OTL(2)再送
E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=PRTOS1&src=IE11TR&pc=TBTE
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://toshiba17win10.msn.com/?pc=TBTE
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://toshiba17win10.msn.com/?pc=TBTE
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFRECompletionTime = BB E2 D1 7A 19 30 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,IE11DefaultsFREConfigUpdateTimestamp = 6C B2 91 C3 D6 40 D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://toshibaplaces.jp/tps/ [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://toshiba17win10.msn.com/?pc=TBTE
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 4D 07 FA 86 91 2A D5 01 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 2A 00 00 00 F1 E0 2F BD 98 8B 5D 53 C9 71 5B CA 85 7E B3 A3 67 FC 34 CE C3 72 B4 58 97 35 7D 76 A0 89 20 E4 34 70 67 3E DB 19 28 EE CF 55 02 00 00 00 10 00 00 00 41 2F 25 32 62 6A 73 34 34 63 7A 66 38 25 33 64 [binary data]
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1460922254-185261916-941432131-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll (Google LLC)
[color=#E56717]========== Chrome ==========[/color]
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.2_1\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\
CHR - Extension: No name found = C:\Users\sho50\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7519.422.0.3_0\
O1 HOSTS File: ([2016/07/16 20:45:37 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:[b]64bit:[/b] - HKLM..\Run: [] File not found
O4:[b]64bit:[/b] - HKLM..\Run: [SecurityHealth] C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TecoResident] C:\Program Files\TOSHIBA\Teco\TecoResident.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (Toshiba Client Solutions Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe (Trend Micro Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [VizorHtmlDialog.exe] C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [CCleaner Smart Cleaning] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Software Ltd)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\Run: [OneDrive] C:\Users\sho50\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1460922254-185261916-941432131-1001..\RunOnce: [Application Restart #0] C:\Program Files (x86)\sMedio\TVConnectSuite\bin\TVCSDubbingServiceTrayIcon.exe (sMedio Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableFullTrustStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUwpStartupTasks = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportFullTrustStartupTasks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SupportUwpStartupTasks = 1
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.3.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{406fe38c-c20f-4157-aa17-bc878f6bffb5}: DhcpNameServer = 192.168.0.1 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7cb959f8-1ae5-4608-9757-b23f04f03130}: DhcpNameServer = 192.168.3.1
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C6658531-8DB9-3115-B6D1-F89B57830CFC} - .NET Framework
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {23A20C3C-2ADD-4A80-AFB4-C146F8847D79} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B82EE9BD-ADE2-3058-8091-78419781EC8E} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2019/07/23 22:25:10 | 000,073,584 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2019/07/23 22:25:08 | 000,224,408 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2019/07/23 22:25:08 | 000,116,112 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2019/07/23 22:25:04 | 000,275,232 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbamswissarmy.sys
[2019/07/23 22:19:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\sho50\Desktop\OTL.exe
[2019/07/20 06:11:52 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\sMedio
[2019/07/14 16:58:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2019/07/14 16:57:48 | 007,025,360 | ---- | C] (Malwarebytes) -- C:\Users\sho50\Desktop\AdwCleaner.exe
[2019/07/13 12:35:21 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbam
[2019/07/13 12:35:07 | 000,199,768 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamChameleon.sys
[2019/07/13 12:34:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\mbamtray
[2019/07/13 12:34:51 | 000,020,936 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MbamElam.sys
[2019/07/13 12:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2019/07/13 12:34:49 | 000,153,328 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2019/07/13 12:34:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2019/07/13 12:32:48 | 064,552,472 | ---- | C] (Malwarebytes ) -- C:\Users\sho50\Desktop\mb3-setup-consumer-3.8.3.2965-1.0.613-1.0.11520.exe
[2019/07/13 03:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office ツール
[2019/07/11 07:12:50 | 007,519,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:50 | 006,570,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Protection.PlayReady.dll
[2019/07/11 07:12:49 | 025,857,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgehtml.dll
[2019/07/11 07:12:44 | 022,017,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgehtml.dll
[2019/07/11 07:12:43 | 009,084,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2019/07/11 07:12:42 | 007,589,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Chakra.dll
[2019/07/11 07:12:42 | 007,436,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\windows.storage.dll
[2019/07/11 07:12:41 | 005,625,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StartTileData.dll
[2019/07/11 07:12:40 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Chakra.dll
[2019/07/11 07:12:40 | 004,847,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_nt.dll
[2019/07/11 07:12:40 | 001,721,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2019/07/11 07:12:40 | 001,616,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2019/07/11 07:12:39 | 006,044,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\windows.storage.dll
[2019/07/11 07:12:39 | 004,718,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.pcshell.dll
[2019/07/11 07:12:39 | 003,614,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kfull.sys
