Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zdetekovane rovnake IP

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

zdetekovane rovnake IP

#1 Příspěvek od Brigit900 »

Dobry den,

poprosila by som Vas o kontrolu logu, po prihlaseni sa na wifi siet Eset hlasi zdetekovane rovnake IP adresy a utoky z vlastnej IP...
Dakujem :)


Logfile of random's system information tool 1.10 (written by random/random)
Run by Be at 2015-11-25 21:24:58
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 896 GB (94%) free of 954 GB
Total RAM: 3987 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:02, on 25. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Be.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [HP Camera Driver_Monitor] "C:\Program Files (x86)\HP Camera Driver\monitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.hola.org
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hola Better Internet Engine (hola_svc) - Hola Networks Ltd. - C:\Program Files\Hola\app\hola_svc.exe
O23 - Service: Hola Better Internet Updater (hola_updater) - Hola Networks Ltd. - C:\Program Files\Hola\app\hola_updater.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9432 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe"
"C:\Program Files\Hola\app\hola.exe" --silent
"C:\Program Files\ESET\ESET Endpoint Security\egui.exe" /hide /waitservice
"C:\Program Files\Hola\app\hola_svc.exe" --service
"C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\Hola\app\hola_updater.exe" --service --run-as hola_updater
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1992_00A411C0_676717581 µTorrent4823DF041B09 uTorrent
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1992_00A41270_1695716828 µTorrent4823DF041B09 uTorrent
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1692.0.2091558777\1170257836" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x0000 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1002.1008 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledInitialReceiveWindow64KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1692.2.1908242142\753227108" --font-cache-shared-handle=2120 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledInitialReceiveWindow64KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1692.3.839751721\1689297112" --font-cache-shared-handle=2664 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledInitialReceiveWindow64KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1692.4.1866265376\852560631" --font-cache-shared-handle=3864 /prefetch:673131151
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledInitialReceiveWindow64KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1692.9.133716976\98708499" --font-cache-shared-handle=4868 /prefetch:673131151
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524

