
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbore
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbore
Zdravím odborníkov.
Prosím vás o pomoc, radu. Do svojho NB s čerstvo nainštalovaným OS som nainštaloval softvér, o ktorom som, bohužiaľ až dodatočne zistil, že inštalačný iso súbor bol infikovaný. Pri (dodatočnom) skenovaní iso súboru ESET zachytil infiltráciu Win32/Installmonetizer.AQ ako potenciálne nechcenú aplikáciu. Predpokladám, že teraz mám infikovaný NB, hoci zatiaľ sa správa vcelku normálne a ani pri inštalácii softvéru nevybehla žiadna hláška (ESET som ponechal nepretržite aktívny počas inštalácie).
Ako mám postupovať, prosím? Vopred ďakujem za radu!
Log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 16:46:53
Microsoft Windows 10 Home
System drive C: has 230 GB (77%) free of 300 GB
Total RAM: 6074 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:48:23, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swVBAServer\swvbaserver.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9174 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
dashost.exe {b922d59c-57e8-4bad-8f3c2a9256602a76}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
atieclxx
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.803.16240.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swVBAServer\swvbaserver.exe" -Embedding
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Users\Olivetti\Downloads\RSITx64.exe"
taskeng.exe {6F4A3AE2-46AD-4229-810E-3658C0197382}
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:54 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-11 10:09:52 ----A---- C:\Windows\system32\mshtml.dll
2015-08-11 10:09:48 ----A---- C:\Windows\system32\shell32.dll
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:44 ----A---- C:\Windows\system32\ieframe.dll
2015-08-11 10:09:43 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:35 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-11 10:09:35 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-11 10:09:33 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:30 ----A---- C:\Windows\system32\mfcore.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:19 ----A---- C:\Windows\system32\InputService.dll
2015-08-11 10:09:19 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\DWrite.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:14 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:10 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-11 10:09:10 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\RDXService.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\LogonController.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\FntCache.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ntdll.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:52 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:49 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\atmfd.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mfps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 16:44:52 ----D---- C:\Windows\Temp
2015-08-12 16:42:26 ----D---- C:\Windows\Microsoft.NET
2015-08-12 16:41:19 ----D---- C:\Windows\System32
2015-08-12 16:39:00 ----D---- C:\Windows\system32\sru
2015-08-12 15:54:11 ----SHD---- C:\Windows\Installer
2015-08-12 15:54:11 ----SHD---- C:\Config.Msi
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:42:37 ----RD---- C:\Windows\assembly
2015-08-12 15:40:43 ----D---- C:\Windows\system32\config
2015-08-12 13:31:08 ----D---- C:\Windows\WinSxS
2015-08-12 13:29:20 ----D---- C:\Windows\CbsTemp
2015-08-12 13:27:20 ----D---- C:\Windows\SysWOW64
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:38:31 ----D---- C:\Windows\system32\Tasks
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 23:48:16 ----D---- C:\Windows\INF
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:40:04 ----D---- C:\Windows
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:20:07 ----D---- C:\Windows\system32\DriverStore
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:46:59 ----D---- C:\Windows\system32\drivers
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\oobe
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:44:08 ----D---- C:\Windows\system32\appraiser
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Windows\AppPatch
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:41:10 ----D---- C:\Windows\Tasks
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:58:33 ----D---- C:\Windows\system32\WDI
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
Prosím vás o pomoc, radu. Do svojho NB s čerstvo nainštalovaným OS som nainštaloval softvér, o ktorom som, bohužiaľ až dodatočne zistil, že inštalačný iso súbor bol infikovaný. Pri (dodatočnom) skenovaní iso súboru ESET zachytil infiltráciu Win32/Installmonetizer.AQ ako potenciálne nechcenú aplikáciu. Predpokladám, že teraz mám infikovaný NB, hoci zatiaľ sa správa vcelku normálne a ani pri inštalácii softvéru nevybehla žiadna hláška (ESET som ponechal nepretržite aktívny počas inštalácie).
Ako mám postupovať, prosím? Vopred ďakujem za radu!
Log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 16:46:53
Microsoft Windows 10 Home
System drive C: has 230 GB (77%) free of 300 GB
Total RAM: 6074 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:48:23, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swVBAServer\swvbaserver.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9174 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
dashost.exe {b922d59c-57e8-4bad-8f3c2a9256602a76}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
atieclxx
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.803.16240.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swVBAServer\swvbaserver.exe" -Embedding
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Users\Olivetti\Downloads\RSITx64.exe"
taskeng.exe {6F4A3AE2-46AD-4229-810E-3658C0197382}
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:54 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-11 10:09:52 ----A---- C:\Windows\system32\mshtml.dll
2015-08-11 10:09:48 ----A---- C:\Windows\system32\shell32.dll
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:44 ----A---- C:\Windows\system32\ieframe.dll
2015-08-11 10:09:43 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:35 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-11 10:09:35 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-11 10:09:33 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:30 ----A---- C:\Windows\system32\mfcore.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:19 ----A---- C:\Windows\system32\InputService.dll
2015-08-11 10:09:19 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\DWrite.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:14 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:10 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-11 10:09:10 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\RDXService.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\LogonController.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\FntCache.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ntdll.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:52 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:49 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\atmfd.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mfps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 16:44:52 ----D---- C:\Windows\Temp
2015-08-12 16:42:26 ----D---- C:\Windows\Microsoft.NET
2015-08-12 16:41:19 ----D---- C:\Windows\System32
2015-08-12 16:39:00 ----D---- C:\Windows\system32\sru
2015-08-12 15:54:11 ----SHD---- C:\Windows\Installer
2015-08-12 15:54:11 ----SHD---- C:\Config.Msi
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:42:37 ----RD---- C:\Windows\assembly
2015-08-12 15:40:43 ----D---- C:\Windows\system32\config
2015-08-12 13:31:08 ----D---- C:\Windows\WinSxS
2015-08-12 13:29:20 ----D---- C:\Windows\CbsTemp
2015-08-12 13:27:20 ----D---- C:\Windows\SysWOW64
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:38:31 ----D---- C:\Windows\system32\Tasks
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 23:48:16 ----D---- C:\Windows\INF
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:40:04 ----D---- C:\Windows
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:20:07 ----D---- C:\Windows\system32\DriverStore
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:46:59 ----D---- C:\Windows\system32\drivers
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\oobe
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:44:08 ----D---- C:\Windows\system32\appraiser
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Windows\AppPatch
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:41:10 ----D---- C:\Windows\Tasks
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:58:33 ----D---- C:\Windows\system32\WDI
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Zdravím!