[2019/07/11 07:12:38 | 006,586,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2019/07/11 07:12:38 | 004,861,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2019/07/11 07:12:38 | 004,385,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeContent.dll
[2019/07/11 07:12:38 | 004,038,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2019/07/11 07:12:38 | 003,292,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2019/07/11 07:12:38 | 002,882,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\win32kfull.sys
[2019/07/11 07:12:37 | 003,401,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2019/07/11 07:12:37 | 000,740,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2019/07/11 07:12:37 | 000,513,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepic.dll
[2019/07/11 07:12:36 | 005,657,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2019/07/11 07:12:36 | 004,771,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputService.dll
[2019/07/11 07:12:36 | 003,700,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2019/07/11 07:12:35 | 002,871,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aitstatic.exe
[2019/07/11 07:12:35 | 002,479,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2019/07/11 07:12:35 | 001,035,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ApplyTrustOffline.exe
[2019/07/11 07:12:35 | 000,810,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2019/07/11 07:12:34 | 003,318,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2019/07/11 07:12:34 | 003,202,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2019/07/11 07:12:34 | 002,370,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WebRuntimeManager.dll
[2019/07/11 07:12:34 | 002,166,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32kbase.sys
[2019/07/11 07:12:34 | 001,219,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvix64.exe
[2019/07/11 07:12:34 | 000,951,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcext.dll
[2019/07/11 07:12:34 | 000,900,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\slui.exe
[2019/07/11 07:12:34 | 000,896,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sppcext.dll
[2019/07/11 07:12:34 | 000,767,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppcommdlg.dll
[2019/07/11 07:12:34 | 000,415,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\aepic.dll
[2019/07/11 07:12:33 | 008,627,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2019/07/11 07:12:33 | 002,899,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2019/07/11 07:12:33 | 002,571,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2019/07/11 07:12:33 | 001,400,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBroker.dll
[2019/07/11 07:12:33 | 001,215,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationController.dll
[2019/07/11 07:12:33 | 001,027,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvax64.exe
[2019/07/11 07:12:33 | 000,637,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2019/07/11 07:12:33 | 000,511,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dcntel.dll
[2019/07/11 07:12:33 | 000,464,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2019/07/11 07:12:33 | 000,164,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2019/07/11 07:12:33 | 000,071,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32appinventorycsp.dll
[2019/07/11 07:12:32 | 003,554,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputService.dll
[2019/07/11 07:12:32 | 001,631,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32full.dll
[2019/07/11 07:12:32 | 001,626,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enterprisecsps.dll
[2019/07/11 07:12:32 | 001,453,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gdi32full.dll
[2019/07/11 07:12:32 | 001,376,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2019/07/11 07:12:32 | 001,175,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncCore.dll
[2019/07/11 07:12:32 | 000,922,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:32 | 000,808,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EdgeManager.dll
[2019/07/11 07:12:32 | 000,607,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TextInputFramework.dll
[2019/07/11 07:12:32 | 000,324,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2019/07/11 07:12:31 | 007,990,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2019/07/11 07:12:31 | 002,546,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpdateAgent.dll
[2019/07/11 07:12:31 | 002,176,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.onecore.dll
[2019/07/11 07:12:31 | 001,663,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2019/07/11 07:12:31 | 001,566,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxPackaging.dll
[2019/07/11 07:12:31 | 001,561,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentExtensions.desktop.dll
[2019/07/11 07:12:31 | 001,549,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2019/07/11 07:12:31 | 001,471,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2019/07/11 07:12:31 | 001,459,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2019/07/11 07:12:31 | 001,048,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Internal.Shell.Broker.dll
[2019/07/11 07:12:31 | 001,033,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ClipSVC.dll
[2019/07/11 07:12:31 | 000,916,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusUpdateHandlers.dll
[2019/07/11 07:12:31 | 000,894,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webplatstorageserver.dll
[2019/07/11 07:12:31 | 000,567,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\daxexec.dll
[2019/07/11 07:12:31 | 000,566,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\phoneactivate.exe
[2019/07/11 07:12:30 | 001,427,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxPackaging.dll
[2019/07/11 07:12:30 | 001,260,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2019/07/11 07:12:30 | 001,141,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2019/07/11 07:12:30 | 001,127,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nettrace.dll
[2019/07/11 07:12:30 | 001,003,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBroker.dll
[2019/07/11 07:12:30 | 000,986,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingSyncHost.exe