"C:\Users\Be\Downloads\RSITx64 (2).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20 153768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"hola"=C:\Program Files\Hola\app\hola.exe [2015-11-08 2031232]
"egui"=C:\Program Files\ESET\ESET Endpoint Security\egui.exe [2015-08-05 4150472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe [2015-11-08 1822048]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-06-18 4468056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Camera Driver_Monitor"=C:\Program Files (x86)\HP Camera Driver\monitor.exe []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-04-10 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-08-25 293872]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-20 00:18:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-11-19 20:29:53 ----A---- C:\Windows\system32\win32k.sys
2015-11-12 00:44:03 ----D---- C:\Windows\system32\MRT
2015-11-12 00:43:41 ----A---- C:\Windows\system32\MRT.exe
2015-11-12 00:34:07 ----D---- C:\Program Files\Microsoft.NET
2015-11-11 23:42:15 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2015-11-11 23:42:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDBASH.DLL
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\iernonce.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-11 23:34:03 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 23:34:02 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\urlmon.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\occache.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 23:34:00 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\iesetup.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-11 23:33:58 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-11 23:33:58 ----A---- C:\Windows\system32\iertutil.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-11 23:33:57 ----A---- C:\Windows\system32\vbscript.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieui.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieframe.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\wininet.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\webcheck.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\msrating.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\mshtml.dll
2015-11-11 23:32:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2015-11-11 23:32:52 ----A---- C:\Windows\system32\d2d1.dll
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\bthport.sys
2015-11-11 23:28:47 ----A---- C:\Windows\system32\fsutil.exe
2015-11-11 23:28:47 ----A---- C:\Windows\system32\esent.dll
2015-11-11 23:28:47 ----A---- C:\Windows\system32\drivers\amdxata.sys
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\esent.dll
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvstor.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvraid.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\amdsata.sys
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\FntCache.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-11 22:39:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-11 22:39:26 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-11 22:39:10 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-11 22:39:10 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-11 21:49:05 ----SD---- C:\Windows\system32\CompatTel
2015-11-11 21:49:05 ----D---- C:\Windows\system32\appraiser
2015-11-11 21:48:55 ----D---- C:\Windows\SYSWOW64\Wat
2015-11-11 21:48:55 ----D---- C:\Windows\system32\Wat
2015-11-11 21:48:46 ----SD---- C:\Windows\SYSWOW64\GWX
2015-11-11 21:48:46 ----SD---- C:\Windows\system32\GWX
2015-11-11 21:48:46 ----D---- C:\Windows\Migration
2015-11-11 03:07:03 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:07:03 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:04:43 ----A---- C:\Windows\system32\IEUDINIT.EXE
2015-11-11 02:56:42 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\msls31.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2015-11-11 02:56:37 ----A---- C:\Windows\system32\elshyph.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\url.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\icardie.dll
2015-11-11 02:56:33 ----A---- C:\Windows\SYSWOW64\inseng.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\wextract.exe
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\mshta.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2015-11-11 02:56:26 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-11-11 02:56:26 ----A---- C:\Windows\system32\jsIntl.dll
2015-11-11 02:56:25 ----A---- C:\Windows\system32\msls31.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedssync.exe
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-11-11 02:56:23 ----A---- C:\Windows\system32\mshtmler.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\iesysprep.dll
2015-11-11 02:56:21 ----A---- C:\Windows\system32\ieapfltr.dat
2015-11-11 02:56:19 ----A---- C:\Windows\system32\url.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\licmgr10.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\icardie.dll
2015-11-11 02:56:18 ----A---- C:\Windows\system32\inseng.dll
2015-11-11 02:56:17 ----A---- C:\Windows\system32\wextract.exe
2015-11-11 02:56:17 ----A---- C:\Windows\system32\iexpress.exe
2015-11-11 02:56:14 ----A---- C:\Windows\system32\pngfilt.dll
2015-11-11 02:56:14 ----A---- C:\Windows\system32\mshta.exe
2015-11-11 02:56:12 ----A---- C:\Windows\system32\imgutil.dll
2015-11-11 02:56:12 ----A---- C:\Windows\system32\iepeers.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:15 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2015-11-11 02:50:13 ----A---- C:\Windows\system32\dxgi.dll
2015-11-11 02:50:12 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10.dll
2015-11-11 02:50:09 ----A---- C:\Windows\system32\d3d10level9.dll
2015-11-11 02:50:08 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-11-11 02:50:07 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2015-11-11 02:50:07 ----A---- C:\Windows\system32\UIAnimation.dll
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFSvc.dll
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFPlatform.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFx.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFHost.exe