Pokud vir v *.iso souboru, sdám od sebe se z něj nedostane. Pokud jste iso nerozbalil, stačí jej pouze smazat.
Pokud vir v *.iso souboru, sdám od sebe se z něj nedostane. Pokud jste iso nerozbalil, stačí jej pouze smazat.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Problém je v tom, že ja som to iso nahral do virtuálnej DVD mechaniky a softvér nainštaloval (mal som ho predtým preskenovať, ale som trúba a napadlo mi to až po inštalácií
).
To, že je tam vírus som teda zistil až neskôr, keď mi docvaklo, že som sa zachoval veľmi neopatrne a až dodatočne som to iso preskenoval NOD-om
Ako hodnotíte ten log z RSIT, prosím vás? Vidno tam niečo podozrivé? Je možné že ten vírus je niekde zašitý/latentný a časom sa objaví?
Ďakujem.
To, že je tam vírus som teda zistil až neskôr, keď mi docvaklo, že som sa zachoval veľmi neopatrne a až dodatočne som to iso preskenoval NOD-om
Ako hodnotíte ten log z RSIT, prosím vás? Vidno tam niečo podozrivé? Je možné že ten vírus je niekde zašitý/latentný a časom sa objaví?
Ďakujem.
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Získaný log:
# AdwCleaner v4.208 - Logfile created 12/08/2015 at 20:04:35
# Updated 09/07/2015 by Xplode
# Database : 2015-08-12.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Olivetti - DESKTOP-RCRN0N9
# Running from : C:\Users\Olivetti\Desktop\adwcleaner_4.208.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.10240.16412
-\\ Google Chrome v44.0.2403.130
*************************
AdwCleaner[R0].txt - [850 bytes] - [12/08/2015 20:01:59]
AdwCleaner[S0].txt - [778 bytes] - [12/08/2015 20:04:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [836 bytes] ##########
# AdwCleaner v4.208 - Logfile created 12/08/2015 at 20:04:35
# Updated 09/07/2015 by Xplode
# Database : 2015-08-12.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Olivetti - DESKTOP-RCRN0N9
# Running from : C:\Users\Olivetti\Desktop\adwcleaner_4.208.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.10240.16412
-\\ Google Chrome v44.0.2403.130
*************************
AdwCleaner[R0].txt - [850 bytes] - [12/08/2015 20:01:59]
AdwCleaner[S0].txt - [778 bytes] - [12/08/2015 20:04:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [836 bytes] ##########
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Nový log RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 21:13:11
Microsoft Windows 10 Home
System drive C: has 233 GB (78%) free of 300 GB
Total RAM: 6074 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:13:14, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9006 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
dashost.exe {990c3c43-d1ba-48e4-b9101cfba0772260}
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
atieclxx
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.803.16240.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 608 612 620 8192 616
"C:\Users\Olivetti\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 20:01:34 ----D---- C:\AdwCleaner
2015-08-12 17:14:27 ----D---- C:\Windows\system32\SleepStudy
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-12 00:01:02 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:01:01 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:00:57 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-12 00:00:55 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-12 00:00:54 ----A---- C:\Windows\system32\mshtml.dll
2015-08-12 00:00:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-12 00:00:50 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 00:00:49 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-12 00:00:46 ----A---- C:\Windows\system32\shell32.dll
2015-08-12 00:00:45 ----A---- C:\Windows\system32\ieframe.dll
2015-08-12 00:00:43 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-12 00:00:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-12 00:00:41 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-12 00:00:40 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-12 00:00:39 ----A---- C:\Windows\system32\mfcore.dll
2015-08-12 00:00:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-12 00:00:35 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-12 00:00:35 ----A---- C:\Windows\system32\DWrite.dll
2015-08-12 00:00:34 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\mf.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\LogonController.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\FntCache.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-12 00:00:33 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-12 00:00:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-12 00:00:32 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-12 00:00:32 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-12 00:00:31 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-12 00:00:31 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-12 00:00:30 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-12 00:00:28 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-12 00:00:27 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\sysmain.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\notepad.exe
2015-08-12 00:00:27 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-12 00:00:27 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-12 00:00:27 ----A---- C:\Windows\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\coredpus.dll
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-12 00:00:24 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\mfps.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-12 00:00:22 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\InputService.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-12 00:00:21 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\rdbui.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\RDXService.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-12 00:00:18 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 21:11:00 ----D---- C:\Windows\system32\sru
2015-08-12 21:05:44 ----SHD---- C:\Windows\Installer
2015-08-12 21:05:44 ----SHD---- C:\Config.Msi
2015-08-12 21:05:44 ----D---- C:\Windows\Temp
2015-08-12 21:05:41 ----RD---- C:\Windows\assembly
2015-08-12 21:05:32 ----D---- C:\Windows\System32
2015-08-12 21:05:31 ----D---- C:\Windows\SysWOW64
2015-08-12 21:05:11 ----D---- C:\Windows\Microsoft.NET
2015-08-12 20:21:36 ----D---- C:\Windows\system32\config
2015-08-12 20:16:31 ----D---- C:\Windows\INF
2015-08-12 20:15:18 ----D---- C:\Windows\system32\Tasks
2015-08-12 20:10:54 ----D---- C:\Windows\WinSxS
2015-08-12 20:08:08 ----D---- C:\Windows\system32\WDI
2015-08-12 20:06:56 ----D---- C:\Windows\SYSWOW64\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-12 20:06:55 ----D---- C:\Windows\system32\oobe