[2019/07/11 07:12:30 | 000,953,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncCore.dll
[2019/07/11 07:12:30 | 000,776,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wer.dll
[2019/07/11 07:12:30 | 000,767,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2019/07/11 07:12:30 | 000,734,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SharedRealitySvc.dll
[2019/07/11 07:12:30 | 000,624,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PsmServiceExtHost.dll
[2019/07/11 07:12:30 | 000,608,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EdgeManager.dll
[2019/07/11 07:12:30 | 000,559,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppXDeploymentClient.dll
[2019/07/11 07:12:30 | 000,545,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2019/07/11 07:12:30 | 000,532,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\QuietHours.dll
[2019/07/11 07:12:30 | 000,510,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\policymanager.dll
[2019/07/11 07:12:30 | 000,506,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\edgeIso.dll
[2019/07/11 07:12:30 | 000,493,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,356,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2019/07/11 07:12:30 | 000,251,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2019/07/11 07:12:30 | 000,093,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wldp.dll
[2019/07/11 07:12:29 | 002,406,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AcGenral.dll
[2019/07/11 07:12:29 | 001,609,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2019/07/11 07:12:29 | 001,339,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TaskFlowDataEngine.dll
[2019/07/11 07:12:29 | 001,328,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpx.dll
[2019/07/11 07:12:29 | 001,130,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msvproc.dll
[2019/07/11 07:12:29 | 001,098,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msvproc.dll
[2019/07/11 07:12:29 | 000,983,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2019/07/11 07:12:29 | 000,832,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2019/07/11 07:12:29 | 000,790,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fontdrvhost.exe
[2019/07/11 07:12:29 | 000,785,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pkeyhelper.dll
[2019/07/11 07:12:29 | 000,765,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2019/07/11 07:12:29 | 000,723,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2019/07/11 07:12:29 | 000,681,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Security.Authentication.Web.Core.dll
[2019/07/11 07:12:29 | 000,544,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2019/07/11 07:12:29 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotification.exe
[2019/07/11 07:12:29 | 000,392,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\daxexec.dll
[2019/07/11 07:12:29 | 000,362,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:29 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AcGenral.dll
[2019/07/11 07:12:29 | 000,080,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wldp.dll
[2019/07/11 07:12:28 | 001,220,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Unistore.dll
[2019/07/11 07:12:28 | 001,217,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2019/07/11 07:12:28 | 001,076,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\efscore.dll
[2019/07/11 07:12:28 | 001,063,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SecConfig.efi
[2019/07/11 07:12:28 | 000,871,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,869,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,849,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,766,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,713,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MSVideoDSP.dll
[2019/07/11 07:12:28 | 000,665,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wer.dll
[2019/07/11 07:12:28 | 000,662,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\fontdrvhost.exe
[2019/07/11 07:12:28 | 000,660,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LicensingWinRT.dll
[2019/07/11 07:12:28 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.BackgroundMediaPlayback.dll
[2019/07/11 07:12:28 | 000,646,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.BackgroundMediaPlayer.dll
[2019/07/11 07:12:28 | 000,630,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Playback.MediaPlayer.dll
[2019/07/11 07:12:28 | 000,622,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2019/07/11 07:12:28 | 000,604,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\securekernel.exe
[2019/07/11 07:12:28 | 000,568,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tcblaunch.exe
[2019/07/11 07:12:28 | 000,523,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmenrollengine.dll
[2019/07/11 07:12:28 | 000,443,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\policymanager.dll
[2019/07/11 07:12:28 | 000,361,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceEnroller.exe
[2019/07/11 07:12:28 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\edgeIso.dll
[2019/07/11 07:12:28 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MusNotificationUx.exe
[2019/07/11 07:12:28 | 000,302,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CXHProvisioningServer.dll
[2019/07/11 07:12:28 | 000,295,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TDLMigration.dll
[2019/07/11 07:12:28 | 000,287,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Storage.ApplicationData.dll
[2019/07/11 07:12:28 | 000,130,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rmclient.dll
[2019/07/11 07:12:27 | 001,076,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2019/07/11 07:12:27 | 000,965,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Unistore.dll
[2019/07/11 07:12:27 | 000,761,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2019/07/11 07:12:27 | 000,755,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:27 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2019/07/11 07:12:27 | 000,581,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSVideoDSP.dll
[2019/07/11 07:12:27 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webplatstorageserver.dll