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2015-11-11 00:51:14 ----A---- C:\Windows\SYSWOW64\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups2.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wucltux.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-11 00:35:44 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\powertracker.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\perftrack.dll
2015-11-11 00:34:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\schannel.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\kerberos.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-11 00:34:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\kernel32.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-11 00:34:37 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-11 00:34:36 ----A---- C:\Windows\system32\wow64.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\winsrv.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\srcore.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\conhost.exe
2015-11-11 00:34:35 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-11 00:34:35 ----A---- C:\Windows\system32\rstrui.exe
2015-11-11 00:34:35 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-11 00:34:34 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\wdigest.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\sspicli.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\smss.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\srclient.dll
2015-11-11 00:34:33 ----A---- C:\Windows\system32\lsass.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\auditpol.exe
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64win.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-11 00:34:32 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\credssp.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-11 00:34:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-11 00:34:25 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-11 00:34:23 ----A---- C:\Windows\system32\adtschema.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msaudite.dll
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-11 00:21:44 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\aelupsvc.dll
2015-11-11 00:12:45 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-11 00:12:20 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-11 00:12:20 ----A---- C:\Windows\system32\InkEd.dll
2015-11-11 00:12:19 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-10 23:18:30 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-11-10 23:18:30 ----A---- C:\Windows\system32\ntshrui.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\CPFilters.dll
2015-11-10 23:18:08 ----A---- C:\Windows\system32\blackbox.dll
2015-11-10 23:18:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-10 23:18:06 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-10 23:18:05 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-10 23:17:59 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-10 23:17:59 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-10 23:17:57 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-10 23:17:56 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-10 23:17:55 ----A---- C:\Windows\system32\quartz.dll
2015-11-10 23:17:54 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\qdvd.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\mfplat.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\cryptui.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\EncDump.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\msscp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\pcadm.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\audiodg.exe
2015-11-10 23:17:49 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcalua.exe
2015-11-10 23:17:48 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\mferror.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\sysmain.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-10 23:17:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-10 23:16:34 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2015-11-10 23:16:34 ----A---- C:\Windows\system32\rdpcore.dll
2015-11-10 23:16:33 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2015-11-10 23:16:31 ----A---- C:\Windows\system32\drivers\tcpip.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\netio.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2015-11-10 23:16:05 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcore6.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmapi.dll
2015-11-10 23:15:33 ----A---- C:\Windows\system32\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-11-10 23:15:32 ----A---- C:\Windows\system32\mfc42.dll
2015-11-10 23:15:30 ----A---- C:\Windows\system32\localspl.dll
2015-11-10 23:15:16 ----A---- C:\Windows\system32\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\system32\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\logman.exe
2015-11-10 23:15:14 ----A---- C:\Windows\system32\diskperf.exe
2015-11-10 23:15:12 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-11-10 23:14:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-11-10 23:14:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-11-10 23:14:46 ----A---- C:\Windows\system32\drivers\fvevol.sys
2015-11-10 23:13:48 ----A---- C:\Windows\SYSWOW64\webio.dll
2015-11-10 23:13:48 ----A---- C:\Windows\system32\webio.dll
2015-11-10 23:13:44 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2015-11-10 23:13:44 ----A---- C:\Windows\system32\xmllite.dll
2015-11-10 23:13:42 ----A---- C:\Windows\system32\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\aaclient.dll
2015-11-10 23:13:24 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-10 23:13:24 ----A---- C:\Windows\system32\certcli.dll
2015-11-10 23:13:03 ----A---- C:\Windows\system32\termsrv.dll
2015-11-10 23:12:52 ----A---- C:\Windows\SYSWOW64\usp10.dll
2015-11-10 23:12:52 ----A---- C:\Windows\system32\usp10.dll
2015-11-10 23:12:48 ----A---- C:\Windows\system32\wmp.dll
2015-11-10 23:12:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\system32\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-10 23:12:28 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2015-11-10 23:12:28 ----A---- C:\Windows\system32\msieftp.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwansvc.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwanprotdim.dll
2015-11-10 23:12:21 ----A---- C:\Windows\system32\winlogon.exe
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdrmemptylst.exe