2015-08-12 20:06:55 ----D---- C:\Windows\system32\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers\en-US
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers
2015-08-12 20:06:55 ----D---- C:\Windows\system32\appraiser
2015-08-12 20:06:54 ----D---- C:\Windows\AppPatch
2015-08-12 20:06:54 ----D---- C:\Windows
2015-08-12 20:06:52 ----D---- C:\Windows\system32\DriverStore
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:38:40 ----D---- C:\Windows\CbsTemp
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:41:10 ----D---- C:\Windows\Tasks
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 21:13:11
Microsoft Windows 10 Home
System drive C: has 233 GB (78%) free of 300 GB
Total RAM: 6074 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:13:14, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9006 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
dashost.exe {990c3c43-d1ba-48e4-b9101cfba0772260}
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
atieclxx
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.803.16240.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 608 612 620 8192 616
"C:\Users\Olivetti\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 20:01:34 ----D---- C:\AdwCleaner
2015-08-12 17:14:27 ----D---- C:\Windows\system32\SleepStudy
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-12 00:01:02 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:01:01 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:00:57 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-12 00:00:55 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-12 00:00:54 ----A---- C:\Windows\system32\mshtml.dll
2015-08-12 00:00:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-12 00:00:50 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 00:00:49 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-12 00:00:46 ----A---- C:\Windows\system32\shell32.dll
2015-08-12 00:00:45 ----A---- C:\Windows\system32\ieframe.dll
2015-08-12 00:00:43 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-12 00:00:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-12 00:00:41 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-12 00:00:40 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-12 00:00:39 ----A---- C:\Windows\system32\mfcore.dll
2015-08-12 00:00:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-12 00:00:35 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-12 00:00:35 ----A---- C:\Windows\system32\DWrite.dll
2015-08-12 00:00:34 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\mf.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\LogonController.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\FntCache.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-12 00:00:33 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-12 00:00:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-12 00:00:32 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-12 00:00:32 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-12 00:00:31 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-12 00:00:31 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-12 00:00:30 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-12 00:00:28 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-12 00:00:27 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\sysmain.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\notepad.exe
2015-08-12 00:00:27 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-12 00:00:27 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-12 00:00:27 ----A---- C:\Windows\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\coredpus.dll
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-12 00:00:24 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\mfps.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-12 00:00:22 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\InputService.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-12 00:00:21 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\rdbui.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\RDXService.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-12 00:00:18 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 21:11:00 ----D---- C:\Windows\system32\sru
2015-08-12 21:05:44 ----SHD---- C:\Windows\Installer
2015-08-12 21:05:44 ----SHD---- C:\Config.Msi
2015-08-12 21:05:44 ----D---- C:\Windows\Temp
2015-08-12 21:05:41 ----RD---- C:\Windows\assembly
2015-08-12 21:05:32 ----D---- C:\Windows\System32
2015-08-12 21:05:31 ----D---- C:\Windows\SysWOW64
2015-08-12 21:05:11 ----D---- C:\Windows\Microsoft.NET
2015-08-12 20:21:36 ----D---- C:\Windows\system32\config
2015-08-12 20:16:31 ----D---- C:\Windows\INF
2015-08-12 20:15:18 ----D---- C:\Windows\system32\Tasks
2015-08-12 20:10:54 ----D---- C:\Windows\WinSxS
2015-08-12 20:08:08 ----D---- C:\Windows\system32\WDI
2015-08-12 20:06:56 ----D---- C:\Windows\SYSWOW64\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-12 20:06:55 ----D---- C:\Windows\system32\oobe
2015-08-12 20:06:55 ----D---- C:\Windows\system32\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers\en-US
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers
2015-08-12 20:06:55 ----D---- C:\Windows\system32\appraiser
2015-08-12 20:06:54 ----D---- C:\Windows\AppPatch
2015-08-12 20:06:54 ----D---- C:\Windows
2015-08-12 20:06:52 ----D---- C:\Windows\system32\DriverStore
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:38:40 ----D---- C:\Windows\CbsTemp
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:41:10 ----D---- C:\Windows\Tasks
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Vykonané, log z OTM:
All processes killed
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Olivetti
->Temp folder emptied: 21078175 bytes
->Temporary Internet Files folder emptied: 1549470 bytes
->Google Chrome cache emptied: 277593856 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 18175048 bytes
RecycleBin emptied: 3395072 bytes
Total Files Cleaned = 307,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Olivetti
User: Public
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 08122015_223703
Files moved on Reboot...
C:\Users\Olivetti\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. C:\Windows\temp\ngp.log scheduled to be moved on reboot.
Registry entries deleted on Reboot...
All processes killed
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Olivetti
->Temp folder emptied: 21078175 bytes
->Temporary Internet Files folder emptied: 1549470 bytes
->Google Chrome cache emptied: 277593856 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 18175048 bytes
RecycleBin emptied: 3395072 bytes
Total Files Cleaned = 307,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Olivetti
User: Public
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 08122015_223703
Files moved on Reboot...