[2019/07/11 07:12:27 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nltest.exe
[2019/07/11 07:12:27 | 000,501,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2019/07/11 07:12:27 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcdedit.exe
[2019/07/11 07:12:27 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmenrollengine.dll
[2019/07/11 07:12:27 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2019/07/11 07:12:27 | 000,416,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanapi.dll
[2019/07/11 07:12:27 | 000,394,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputSwitch.dll
[2019/07/11 07:12:27 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptprov.dll
[2019/07/11 07:12:27 | 000,328,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wlanapi.dll
[2019/07/11 07:12:27 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxAllUserStore.dll
[2019/07/11 07:12:27 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wc_storage.dll
[2019/07/11 07:12:27 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptprov.dll
[2019/07/11 07:12:27 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vdsbas.dll
[2019/07/11 07:12:27 | 000,236,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,221,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\EditionUpgradeManagerObj.dll
[2019/07/11 07:12:27 | 000,209,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wermgr.exe
[2019/07/11 07:12:27 | 000,194,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\skci.dll
[2019/07/11 07:12:27 | 000,191,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wermgr.exe
[2019/07/11 07:12:27 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssvc.dll
[2019/07/11 07:12:27 | 000,146,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LicensingUI.exe
[2019/07/11 07:12:27 | 000,137,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2019/07/11 07:12:27 | 000,134,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hvloader.dll
[2019/07/11 07:12:27 | 000,115,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\kdnet.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\profext.dll
[2019/07/11 07:12:27 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ngcpopkeysrv.dll
[2019/07/11 07:12:27 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NotificationControllerPS.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rmclient.dll
[2019/07/11 07:12:27 | 000,101,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\changepk.exe
[2019/07/11 07:12:27 | 000,094,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2019/07/11 07:12:27 | 000,091,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2019/07/11 07:12:27 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KdsCli.dll
[2019/07/11 07:12:27 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2019/07/11 07:12:27 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2019/07/11 07:12:27 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TokenBrokerUI.dll
[2019/07/11 07:12:27 | 000,036,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DeviceCensus.exe
[2019/07/11 07:12:26 | 000,677,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\HeadTrackerStorage.dll
[2019/07/11 07:12:26 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Core.TextInput.dll
[2019/07/11 07:12:26 | 000,508,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers_Notifications.dll
[2019/07/11 07:12:26 | 000,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2019/07/11 07:12:26 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wlanmsm.dll
[2019/07/11 07:12:26 | 000,371,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InputSwitch.dll
[2019/07/11 07:12:26 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msIso.dll
[2019/07/11 07:12:26 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DesktopSwitcherDataModel.dll
[2019/07/11 07:12:26 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\AppxAllUserStore.dll
[2019/07/11 07:12:26 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\EditionUpgradeHelper.dll
[2019/07/11 07:12:26 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\enrollmentapi.dll
[2019/07/11 07:12:26 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dmvdsitf.dll
[2019/07/11 07:12:26 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mdmmigrator.dll
[2019/07/11 07:12:26 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InputLocaleManager.dll
[2019/07/11 07:12:26 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\splwow64.exe
[2019/07/11 07:12:26 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppxSysprep.dll
[2019/07/11 07:12:26 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\profext.dll
[2019/07/11 07:12:26 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RjvMDMConfig.dll
[2019/07/11 07:12:26 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2019/07/11 07:12:26 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSReset.exe
[2019/07/11 07:12:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2019/07/11 07:12:26 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UpgradeResultsUI.exe
[2019/07/11 07:12:26 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TokenBrokerUI.dll
[2019/07/11 07:12:26 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\werdiagcontroller.dll
[2019/07/10 05:05:18 | 000,367,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdFilter.sys
[2019/07/10 05:05:18 | 000,054,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdNisDrv.sys
[2019/07/10 05:05:18 | 000,047,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wd\WdBoot.sys
[2019/07/09 22:54:17 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Macromedia
[2019/07/08 23:47:42 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Geek Uninstaller
[2019/07/08 23:42:17 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\sho50\Desktop\HijackThis.exe
[2019/07/08 23:40:08 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Google
[2019/07/08 23:38:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2019/07/08 23:33:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2019/07/08 23:30:46 | 000,000,000 | ---D | C] -- C:\Users\sho50\Desktop\geek (3)
[2019/07/08 23:28:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lhaplus
[2019/07/08 23:28:23 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Programs