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdpwsx.dll
2015-11-10 23:12:19 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-10 23:11:58 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-10 23:11:58 ----A---- C:\Windows\system32\ubpm.dll
2015-11-10 23:11:57 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-10 23:11:54 ----A---- C:\Windows\system32\mscorier.dll
2015-11-10 23:11:53 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\dfshim.dll
2015-11-10 23:11:42 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-10 23:11:42 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-10 23:11:40 ----A---- C:\Windows\system32\drivers\ataport.sys
2015-11-10 23:11:38 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-11-10 23:11:26 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2015-11-10 23:11:26 ----A---- C:\Windows\system32\oleacc.dll
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\cdd.dll
2015-11-10 23:11:14 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2015-11-10 23:11:14 ----A---- C:\Windows\system32\prevhost.exe
2015-11-10 23:11:04 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-10 23:11:04 ----A---- C:\Windows\system32\rastls.dll
2015-11-10 23:11:02 ----A---- C:\Windows\system32\FXSCOVER.exe
2015-11-10 23:10:55 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfs.sys
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccu32.dll
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbccp32.dll
2015-11-10 23:09:57 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\tquery.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-11-10 23:09:57 ----A---- C:\Windows\system32\mssrch.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchFilterHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssphtb.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssph.dll
2015-11-10 23:09:55 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2015-11-10 23:09:55 ----A---- C:\Windows\system32\msscntrs.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2015-11-10 23:09:39 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-10 23:09:39 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-10 23:09:26 ----A---- C:\Windows\system32\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-10 23:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\portcls.sys
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\drmk.sys
2015-11-10 23:09:22 ----A---- C:\Windows\system32\profsvc.dll
2015-11-10 23:09:05 ----A---- C:\Windows\system32\basesrv.dll
2015-11-10 23:08:33 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-10 23:08:33 ----A---- C:\Windows\system32\tzres.dll
2015-11-10 23:08:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2015-11-10 23:08:20 ----A---- C:\Windows\system32\WMVDECOD.DLL
2015-11-10 23:08:17 ----A---- C:\Windows\SYSWOW64\osk.exe
2015-11-10 23:08:17 ----A---- C:\Windows\system32\osk.exe
2015-11-10 23:08:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winresume.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winload.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidapi.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-10 23:08:08 ----A---- C:\Windows\system32\ci.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-10 23:07:35 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2015-11-10 23:07:35 ----A---- C:\Windows\system32\d3d11.dll
2015-11-10 23:07:28 ----A---- C:\Windows\system32\comctl32.dll
2015-11-10 23:07:27 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-10 23:07:24 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-10 23:06:54 ----A---- C:\Windows\SYSWOW64\qedit.dll
2015-11-10 23:06:54 ----A---- C:\Windows\system32\qedit.dll
2015-11-10 23:06:44 ----A---- C:\Windows\system32\msi.dll
2015-11-10 23:06:43 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msiexec.exe
2015-11-10 23:06:19 ----A---- C:\Windows\system32\UtcResources.dll
2015-11-10 23:06:19 ----A---- C:\Windows\system32\diagtrack.dll
2015-11-10 23:06:16 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\advapi32.dll
2015-11-10 23:06:15 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\ucrtbase.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:04:26 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2015-11-10 23:04:26 ----A---- C:\Windows\system32\dpnet.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\gameux.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\gameux.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dpapiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\capiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\adprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\system32\wincredprovider.dll
2015-11-10 23:03:33 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2015-11-10 23:02:40 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\system32\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\notepad.exe
2015-11-10 23:02:29 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-10 23:02:29 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-10 23:02:26 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2015-11-10 23:02:26 ----A---- C:\Windows\system32\mswsock.dll
2015-11-10 23:02:24 ----A---- C:\Windows\system32\drivers\partmgr.sys
2015-11-10 23:02:19 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2015-11-10 23:02:19 ----A---- C:\Windows\system32\psisdecd.dll
2015-11-10 23:01:27 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\storport.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2015-11-10 23:01:13 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-10 23:01:13 ----A---- C:\Windows\system32\pku2u.dll
2015-11-10 23:01:01 ----A---- C:\Windows\SYSWOW64\synceng.dll
2015-11-10 23:01:01 ----A---- C:\Windows\system32\synceng.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdusb.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdcom.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kd1394.dll
2015-11-10 23:00:48 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2015-11-10 23:00:48 ----A---- C:\Windows\system32\shdocvw.dll
2015-11-10 23:00:33 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2015-11-10 23:00:33 ----A---- C:\Windows\system32\WsmSvc.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2015-11-10 23:00:28 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-10 23:00:28 ----A---- C:\Windows\system32\msctf.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3.dll