C:\Users\Olivetti\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. C:\Windows\temp\ngp.log scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
A ešte pridávam log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 22:43:17
Microsoft Windows 10 Home
System drive C: has 234 GB (78%) free of 300 GB
Total RAM: 6074 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:43:23, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office
\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office
\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler
\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown
owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher
\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher
\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file
missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS
Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file
missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file
missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file
missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player
\wmpnetwk.exe (file missing)
--
End of file - 9006 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
dashost.exe {1eac56f4-8200-45dc-8d107b047675a1ff}
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\wbem\wmiprvse.exe
taskeng.exe {D2BA7335-3B0A-4F8F-85CB-F6FEF0E3E98C}
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
taskeng.exe {2A2D62A3-5F97-467C-91BC-9AB8A5B1C5F0}
"C:\Program Files\Microsoft Office\Office15\MsoSync.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1573193348-195188332-3938641167-10011_ Global
\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1573193348-195188332-3938641167-10011 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible;
MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
"C:\Windows\system32\SearchFilterHost.exe" 0 600 612 620 8192 616
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\TiWorker.exe -Embedding
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft
\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"
"DownLevelDaemon"
C:\Windows\system32\SppExtComObj.exe -Embedding
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Olivetti\Desktop\RSITx64.exe"
"C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
\??\C:\Windows\system32\conhost.exe 0x4
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 22:37:03 ----D---- C:\_OTM
2015-08-12 20:01:34 ----D---- C:\AdwCleaner
2015-08-12 17:14:27 ----D---- C:\Windows\system32\SleepStudy
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-12 00:01:02 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:01:01 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:00:57 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-12 00:00:55 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-12 00:00:54 ----A---- C:\Windows\system32\mshtml.dll
2015-08-12 00:00:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-12 00:00:50 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 00:00:49 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-12 00:00:46 ----A---- C:\Windows\system32\shell32.dll
2015-08-12 00:00:45 ----A---- C:\Windows\system32\ieframe.dll
2015-08-12 00:00:43 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-12 00:00:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-12 00:00:41 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-12 00:00:40 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-12 00:00:39 ----A---- C:\Windows\system32\mfcore.dll
2015-08-12 00:00:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-12 00:00:35 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-12 00:00:35 ----A---- C:\Windows\system32\DWrite.dll
2015-08-12 00:00:34 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\mf.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\LogonController.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\FntCache.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-12 00:00:33 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-12 00:00:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-12 00:00:32 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-12 00:00:32 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-12 00:00:31 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-12 00:00:31 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-12 00:00:30 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-12 00:00:28 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-12 00:00:27 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\sysmain.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\notepad.exe
2015-08-12 00:00:27 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-12 00:00:27 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-12 00:00:27 ----A---- C:\Windows\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\coredpus.dll
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-12 00:00:24 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\mfps.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-12 00:00:22 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\InputService.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-12 00:00:21 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\rdbui.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\RDXService.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-12 00:00:18 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 22:43:19 ----D---- C:\Windows\system32\Tasks
2015-08-12 22:43:08 ----D---- C:\Windows\Temp
2015-08-12 22:41:25 ----D---- C:\Windows\system32\sru
2015-08-12 22:40:07 ----D---- C:\Windows\System32
2015-08-12 22:37:03 ----D---- C:\Windows\Tasks
2015-08-12 21:26:24 ----D---- C:\Windows\Microsoft.NET
2015-08-12 21:05:44 ----SHD---- C:\Windows\Installer
2015-08-12 21:05:44 ----SHD---- C:\Config.Msi
2015-08-12 21:05:41 ----RD---- C:\Windows\assembly
2015-08-12 21:05:31 ----D---- C:\Windows\SysWOW64
2015-08-12 20:21:36 ----D---- C:\Windows\system32\config
2015-08-12 20:16:31 ----D---- C:\Windows\INF
2015-08-12 20:10:54 ----D---- C:\Windows\WinSxS
2015-08-12 20:08:08 ----D---- C:\Windows\system32\WDI
2015-08-12 20:06:56 ----D---- C:\Windows\SYSWOW64\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-12 20:06:55 ----D---- C:\Windows\system32\oobe
2015-08-12 20:06:55 ----D---- C:\Windows\system32\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers\en-US
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers
2015-08-12 20:06:55 ----D---- C:\Windows\system32\appraiser
2015-08-12 20:06:54 ----D---- C:\Windows\AppPatch
2015-08-12 20:06:54 ----D---- C:\Windows
2015-08-12 20:06:52 ----D---- C:\Windows\system32\DriverStore
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:38:40 ----D---- C:\Windows\CbsTemp
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows
\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys
[2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys
[2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW
\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows
\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
[2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
[2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-
08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olivetti at 2015-08-12 22:43:17
Microsoft Windows 10 Home
System drive C: has 234 GB (78%) free of 300 GB
Total RAM: 6074 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:43:23, on 12.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\trend micro\Olivetti.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2015 Fast Start.lnk = ?
