05 15:08:59 | 000,714,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mssvp.dll
[2017/04/05 15:08:59 | 000,291,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Search.ProtocolHandler.MAPI2.dll
[2017/04/05 15:08:58 | 000,458,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wlidprov.dll
[2017/04/05 15:08:58 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mssph.dll
[2017/04/05 15:08:58 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mssitlb.dll
[2017/04/05 15:08:58 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Gaming.UI.GameBar.dll
[2017/04/05 15:08:58 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XInputUap.dll
[2017/04/05 15:08:57 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\nshwfp.dll
[2017/04/05 15:08:56 | 001,969,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\hevcdecoder.dll
[2017/04/05 15:08:52 | 002,748,928 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mispace.dll
[2017/04/05 15:08:52 | 001,323,008 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wsp_fs.dll
[2017/04/05 15:08:52 | 001,137,152 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wsp_health.dll
[2017/04/05 15:08:52 | 000,719,872 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wsp_sr.dll
[2017/04/05 15:08:52 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WMVSENCD.DLL
[2017/04/05 15:08:51 | 004,557,824 | ---- | C] (Microsoft) -- C:\windows\SysWow64\dbgeng.dll
[2017/04/05 15:08:51 | 001,557,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\winmde.dll
[2017/04/05 15:08:51 | 001,556,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Immersive.dll
[2017/04/05 15:08:51 | 001,293,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WMPDMC.exe
[2017/04/05 15:08:51 | 000,781,152 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WWAHost.exe
[2017/04/05 15:08:47 | 001,362,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wmpmde.dll
[2017/04/05 15:08:46 | 001,231,360 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wcnwiz.dll
[2017/04/05 15:08:46 | 001,154,560 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Pimstore.dll
[2017/04/05 15:08:46 | 000,236,032 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\WsmWmiPl.dll
[2017/04/05 15:08:46 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UserDeviceRegistration.Ngc.dll
[2017/04/05 15:08:45 | 003,478,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\UIRibbon.dll
[2017/04/05 15:08:45 | 000,711,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Search.dll
[2017/04/05 15:08:45 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cemapi.dll
[2017/04/05 15:08:45 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Shell.Search.UriHandler.dll
[2017/04/05 15:08:44 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Unistore.dll
[2017/04/05 15:08:44 | 000,858,112 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\EmailApis.dll
[2017/04/05 15:08:44 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ContactApis.dll
[2017/04/05 15:08:44 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\AppointmentApis.dll
[2017/04/05 15:08:44 | 000,567,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ChatApis.dll
[2017/04/05 15:08:44 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\VCardParser.dll
[2017/04/05 15:08:43 | 007,626,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\twinui.dll
[2017/04/05 15:08:43 | 000,449,024 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TpmCoreProvisioning.dll
[2017/04/05 15:08:43 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\twinapi.dll
[2017/04/05 15:08:43 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tcpipcfg.dll
[2017/04/05 15:08:43 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netiohlp.dll
[2017/04/05 15:08:43 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\LaunchWinApp.exe
[2017/04/05 15:08:43 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netiougc.exe
[2017/04/05 15:08:41 | 002,153,984 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\storagewmi.dll
[2017/04/05 15:08:41 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2017/04/05 15:08:40 | 000,549,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SHCore.dll
[2017/04/05 15:08:40 | 000,493,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\SettingSyncHost.exe
[2017/04/05 15:08:39 | 000,426,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\OneDriveSettingSyncProvider.dll
[2017/04/05 15:08:39 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tbauth.dll
[2017/04/05 15:08:39 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TokenBrokerCookies.exe
[2017/04/05 15:08:38 | 000,822,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Chakradiag.dll
[2017/04/05 15:08:38 | 000,635,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript9diag.dll
[2017/04/05 15:08:37 | 000,531,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iprtrmgr.dll
[2017/04/05 15:08:35 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.Media.BackgroundMediaPlayback.dll
[2017/04/05 15:08:34 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Wpc.dll
[2017/04/05 15:08:34 | 000,525,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\PrintDialogs.dll