2015-11-10 23:00:08 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-10 23:00:08 ----A---- C:\Windows\system32\packager.dll
2015-11-10 23:00:07 ----A---- C:\Windows\system32\scesrv.dll
2015-11-10 23:00:06 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-10 23:00:05 ----A---- C:\Windows\SYSWOW64\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\scrrun.dll
2015-11-10 23:00:05 ----A---- C:\Windows\system32\cscript.exe
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\cscript.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devobj.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2015-11-10 22:59:44 ----A---- C:\Windows\system32\umpnpmgr.dll
2015-11-10 22:59:34 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2015-11-10 22:59:34 ----A---- C:\Windows\system32\cryptdlg.dll
2015-11-10 22:58:38 ----A---- C:\Windows\system32\drivers\bowser.sys
2015-11-10 22:58:25 ----A---- C:\Windows\SYSWOW64\certutil.exe
2015-11-10 22:58:25 ----A---- C:\Windows\system32\certutil.exe
2015-11-10 22:58:23 ----A---- C:\Windows\SYSWOW64\certenc.dll
2015-11-10 22:58:23 ----A---- C:\Windows\system32\certenc.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\browcli.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browser.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browcli.dll
2015-11-10 22:56:25 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-10 22:56:25 ----A---- C:\Windows\system32\poqexec.exe
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmfd.dll
2015-11-10 22:46:24 ----A---- C:\Windows\system32\wer.dll
2015-11-10 22:46:23 ----A---- C:\Windows\SYSWOW64\wer.dll
2015-11-10 22:45:08 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2015-11-10 22:45:08 ----A---- C:\Windows\system32\imagehlp.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-10 22:43:40 ----A---- C:\Windows\SYSWOW64\charmap.exe
2015-11-10 22:43:40 ----A---- C:\Windows\system32\charmap.exe
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\davclnt.dll
2015-11-10 22:43:26 ----A---- C:\Windows\system32\drivers\usb8023.sys
2015-11-10 22:43:08 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-10 22:42:41 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-10 22:42:41 ----A---- C:\Windows\system32\crypt32.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-10 22:42:06 ----A---- C:\Windows\system32\wpdshext.dll
2015-11-10 22:42:05 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-11-10 22:41:18 ----A---- C:\Windows\system32\OxpsConverter.exe
2015-11-10 22:40:40 ----A---- C:\Windows\system32\drivers\stream.sys
2015-11-10 22:39:34 ----A---- C:\Windows\system32\taskhost.exe
2015-11-10 22:36:02 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2015-11-10 22:36:02 ----A---- C:\Windows\system32\EncDec.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\generaltel.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\devinv.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-11-10 22:33:04 ----A---- C:\Windows\system32\aitstatic.exe
2015-11-10 22:33:03 ----A---- C:\Windows\system32\invagent.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\appraiser.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\aepic.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\acmigration.dll
2015-11-10 22:33:02 ----A---- C:\Windows\system32\aeinv.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\credui.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\credui.dll
2015-11-10 22:05:15 ----A---- C:\Windows\system32\drivers\usbcir.sys
2015-11-10 22:04:18 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-10 22:04:18 ----A---- C:\Windows\system32\ole32.dll
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsrslvr.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsapi.dll
2015-11-10 21:02:15 ----A---- C:\Windows\system32\TSWorkspace.dll
2015-11-10 21:02:14 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2015-11-10 20:53:11 ----A---- C:\Windows\system32\gdi32.dll
2015-11-10 20:53:10 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbport.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbehci.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbd.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2015-11-10 20:39:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2015-11-10 20:37:33 ----D---- C:\Program Files\trend micro
2015-11-10 20:37:17 ----D---- C:\rsit
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidparse.sys
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidclass.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv.sys
2015-11-10 20:04:19 ----A---- C:\Windows\system32\drivers\srvnet.sys
2015-11-10 19:51:33 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2015-11-10 19:51:33 ----A---- C:\Windows\system32\win32spl.dll
2015-11-10 19:49:39 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2015-11-10 19:49:39 ----A---- C:\Windows\system32\msvcrt.dll
2015-11-10 19:47:57 ----D---- C:\Windows\AutoKMS
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2015-11-10 19:41:24 ----A---- C:\Windows\system32\services.exe
2015-11-10 19:40:47 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\consent.exe
2015-11-10 19:40:43 ----A---- C:\Windows\system32\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\appinfo.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\nlaapi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\ncsi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\iphlpsvc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2015-11-10 19:39:51 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2015-11-10 19:39:48 ----A---- C:\Windows\system32\cdosys.dll
2015-11-10 19:39:27 ----A---- C:\Windows\system32\scavengeui.dll
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files\DESIGNER
2015-11-10 19:19:01 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-11-10 19:18:20 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-11-10 19:17:15 ----D---- C:\Windows\PCHEALTH
2015-11-10 19:17:15 ----D---- C:\Program Files\Microsoft SQL Server
2015-11-10 19:12:28 ----D---- C:\Program Files\Microsoft Analysis Services
2015-11-10 19:12:28 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-11-10 19:12:00 ----D---- C:\Program Files (x86)\Microsoft Office
2015-11-10 19:11:48 ----D---- C:\Program Files\Microsoft Office
2015-11-10 19:11:46 ----D---- C:\ProgramData\Microsoft Help
2015-11-10 19:10:14 ----RHD---- C:\MSOCache