O4 - Global Startup: SOLIDWORKS Background Downloader.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office
\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office
\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler
\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown
owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher
\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher
\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem3.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file
missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2015 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS
Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file
missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file
missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file
missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player
\wmpnetwk.exe (file missing)
--
End of file - 9006 bytes
======Listing Processes======
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
dashost.exe {1eac56f4-8200-45dc-8d107b047675a1ff}
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2015"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\wbem\wmiprvse.exe
taskeng.exe {D2BA7335-3B0A-4F8F-85CB-F6FEF0E3E98C}
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
taskeng.exe {2A2D62A3-5F97-467C-91BC-9AB8A5B1C5F0}
"C:\Program Files\Microsoft Office\Office15\MsoSync.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1573193348-195188332-3938641167-10011_ Global
\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1573193348-195188332-3938641167-10011 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible;
MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
"C:\Windows\system32\SearchFilterHost.exe" 0 600 612 620 8192 616
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\TiWorker.exe -Embedding
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft
\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc"
"DownLevelDaemon"
C:\Windows\system32\SppExtComObj.exe -Embedding
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Olivetti\Desktop\RSITx64.exe"
"C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
\??\C:\Windows\system32\conhost.exe 0x4
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 1729752]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Olivetti\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-11 402632]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2015 Fast Start.lnk - C:\Windows\Installer\{F8093877-4F2C-40ED-9BA7-2F9F48F5176F}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Background Downloader.lnk - C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-12 22:37:03 ----D---- C:\_OTM
2015-08-12 20:01:34 ----D---- C:\AdwCleaner
2015-08-12 17:14:27 ----D---- C:\Windows\system32\SleepStudy
2015-08-12 16:46:53 ----D---- C:\rsit
2015-08-12 16:46:53 ----D---- C:\Program Files\trend micro
2015-08-12 15:48:23 ----D---- C:\Windows\system32\MRT
2015-08-12 15:48:11 ----A---- C:\Windows\system32\MRT.exe
2015-08-12 00:01:02 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:01:01 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 00:00:57 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-12 00:00:55 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-12 00:00:54 ----A---- C:\Windows\system32\mshtml.dll
2015-08-12 00:00:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-12 00:00:50 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 00:00:49 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-12 00:00:46 ----A---- C:\Windows\system32\shell32.dll
2015-08-12 00:00:45 ----A---- C:\Windows\system32\ieframe.dll
2015-08-12 00:00:43 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-12 00:00:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-12 00:00:41 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-12 00:00:40 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-12 00:00:39 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-12 00:00:39 ----A---- C:\Windows\system32\mfcore.dll
2015-08-12 00:00:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-12 00:00:36 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-12 00:00:35 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-12 00:00:35 ----A---- C:\Windows\system32\DWrite.dll
2015-08-12 00:00:34 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\mf.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\LogonController.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\FntCache.dll
2015-08-12 00:00:34 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-12 00:00:33 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-12 00:00:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-12 00:00:32 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-12 00:00:32 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-12 00:00:32 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-12 00:00:31 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-12 00:00:31 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-12 00:00:31 ----A---- C:\Windows\system32\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-12 00:00:30 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-12 00:00:30 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-12 00:00:30 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-12 00:00:29 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-12 00:00:28 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-12 00:00:28 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-12 00:00:28 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-12 00:00:27 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\sysmain.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\ntdll.dll
2015-08-12 00:00:27 ----A---- C:\Windows\system32\notepad.exe
2015-08-12 00:00:27 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-12 00:00:27 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-12 00:00:27 ----A---- C:\Windows\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-12 00:00:26 ----A---- C:\Windows\system32\coredpus.dll
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-12 00:00:25 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-12 00:00:24 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\mfps.dll
2015-08-12 00:00:23 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-12 00:00:22 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\InputService.dll
2015-08-12 00:00:22 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-12 00:00:21 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\rdbui.dll
2015-08-12 00:00:21 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\RDXService.dll
2015-08-12 00:00:20 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-12 00:00:19 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-12 00:00:18 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 19:12:57 ----D---- C:\ProgramData\Adobe
2015-08-11 18:48:04 ----D---- C:\ProgramData\Simpoe
2015-08-11 18:46:36 ----D---- C:\ProgramData\COSMOS Applications
2015-08-11 18:46:26 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2015-08-11 18:40:04 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2015-08-11 18:39:58 ----D---- C:\Users\Olivetti\AppData\Roaming\help_images_otherUI
2015-08-11 18:34:10 ----D---- C:\Users\Olivetti\AppData\Roaming\DassaultSystemes
2015-08-11 18:34:10 ----D---- C:\ProgramData\DassaultSystemes
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files\SOLIDWORKS Shared
2015-08-11 18:12:50 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-08-11 18:12:50 ----AD---- C:\ProgramData\SOLIDWORKS
2015-08-11 18:12:50 ----AD---- C:\Program Files\SOLIDWORKS Corp
2015-08-11 18:12:21 ----D---- C:\Program Files\Common Files\Macrovision Shared
2015-08-11 18:10:38 ----D---- C:\ProgramData\Apple
2015-08-11 18:10:38 ----AD---- C:\Program Files\Bonjour
2015-08-11 18:10:38 ----AD---- C:\Program Files (x86)\Bonjour
2015-08-11 18:06:00 ----D---- C:\Program Files (x86)\MSECache
2015-08-11 18:05:39 ----D---- C:\ProgramData\Package Cache
2015-08-11 18:03:03 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2015-08-11 18:02:40 ----D---- C:\ProgramData\FLEXnet
2015-08-11 18:02:20 ----D---- C:\SOLIDWORKS Data (6)
2015-08-11 17:43:03 ----D---- C:\Windows\SolidWorks
2015-08-11 17:42:57 ----D---- C:\Users\Olivetti\AppData\Roaming\SOLIDWORKS