[2017/04/05 15:08:34 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ProximityCommon.dll
[2017/04/05 15:08:33 | 000,368,128 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\puiobj.dll
[2017/04/05 15:08:33 | 000,313,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wlanapi.dll
[2017/04/05 15:08:33 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\puiapi.dll
[2017/04/05 15:08:33 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\DafPrintProvider.dll
[2017/04/05 15:08:33 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\findnetprinters.dll
[2017/04/05 15:08:33 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wfdprov.dll
[2017/04/05 15:08:32 | 008,886,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\OneDriveSetup.exe
[2017/04/05 15:08:27 | 001,299,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MSVPXENC.dll
[2017/04/05 15:08:27 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MSVP9DEC.dll
[2017/04/05 15:08:26 | 002,740,224 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msftedit.dll
[2017/04/05 15:08:26 | 002,206,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msmpeg2vdec.dll
[2017/04/05 15:08:26 | 001,123,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfplat.dll
[2017/04/05 15:08:26 | 000,374,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MFPlay.dll
[2017/04/05 15:08:25 | 000,976,184 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfds.dll
[2017/04/05 15:08:25 | 000,545,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfmkvsrcsnk.dll
[2017/04/05 15:08:24 | 012,349,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wmp.dll
[2017/04/05 15:08:24 | 000,952,416 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mfsvr.dll
[2017/04/05 15:08:24 | 000,530,480 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mf.dll
[2017/04/05 15:08:24 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MCCSEngineShared.dll
[2017/04/05 15:08:23 | 002,363,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MapRouter.dll
[2017/04/05 15:08:23 | 002,109,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MapGeocoder.dll
[2017/04/05 15:08:23 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\DavSyncProvider.dll
[2017/04/05 15:08:23 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MapConfiguration.dll
[2017/04/05 15:08:23 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\accountaccessor.dll
[2017/04/05 15:08:22 | 005,380,608 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\BingMaps.dll
[2017/04/05 15:08:21 | 001,709,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ActiveSyncProvider.dll
[2017/04/05 15:08:21 | 001,357,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\MSPhotography.dll
[2017/04/05 15:08:20 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\LogonController.dll
[2017/04/05 15:08:20 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\LockAppBroker.dll
[2017/04/05 15:08:20 | 000,321,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\LockAppHost.exe
[2017/04/05 15:08:17 | 000,353,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\TextInputFramework.dll
[2017/04/05 15:08:17 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Core.TextInput.dll
[2017/04/05 15:08:14 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\indexeddbserver.dll
[2017/04/05 15:08:06 | 000,753,152 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\imapi2fs.dll
[2017/04/05 15:08:05 | 004,312,248 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\explorer.exe
[2017/04/05 15:08:05 | 002,484,736 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\gameux.dll
[2017/04/05 15:08:05 | 000,896,512 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\fontext.dll
[2017/04/05 15:08:05 | 000,545,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\uReFS.dll
[2017/04/05 15:08:04 | 004,423,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ExplorerFrame.dll
[2017/04/05 15:08:04 | 000,640,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\evr.dll
[2017/04/05 15:08:03 | 002,277,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\d3d11.dll
[2017/04/05 15:08:02 | 013,873,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Xaml.dll
[2017/04/05 15:08:02 | 001,631,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Windows.UI.Xaml.Resources.dll
[2017/04/05 15:08:02 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dhcpcore6.dll
[2017/04/05 15:08:00 | 001,993,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dwmcore.dll
[2017/04/05 15:08:00 | 000,248,992 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\policymanager.dll
[2017/04/05 15:07:58 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CloudBackupSettings.dll
[2017/04/05 15:07:58 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\CameraCaptureUI.dll
[2017/04/05 15:07:55 | 000,328,192 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\daxexec.dll
[2017/04/05 15:07:55 | 000,192,352 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\aepic.dll
[2017/04/05 15:07:54 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\BcastDVRHelper.dll
[2017/04/05 14:53:20 | 004,674,360 | ---- | C] (Microsoft Corporation) -- C:\windows\explorer.exe