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2015-11-08 21:46:36 ----A---- C:\Windows\system32\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\system32\icardagt.exe
2015-11-08 21:46:35 ----A---- C:\Windows\SYSWOW64\icardres.dll
2015-11-08 21:46:35 ----A---- C:\Windows\system32\icardres.dll
2015-11-08 21:46:26 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2015-11-08 21:46:26 ----A---- C:\Windows\system32\TsWpfWrp.exe
2015-11-08 21:45:32 ----D---- C:\Users\Be\AppData\Roaming\WinRAR
2015-11-08 21:03:45 ----A---- C:\Windows\system32\Wdfres.dll
2015-11-08 21:03:45 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2015-11-08 20:50:08 ----D---- C:\Program Files\WinRAR
2015-11-08 19:42:42 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\msdrm.dll
2015-11-08 19:34:27 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-08 19:16:56 ----D---- C:\Users\Be\AppData\Roaming\ESET
2015-11-08 19:07:39 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2015-11-08 18:56:40 ----D---- C:\Program Files\ESET
2015-11-08 18:56:39 ----D---- C:\ProgramData\ESET
2015-11-08 18:45:11 ----D---- C:\Users\Be\AppData\Roaming\ATI
2015-11-08 18:45:11 ----D---- C:\ProgramData\ATI
2015-11-08 18:39:40 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-11-08 18:32:37 ----D---- C:\ProgramData\AMD
2015-11-08 18:32:31 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\AMD AVT
2015-11-08 18:30:33 ----D---- C:\Program Files (x86)\ATI Technologies
2015-11-08 18:26:05 ----D---- C:\Users\Be\AppData\Roaming\AVG
2015-11-08 18:25:52 ----D---- C:\Program Files (x86)\AVG
2015-11-08 18:24:32 ----D---- C:\Program Files\AMD
2015-11-08 18:23:03 ----A---- C:\Windows\un_dext.exe
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.src
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.ini
2015-11-08 18:23:03 ----A---- C:\Windows\SYSWOW64\VCamPPage.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\VCamPPage_x64.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\drivers\SPUVCBv_x64.sys
2015-11-08 18:23:02 ----D---- C:\Program Files (x86)\HP Camera Driver
2015-11-08 18:23:02 ----A---- C:\Windows\system32\CoInstaller_x64.dll
2015-11-08 18:23:02 ----A---- C:\Windows\SPRemove_x64.exe
2015-11-08 18:23:02 ----A---- C:\Windows\remove.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_36.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_31.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_30.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_29.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_27.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_25.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_24.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_22.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_21.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_2052.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_20.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_19.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_18.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_17.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_16.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_14.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_13.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_12.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_11.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_1046.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_10.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_09.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_08.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_07.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_06.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_05.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_04.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_02.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_01.ini
2015-11-08 18:21:35 ----HD---- C:\ProgramData\Common Files
2015-11-08 18:21:34 ----D---- C:\ProgramData\AVG
2015-11-08 18:18:45 ----D---- C:\Users\Be\AppData\Roaming\Opera Software
2015-11-08 18:14:16 ----D---- C:\Program Files (x86)\Opera
2015-11-08 18:13:52 ----D---- C:\Users\Be\AppData\Roaming\RHEng
2015-11-08 18:13:52 ----D---- C:\Program Files (x86)\Disc Soft
2015-11-08 18:12:46 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-11-08 18:12:45 ----D---- C:\Users\Be\AppData\Roaming\DAEMON Tools Lite
2015-11-08 18:12:43 ----D---- C:\Program Files\DAEMON Tools Lite
2015-11-08 18:12:22 ----D---- C:\ProgramData\DAEMON Tools Lite
2015-11-08 18:11:50 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-08 18:09:02 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-11-08 18:07:13 ----D---- C:\b28b719981fddbf1baa95a
2015-11-08 18:06:18 ----D---- C:\Program Files\ATI Technologies
2015-11-08 18:06:14 ----D---- C:\Program Files\ATI
2015-11-08 18:05:42 ----D---- C:\Users\Be\AppData\Roaming\Adobe
2015-11-08 18:04:20 ----D---- C:\Users\Be\AppData\Roaming\Hola
2015-11-08 18:03:20 ----D---- C:\Program Files\Hola
2015-11-08 18:01:20 ----D---- C:\Users\Be\AppData\Roaming\IrfanView
2015-11-08 18:01:20 ----D---- C:\Program Files (x86)\IrfanView
2015-11-08 18:00:25 ----D---- C:\Program Files (x86)\Adobe
2015-11-08 17:59:15 ----D---- C:\ProgramData\Adobe
2015-11-08 17:57:31 ----D---- C:\Users\Be\AppData\Roaming\vlc
2015-11-08 17:56:57 ----D---- C:\Program Files (x86)\VideoLAN
2015-11-08 17:53:40 ----D---- C:\Program Files (x86)\Intel
2015-11-08 17:53:11 ----D---- C:\Program Files\Intel
2015-11-08 17:50:15 ----D---- C:\Intel
2015-11-08 17:42:12 ----D---- C:\Program Files (x86)\Google
2015-11-08 00:16:10 ----D---- C:\Users\Be\AppData\Roaming\TeamViewer
2015-11-08 00:05:01 ----D---- C:\Users\Be\AppData\Roaming\uTorrent
2015-11-08 00:04:12 ----HD---- C:\Windows\AxInstSV
2015-11-08 00:01:30 ----SHD---- C:\Windows\Installer
2015-11-08 00:01:25 ----D---- C:\ProgramData\Package Cache
2015-11-08 00:00:15 ----HD---- C:\system.sav
2015-11-07 23:26:23 ----D---- C:\ProgramData\Qualcomm Atheros
2015-11-07 23:12:05 ----A---- C:\Windows\HPSetLog.txt
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RTNUninst64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RtNicProp64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2015-11-07 23:01:08 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-11-07 23:01:08 ----D---- C:\Program Files (x86)\Realtek
2015-11-07 23:00:49 ----D---- C:\SWSetup