2015-08-11 16:35:57 ----D---- C:\Users\Olivetti\AppData\Roaming\qBittorrent
2015-08-11 16:35:30 ----D---- C:\Program Files (x86)\qBittorrent
2015-08-11 14:15:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-11 13:17:55 ----D---- C:\Program Files\Microsoft.NET
2015-08-11 12:49:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-11 11:55:14 ----D---- C:\Windows\AutoKMS
2015-08-11 11:53:41 ----D---- C:\ProgramData\Microsoft Toolkit
2015-08-11 11:24:31 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-11 11:23:49 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-08-11 11:22:09 ----D---- C:\Windows\PCHEALTH
2015-08-11 11:22:09 ----D---- C:\Program Files\Microsoft SQL Server
2015-08-11 11:20:19 ----D---- C:\Program Files\Microsoft Analysis Services
2015-08-11 11:20:19 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-08-11 11:19:50 ----D---- C:\Program Files (x86)\Microsoft Office
2015-08-11 11:19:42 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 11:19:34 ----D---- C:\ProgramData\Microsoft Help
2015-08-11 11:05:21 ----D---- C:\ProgramData\ESET
2015-08-11 11:05:21 ----D---- C:\Program Files\ESET
2015-08-11 10:41:02 ----D---- C:\Program Files (x86)\Google
2015-08-11 10:12:40 ----N---- C:\Windows\system32\MpSigStub.exe
2015-08-11 10:09:46 ----A---- C:\Windows\system32\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-08-11 10:09:45 ----A---- C:\Windows\system32\windows.storage.dll
2015-08-11 10:09:40 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2015-08-11 10:09:39 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-08-11 10:09:33 ----A---- C:\Windows\system32\mssrch.dll
2015-08-11 10:09:32 ----A---- C:\Windows\system32\ClipUp.exe
2015-08-11 10:09:31 ----A---- C:\Windows\explorer.exe
2015-08-11 10:09:30 ----A---- C:\Windows\system32\twinui.dll
2015-08-11 10:09:29 ----A---- C:\Windows\system32\actxprxy.dll
2015-08-11 10:09:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-11 10:09:28 ----A---- C:\Windows\system32\Windows.Media.dll
2015-08-11 10:09:27 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-11 10:09:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-11 10:09:26 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2015-08-11 10:09:25 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-11 10:09:25 ----A---- C:\Windows\system32\msftedit.dll
2015-08-11 10:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-08-11 10:09:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-08-11 10:09:23 ----A---- C:\Windows\system32\msi.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-08-11 10:09:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-08-11 10:09:18 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-08-11 10:09:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-11 10:09:17 ----A---- C:\Windows\system32\dosvc.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIRibbon.dll
2015-08-11 10:09:16 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-11 10:09:15 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-11 10:09:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\LicenseManager.dll
2015-08-11 10:09:13 ----A---- C:\Windows\system32\audiosrv.dll
2015-08-11 10:09:12 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\iertutil.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2015-08-11 10:09:11 ----A---- C:\Windows\system32\AppContracts.dll
2015-08-11 10:09:09 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-08-11 10:09:09 ----A---- C:\Windows\system32\RecoveryDrive.exe
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\Unistore.dll
2015-08-11 10:09:08 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2015-08-11 10:09:08 ----A---- C:\Windows\system32\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\twinapi.appcore.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\SensorDataService.exe
2015-08-11 10:09:07 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\CoreMessaging.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ContactApis.dll
2015-08-11 10:09:07 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-11 10:09:06 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:06 ----A---- C:\Windows\system32\ClipSVC.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\winlogon.exe
2015-08-11 10:09:05 ----A---- C:\Windows\system32\Unistore.dll
2015-08-11 10:09:05 ----A---- C:\Windows\system32\comdlg32.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-08-11 10:09:04 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-11 10:09:04 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-11 10:09:03 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2015-08-11 10:09:03 ----A---- C:\Windows\system32\winload.exe
2015-08-11 10:09:03 ----A---- C:\Windows\system32\d3d9.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2015-08-11 10:09:02 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-08-11 10:09:02 ----A---- C:\Windows\system32\mfplat.dll
2015-08-11 10:09:01 ----A---- C:\Windows\system32\wuapi.dll
2015-08-11 10:09:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\SearchFolder.dll
2015-08-11 10:09:00 ----A---- C:\Windows\system32\gdi32.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-11 10:08:59 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\modernexecserver.dll
2015-08-11 10:08:59 ----A---- C:\Windows\system32\ieproxy.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2015-08-11 10:08:58 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\winmde.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\ntshrui.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\NotificationController.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\efscore.dll
2015-08-11 10:08:58 ----A---- C:\Windows\system32\CredProvDataModel.dll
2015-08-11 10:08:57 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-08-11 10:08:56 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-11 10:08:56 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-11 10:08:56 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-11 10:08:55 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-08-11 10:08:55 ----A---- C:\Windows\system32\winresume.exe
2015-08-11 10:08:55 ----A---- C:\Windows\system32\ncsi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MessagingDataModel2.dll
2015-08-11 10:08:54 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\wimgapi.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\OmaDmAgent.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\MBMediaManager.dll
2015-08-11 10:08:54 ----A---- C:\Windows\system32\ci.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-08-11 10:08:53 ----A---- C:\Windows\SYSWOW64\efscore.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\unenrollhook.dll
2015-08-11 10:08:53 ----A---- C:\Windows\system32\MapControlCore.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2015-08-11 10:08:52 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-08-11 10:08:52 ----A---- C:\Windows\system32\wmpmde.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\updatehandlers.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\stobject.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mos.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\hal.dll
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\refsv1.sys
2015-08-11 10:08:51 ----A---- C:\Windows\system32\drivers\pci.sys
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-08-11 10:08:50 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\wuuhext.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\srumsvc.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\SensorsApi.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2015-08-11 10:08:50 ----A---- C:\Windows\system32\DevicesFlowBroker.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2015-08-11 10:08:49 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\MCRecvSrc.dll
2015-08-11 10:08:49 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-11 10:08:48 ----A---- C:\Windows\SYSWOW64\srumsvc.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\winhttp.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\usocore.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\MessagingDataModel2.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-08-11 10:08:48 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-11 10:08:48 ----A---- C:\Windows\system32\AudioEng.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2015-08-11 10:08:47 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\wintrust.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\provhandlers.dll