[2019/07/08 23:12:57 | 000,000,000 | ---D | C] -- C:\ProgramData\UniqueId
[2019/07/07 13:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2019/07/07 13:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2019/06/29 18:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel\Wlan\Router
[2019/06/29 18:06:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\DriverData\Intel
[2019/06/29 14:22:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2019/06/29 13:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\rempl
[2019/06/29 06:16:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MRT
[2019/06/29 06:08:21 | 000,000,000 | ---D | C] -- C:\Program Files\UNP
[2019/06/26 00:52:25 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft Help
[2019/06/24 22:47:09 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\PlaceholderTileLogoFolder
[2019/06/24 22:45:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Packages
[2019/06/24 22:32:59 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\DBG
[2019/06/24 22:31:04 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Power2Go8
[2019/06/24 22:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2019/06/24 22:30:58 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Comms
[2019/06/24 22:29:41 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\MicrosoftEdge
[2019/06/24 22:29:37 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Publishers
[2019/06/24 22:29:30 | 000,000,000 | R--D | C] -- C:\Users\sho50\Searches
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\VirtualStore
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Packages
[2019/06/24 22:29:29 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Adobe
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Intel
[2019/06/24 22:29:28 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\ConnectedDevicesPlatform
[2019/06/24 22:29:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Intel
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\デスクトップ
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\スタート メニュー
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Templates
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Documents
[2019/06/24 21:09:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\Application Data
[2019/06/24 21:09:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\wd
[2019/06/24 21:07:27 | 000,000,000 | --SD | C] -- C:\Users\sho50\AppData\Roaming\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2019/06/24 21:07:27 | 000,000,000 | R--D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\スタート メニュー
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Temporary Internet Files
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Templates
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\SendTo
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Recent
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\PrintHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\NetHood
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Videos
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Pictures
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Documents\My Music
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\My Documents
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Local Settings
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\History
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Cookies
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\sho50\AppData\Local\Application Data
[2019/06/24 21:07:27 | 000,000,000 | -H-D | C] -- C:\Users\sho50\AppData
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Temp
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\Roaming
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Local\Microsoft
[2019/06/24 21:07:27 | 000,000,000 | ---D | C] -- C:\Users\sho50\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2019/06/24 20:58:32 | 000,000,000 | ---D | C] -- C:\ProgramData\USOShared
[2019/06/24 20:58:31 | 002,752,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PrintConfig.dll
[2019/06/24 20:57:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2019/06/24 20:57:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Audyssey Labs
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2019/06/24 20:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2019/06/24 20:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2019/06/24 20:56:54 | 000,146,384 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.DLL
[2019/06/24 20:56:54 | 000,121,296 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.DLL
[2019/06/24 20:56:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2019/06/24 20:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2019/06/24 20:56:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2019/06/24 20:56:41 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2019/06/24 20:56:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SleepStudy
[2019/06/24 20:55:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\InfusedApps
[2019/06/24 20:55:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2019/06/24 20:55:18 | 000,000,000 | ---D | C] -- C:\Windows.old
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServiceProfiles
[2019/06/24 20:54:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Microsoft
[2019/06/24 20:54:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sda
[2019/06/24 20:53:41 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2019/06/24 20:52:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Setup
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zu-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\yo-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\xh-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\wo-SN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Media Player