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#2 Příspěvek od Brigit900 »

2015-11-07 22:45:15 ----D---- C:\Users\Be\AppData\Roaming\Identities
2015-11-07 22:44:55 ----SD---- C:\Users\Be\AppData\Roaming\Microsoft
2015-11-07 22:44:55 ----D---- C:\Users\Be\AppData\Roaming\Media Center Programs
2015-11-07 22:44:42 ----SHD---- C:\Recovery
2015-11-07 22:39:23 ----D---- C:\Windows\SoftwareDistribution
2015-11-07 22:36:42 ----D---- C:\Windows\Prefetch
2015-11-07 22:35:45 ----ASH---- C:\pagefile.sys
2015-11-07 22:35:44 ----SHD---- C:\System Volume Information
2015-11-07 22:35:44 ----ASH---- C:\hiberfil.sys
2015-11-07 22:35:18 ----D---- C:\Windows\Panther
2015-11-07 22:35:06 ----RASH---- C:\BOOTSECT.BAK
2015-11-07 22:35:03 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 month======

2015-11-25 21:24:59 ----D---- C:\Windows\Temp
2015-11-25 21:20:19 ----D---- C:\Windows\system32\config
2015-11-25 21:14:46 ----RD---- C:\Program Files (x86)
2015-11-25 21:14:45 ----HD---- C:\ProgramData
2015-11-25 21:01:21 ----D---- C:\Windows\system32\drivers
2015-11-24 21:30:09 ----D---- C:\Windows\System32
2015-11-24 21:30:09 ----D---- C:\Windows\inf
2015-11-24 21:30:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-11-23 21:01:27 ----D---- C:\Windows\winsxs
2015-11-20 00:42:44 ----RSD---- C:\Windows\assembly
2015-11-20 00:37:39 ----A---- C:\Windows\win.ini
2015-11-19 23:13:59 ----D---- C:\Windows\rescache
2015-11-19 23:07:59 ----D---- C:\Windows\Logs
2015-11-18 20:56:50 ----D---- C:\Windows\AppCompat
2015-11-18 20:46:15 ----D---- C:\Windows\system32\Tasks
2015-11-18 20:44:49 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-11-18 20:44:49 ----D---- C:\Windows\SysWOW64
2015-11-18 20:44:48 ----D---- C:\Windows\system32\sk-SK
2015-11-18 20:44:48 ----D---- C:\Windows\PolicyDefinitions
2015-11-18 20:44:41 ----RSD---- C:\Windows\Fonts
2015-11-18 20:44:40 ----D---- C:\Windows\tracing
2015-11-18 20:44:39 ----D---- C:\Program Files\Internet Explorer
2015-11-18 20:44:38 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-18 20:44:36 ----D---- C:\Windows\system32\en-US
2015-11-18 20:44:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-18 20:44:16 ----D---- C:\Windows\AppPatch
2015-11-18 20:44:09 ----D---- C:\Windows\system32\migration
2015-11-18 20:44:06 ----D---- C:\Windows\system32\DriverStore
2015-11-12 00:48:01 ----D---- C:\Windows\system32\wdi
2015-11-12 00:44:03 ----D---- C:\Windows\debug
2015-11-12 00:42:14 ----D---- C:\Windows\Microsoft.NET
2015-11-12 00:34:07 ----RD---- C:\Program Files
2015-11-12 00:34:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-11-11 23:40:43 ----D---- C:\Program Files\Windows Journal
2015-11-11 23:32:11 ----D---- C:\Windows\system32\catroot2
2015-11-11 22:09:22 ----D---- C:\Windows
2015-11-11 21:51:21 ----D---- C:\Windows\ehome
2015-11-11 21:51:15 ----D---- C:\Program Files\Windows Media Player
2015-11-11 21:51:15 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-11 21:51:12 ----D---- C:\Program Files\Common Files\System
2015-11-11 21:51:00 ----D---- C:\Windows\SYSWOW64\migration
2015-11-11 21:50:38 ----D---- C:\Windows\SYSWOW64\pt-BR
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\pt-PT
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\it-IT
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\pl-PL
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\ko-KR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-TW
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-HK
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\tr-TR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\sv-SE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\nl-NL
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\hu-HU
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fr-FR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fi-FI
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\es-ES
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\el-GR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\de-DE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\zh-CN
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ru-RU
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\nb-NO
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ja-JP
2015-11-11 21:50:33 ----D---- C:\Windows\SYSWOW64\da-DK
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-PT
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-BR
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pl-PL
2015-11-11 21:50:29 ----D---- C:\Windows\system32\it-IT
2015-11-11 21:50:28 ----D---- C:\Windows\system32\zh-HK
2015-11-11 21:50:28 ----D---- C:\Windows\system32\ko-KR
2015-11-11 21:50:28 ----D---- C:\Windows\system32\hu-HU
2015-11-11 21:50:28 ----D---- C:\Windows\system32\el-GR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\zh-TW
2015-11-11 21:50:27 ----D---- C:\Windows\system32\tr-TR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\sv-SE
2015-11-11 21:50:27 ----D---- C:\Windows\system32\nl-NL
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fr-FR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fi-FI
2015-11-11 21:50:27 ----D---- C:\Windows\system32\es-ES
2015-11-11 21:50:27 ----D---- C:\Windows\system32\de-DE
2015-11-11 21:50:25 ----D---- C:\Windows\system32\zh-CN
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ru-RU
2015-11-11 21:50:25 ----D---- C:\Windows\system32\nb-NO
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ja-JP
2015-11-11 21:50:25 ----D---- C:\Windows\system32\cs-CZ
2015-11-11 21:50:24 ----D---- C:\Windows\system32\da-DK
2015-11-11 21:50:17 ----D---- C:\Windows\system32\drivers\en-US
2015-11-11 21:50:07 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-11 21:50:01 ----D---- C:\Windows\system32\Dism
2015-11-11 21:49:15 ----D---- C:\Windows\system32\AdvancedInstallers
2015-11-11 21:49:09 ----D---- C:\Program Files (x86)\Windows Defender
2015-11-11 21:49:08 ----D---- C:\Program Files\Windows Defender
2015-11-11 21:49:05 ----D---- C:\Windows\system32\wbem
2015-11-11 21:49:01 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-11 21:49:01 ----D---- C:\Windows\system32\Boot
2015-11-11 21:48:51 ----SD---- C:\ProgramData\Microsoft
2015-11-11 21:46:41 ----D---- C:\Windows\system32\drivers\UMDF
2015-11-11 03:30:52 ----D---- C:\Windows\system32\catroot
2015-11-10 19:20:07 ----D---- C:\Windows\ShellNew
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files
2015-11-08 20:48:56 ----D---- C:\Windows\SYSWOW64\drivers
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\Common Files
2015-11-08 18:25:42 ----D---- C:\Windows\twain_32
2015-11-08 17:42:18 ----D---- C:\Windows\Tasks
2015-11-07 23:00:52 ----D---- C:\Windows\system32\restore
2015-11-07 22:45:11 ----SHD---- C:\$Recycle.Bin
2015-11-07 22:44:54 ----RD---- C:\Users
2015-11-07 22:41:39 ----D---- C:\Windows\system32\sysprep
2015-11-07 22:36:37 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2013-12-14 36608]
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 67792]
R0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2014-08-25 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-08-11 249544]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 179544]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 49240]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 222256]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-04-10 16751616]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-04-10 579584]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2015-11-08 30264]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-02-03 4860856]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2014-08-25 383984]
R3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2014-08-25 795120]
R3 NETwNs64;___ Intel(R) Wireless Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw02.sys [2014-12-08 3437848]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-03-28 918232]
R3 SPUVCbv;SPUVCb Driver Service; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2014-10-07 674592]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-02-09 455440]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-04-10 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [2015-08-05 1042064]
R2 hola_svc;Hola Better Internet Engine; C:\Program Files\Hola\app\hola_svc.exe [2015-11-08 8126592]
R2 hola_updater;Hola Better Internet Updater; C:\Program Files\Hola\app\hola_updater.exe [2015-11-08 8126592]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-02-03 344976]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1268568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-02-03 279952]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [2015-08-05 44744]
S3 ESHASRV;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [2015-08-05 192200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-01-25 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-11-11 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: zdetekovane rovnake IP