2015-08-11 10:08:47 ----A---- C:\Windows\system32\PlayToManager.dll
2015-08-11 10:08:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\wpncore.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2015-08-11 10:08:46 ----A---- C:\Windows\system32\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\uxtheme.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\UserDataService.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\TabSvc.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-08-11 10:08:45 ----A---- C:\Windows\system32\psmsrv.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\mfsrcsnk.dll
2015-08-11 10:08:45 ----A---- C:\Windows\system32\ConsoleLogon.dll
2015-08-11 10:08:44 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\shutdownux.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\provengine.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MusNotification.exe
2015-08-11 10:08:44 ----A---- C:\Windows\system32\MFPlay.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-11 10:08:44 ----A---- C:\Windows\system32\AudioSes.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2015-08-11 10:08:43 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sppcomapi.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\SensorService.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\sendmail.dll
2015-08-11 10:08:43 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\sendmail.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2015-08-11 10:08:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\wininit.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\systemcpl.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ReInfo.dll
2015-08-11 10:08:42 ----A---- C:\Windows\system32\omadmclient.exe
2015-08-11 10:08:42 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\mos.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\wpnapps.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\storewuauth.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\dwmapi.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\drivers\dam.sys
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ConhostV2.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\BootMenuUX.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\bcastdvr.exe
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-08-11 10:08:41 ----A---- C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\SYSWOW64\bcd.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\MusNotificationUx.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\msiexec.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-11 10:08:40 ----A---- C:\Windows\system32\drivers\cng.sys
2015-08-11 10:08:40 ----A---- C:\Windows\system32\calc.exe
2015-08-11 10:08:40 ----A---- C:\Windows\system32\bcd.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-08-11 10:08:39 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\wer.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\UIRibbonRes.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\omadmprc.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-11 10:08:39 ----A---- C:\Windows\system32\InstallAgent.exe
2015-08-11 10:08:39 ----A---- C:\Windows\system32\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\SYSWOW64\hmkd.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wimserv.exe
2015-08-11 10:08:38 ----A---- C:\Windows\system32\wcmcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\StoreAgent.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\provisioningcsp.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\LicenseManagerApi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\dxgi.dll
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\usbser.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-08-11 10:08:38 ----A---- C:\Windows\system32\bcdboot.exe
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\SYSWOW64\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\spbcd.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\NotificationControllerPS.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\MapConfiguration.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\LicenseManagerShellext.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\jscript9.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\fwpolicyiomgr.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\BingMaps.dll
2015-08-11 10:08:37 ----A---- C:\Windows\system32\bcdedit.exe
2015-08-11 10:08:37 ----A---- C:\Windows\system32\AppxSysprep.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.V2.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\mfmkvsrcsnk.dll
2015-08-11 10:08:36 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\wpccpl.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\VoiceActivationManager.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\reseteng.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\MapsStore.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\drivers\tunnel.sys
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-11 10:08:36 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-11 10:08:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\Chakra.dll
2015-08-11 10:08:35 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2015-08-11 10:08:35 ----A---- C:\Windows\system32\atmlib.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\rixdicon.dll
2015-08-11 10:01:36 ----A---- C:\Windows\system32\drivers\rixdpx64.sys
2015-08-11 09:29:06 ----A---- C:\Windows\system32\coinst_8.97.100.9001.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsvl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsva.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsny.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\ativvsnl.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiuxp64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6v.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd6a.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiumd64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atiu9p64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atitmm64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atipblag.dat
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atio6axx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimuixx.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\atimpc64.dll
2015-08-11 09:29:05 ----A---- C:\Windows\system32\amdpcom64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2015-08-11 09:29:04 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2015-08-11 09:29:04 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiicdxx.dat
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiglpxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6txx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atig6pxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiesrxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiedu64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atieclxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atidxx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\ATIDEMGX.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticfx64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalrt64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticaldd64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\aticalcl64.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atibtmon.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiapfxx.exe
2015-08-11 09:29:04 ----A---- C:\Windows\system32\atiadlxx.dll
2015-08-11 09:29:04 ----A---- C:\Windows\system32\amdverag.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\tpinspm.dll
2015-08-11 09:28:34 ----A---- C:\Windows\system32\ibmpmsvc.exe
2015-08-11 09:28:34 ----A---- C:\Windows\system32\drivers\ibmpmdrv.sys
2015-08-11 09:28:33 ----A---- C:\Windows\system32\ibmpmctl.exe
2015-08-11 09:28:15 ----D---- C:\Program Files\CONEXANT
2015-08-11 09:28:11 ----A---- C:\Windows\system32\UCI64A41.dll