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\vi-VN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\uz-Latn-UZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ur-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ug-CN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tt-RU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tn-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tk-TM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ti-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\tg-Cyrl-TJ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\te-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ta-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sw-KE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-RS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sr-Cyrl-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sq-AL
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\si-LK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\sd-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\rw-RW
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quz-PE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\quc-Latn-GT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\prs-AF
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\pa-Arab-PK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\or-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\OpenSSH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\OCR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nso-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\nn-NO
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ne-NP
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mt-MT
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ms-MY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mr-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mn-MN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ml-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mk-MK
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\mi-NZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\MailContactsCalendarSync
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lo-LA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\lb-LU
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ky-KG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ku-Arab-IQ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kok-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\km-KH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\kk-KZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ka-GE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\is-IS
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ig-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\id-ID
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hy-AM
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\hi-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ha-Latn-NG
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gu-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gl-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\gd-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ga-IE
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fil-PH
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\fa-IR
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\eu-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\cy-GB
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\chr-CHER-US
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES-valencia
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ca-ES
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bs-Latn-BA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\bn-BD
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\be-BY
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\az-Latn-AZ
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\as-IN
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\am-ET
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\af-ZA
[2019/06/24 20:50:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\af-ZA
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\winrm
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WCN
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\sysprep
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\slmgr
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Printing_Admin_Scripts
[2019/06/24 20:50:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\ja
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winrm
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WCN
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\slmgr
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\Printing_Admin_Scripts
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\ja-JP
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\UMDF\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\drivers\en-US
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\en
[2019/06/24 20:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\0409
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ja-JP
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\ja
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\UMDF\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\drivers\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\en-US
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\en
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\DigitalLocker
[2019/06/24 20:50:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\0409
[2019/06/24 20:49:02 | 000,835,688 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2019/06/24 20:49:02 | 000,179,816 | ---- | C] (Adobe) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2019/06/24 20:47:26 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msclmd.dll
[2019/06/24 20:47:23 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msclmd.dll
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\UNP
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Nui
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\F12
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\dsc
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\DiagSvcs
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysWow64\Configuration
[2019/06/24 20:47:19 | 000,000,000 | --SD | C] -- C:\WINDOWS\SysNative\Configuration
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-TW
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\zh-CN
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\WinMetadata
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\winevt
[2019/06/24 20:47:19 | 000,000,000 | ---D | C] --