2015-08-11 09:28:11 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2015-08-11 09:28:11 ----A---- C:\Windows\system32\CX64QP17.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\SYSWOW64\MLS2.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\NlsData001b.dll
2015-08-11 09:25:58 ----A---- C:\Windows\system32\MLS2.dll
2015-08-11 01:12:05 ----D---- C:\Windows\Panther
2015-08-11 00:41:47 ----D---- C:\ProgramData\Microsoft OneDrive
2015-08-11 00:38:15 ----D---- C:\Users\Olivetti\AppData\Roaming\Adobe
2015-08-11 00:38:08 ----SD---- C:\Users\Olivetti\AppData\Roaming\Microsoft
2015-08-11 00:17:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-10 23:27:05 ----D---- C:\Windows\SoftwareDistribution
2015-08-10 23:17:31 ----A---- C:\Windows\SYSWOW64\PrintConfig.dll
2015-08-10 23:14:15 ----D---- C:\Windows\Prefetch
2015-08-10 16:54:30 ----HD---- C:\$Windows.~WS
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\epfwwfpr.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\edevmon.sys
2015-07-14 15:29:08 ----A---- C:\Windows\system32\drivers\eamonm.sys
======List of files/folders modified in the last 1 month======
2015-08-12 22:43:19 ----D---- C:\Windows\system32\Tasks
2015-08-12 22:43:08 ----D---- C:\Windows\Temp
2015-08-12 22:41:25 ----D---- C:\Windows\system32\sru
2015-08-12 22:40:07 ----D---- C:\Windows\System32
2015-08-12 22:37:03 ----D---- C:\Windows\Tasks
2015-08-12 21:26:24 ----D---- C:\Windows\Microsoft.NET
2015-08-12 21:05:44 ----SHD---- C:\Windows\Installer
2015-08-12 21:05:44 ----SHD---- C:\Config.Msi
2015-08-12 21:05:41 ----RD---- C:\Windows\assembly
2015-08-12 21:05:31 ----D---- C:\Windows\SysWOW64
2015-08-12 20:21:36 ----D---- C:\Windows\system32\config
2015-08-12 20:16:31 ----D---- C:\Windows\INF
2015-08-12 20:10:54 ----D---- C:\Windows\WinSxS
2015-08-12 20:08:08 ----D---- C:\Windows\system32\WDI
2015-08-12 20:06:56 ----D---- C:\Windows\SYSWOW64\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\WinBioPlugIns
2015-08-12 20:06:55 ----D---- C:\Windows\system32\oobe
2015-08-12 20:06:55 ----D---- C:\Windows\system32\en-GB
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers\en-US
2015-08-12 20:06:55 ----D---- C:\Windows\system32\drivers
2015-08-12 20:06:55 ----D---- C:\Windows\system32\appraiser
2015-08-12 20:06:54 ----D---- C:\Windows\AppPatch
2015-08-12 20:06:54 ----D---- C:\Windows
2015-08-12 20:06:52 ----D---- C:\Windows\system32\DriverStore
2015-08-12 16:46:53 ----RD---- C:\Program Files
2015-08-12 15:48:22 ----D---- C:\Windows\debug
2015-08-12 15:44:28 ----A---- C:\Windows\win.ini
2015-08-12 15:38:40 ----D---- C:\Windows\CbsTemp
2015-08-12 10:41:57 ----D---- C:\Windows\Logs
2015-08-12 10:32:32 ----SHD---- C:\System Volume Information
2015-08-12 07:05:00 ----D---- C:\Windows\AppReadiness
2015-08-11 23:52:04 ----D---- C:\Windows\system32\catroot2
2015-08-11 19:13:18 ----RD---- C:\Program Files (x86)
2015-08-11 19:13:18 ----D---- C:\Program Files (x86)\Common Files
2015-08-11 19:12:57 ----HD---- C:\ProgramData
2015-08-11 18:45:31 ----RSD---- C:\Windows\Fonts
2015-08-11 18:12:50 ----D---- C:\Program Files\Common Files
2015-08-11 13:51:17 ----HD---- C:\Program Files\WindowsApps
2015-08-11 13:33:47 ----AD---- C:\Program Files\Common Files\microsoft shared
2015-08-11 13:23:05 ----D---- C:\Program Files\Common Files\System
2015-08-11 13:17:55 ----AD---- C:\Program Files (x86)\Microsoft.NET
2015-08-11 12:49:52 ----SHD---- C:\Boot
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\oobe
2015-08-11 12:44:14 ----D---- C:\Windows\SYSWOW64\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\SystemResetPlatform
2015-08-11 12:44:08 ----D---- C:\Windows\system32\migration
2015-08-11 12:44:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Dism
2015-08-11 12:44:08 ----D---- C:\Windows\system32\Boot
2015-08-11 12:43:59 ----RD---- C:\Windows\PurchaseDialog
2015-08-11 12:43:59 ----D---- C:\Windows\Provisioning
2015-08-11 12:43:58 ----RD---- C:\Windows\ImmersiveControlPanel
2015-08-11 12:43:58 ----D---- C:\Program Files\Internet Explorer
2015-08-11 12:43:58 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-11 11:24:43 ----D---- C:\Windows\ShellNew
2015-08-11 11:23:20 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2015-08-11 11:19:43 ----SD---- C:\ProgramData\Microsoft
2015-08-11 11:02:41 ----SHD---- C:\$Recycle.Bin
2015-08-11 10:10:23 ----D---- C:\Windows\system32\restore
2015-08-11 09:26:11 ----D---- C:\Windows\OCR
2015-08-11 09:05:14 ----RD---- C:\Windows\DevicesFlow
2015-08-11 09:04:22 ----RD---- C:\Users
2015-08-11 01:11:52 ----RASH---- C:\BOOTSECT.BAK
2015-08-11 00:39:38 ----RD---- C:\Windows\PrintDialog
2015-08-11 00:39:37 ----RD---- C:\Windows\MiracastView
2015-08-11 00:21:30 ----D---- C:\Windows\rescache
2015-08-11 00:14:17 ----D---- C:\Windows\system32\wbem
2015-08-11 00:11:24 ----D---- C:\Windows\system32\FxsTmp
2015-08-10 23:23:47 ----D---- C:\Windows\system32\CodeIntegrity
2015-08-10 23:20:27 ----SHD---- C:\Recovery
2015-08-10 23:20:27 ----D---- C:\Windows\system32\Recovery
2015-08-10 23:20:23 ----D---- C:\Windows\system32\Sysprep
2015-07-21 09:27:35 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2015-07-14 251632]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 rismxdp;@oem5.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2015-08-11 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-11 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-11 359936]
R3 b57nd60a;@netb57va.inf,%SvcDispName%;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\System32\drivers\b57nd60a.sys [2015-07-10 452096]
R3 CnxtHdAudService;@oem2.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows
\system32\drivers\CHDRT64.sys [2015-08-11 647168]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-08-11 72400]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\System32\drivers\NETwNs64.sys [2015-07-10 8604672]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2015-07-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2015-07-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2015-07-10 740864]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-07-10 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys
[2015-07-10 32256]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys
[2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-07-10 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-07-10 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-07-10 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\Windows\System32\drivers\usbser.sys [2015-07-24 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\Windows\System32\drivers\vhf.sys [2015-07-10 31744]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-11 238080]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
R2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 IBMPMSVC;@oem3.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-08-11 156920]
R2 OneSyncSvc_Session1;Sync Host_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 RemoteSolverDispatcher;Remote Solver for Flow Simulation 2015; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW
\remotesolverdispatcherservice.exe [2014-12-13 234632]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 CoordinatorServiceHost;DTSInterops; C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe [2014-12-14 81400]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows
\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
[2015-08-11 1484080]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
[2015-08-11 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2015-
08-11 79360]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session1;User Data Storage_Session1; C:\Windows\System32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UserDataSvc_Session1;User Data Access_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\Windows\system32\svchost.exe [2015-07-10 39856]
S3 vmicvmsession;@%systemroot%\system32\icsvc.dll,-901; C:\Windows\system32\svchost.exe [2015-07-10 39856]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Vše smazáno, kromě pár zbytečností to nic nenašlo. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Mělo by být čisto.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
To som teda nečakal, ale spadol mi kameň zo srdca. Veľmi pekne Vám ďakujem za pomoc!
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Infekcia Win32/InstallMonetizer.AQ zachytená v .iso súbo
Nemáte zač! 
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?