#3 Příspěvek od Rudy »

Zdravím!
Tento problém je otázkou nastavení sítě. Pro jistotu se podíváme do systému. Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#4 Příspěvek od Brigit900 »

Scan som vykonala, ak dobre vidim vymazali sa iba subory z aplikacie Hola (sluzi na zmenu IP, pouzivam to na zmenu mojej IP na urcitych strankach, aby som mohla sledovat zahranicne TV vysielanie)
Problem vsak nadalej pretrvava, mam nastavit v PC pevnu IP adresu?
Dakujem za pomoc :)




# AdwCleaner v5.022 - Logfile created 25/11/2015 at 23:24:22
# Updated 22/11/2015 by Xplode
# Database : 2015-11-22.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Be - HP-PC
# Running from : C:\Users\Be\Downloads\adwcleaner_5.022.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : hola_svc
[-] Service Deleted : hola_updater

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\Hola
[-] Folder Deleted : C:\Users\Be\AppData\Local\Hola
[-] Folder Deleted : C:\Users\Be\AppData\Roaming\RHEng
[-] Folder Deleted : C:\Users\Be\AppData\Roaming\Hola

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\MozillaPlugins\@hola.org/FlashPlayer
[-] Key Deleted : HKCU\Software\MozillaPlugins\@hola.org/vlc
[-] Key Deleted : HKCU\Software\Hola
[-] Key Deleted : [x64] HKLM\SOFTWARE\Hola
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hola
[-] Key Deleted : HKU\.DEFAULT\Software\Hola

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1288 bytes] ##########
Naposledy upravil(a) Brigit900 dne 25 lis 2015 23:34, celkem upraveno 1 x.

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#5 Příspěvek od Brigit900 »

a co znamena toto?

25. 11. 2015 23:31:30 Zachytený útok ARP cache poisoning 192.168.1.1 192.168.1.11 ARP






:( :( :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: zdetekovane rovnake IP

#6 Příspěvek od Rudy »

Půjde nejspíše o toto: https://servis.eset.cz/knowledgebase/ar ... lc5vl6Lpdg IP adresy jsou adresami vnitřní sítě. Záškodník by musel být k vaší síti přímo připojen. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#7 Příspěvek od Brigit900 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Be at 2015-11-26 20:30:33
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 896 GB (94%) free of 954 GB
Total RAM: 3987 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:30:35, on 26. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Be.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [HP Camera Driver_Monitor] "C:\Program Files (x86)\HP Camera Driver\monitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.hola.org
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9186 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe"
"C:\Program Files\ESET\ESET Endpoint Security\egui.exe" /hide /waitservice
"C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1796_009D79D0_861744988 µTorrent4823DF041B09 uTorrent
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1796_009D7A80_570233514 µTorrent4823DF041B09 uTorrent
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer.exe" --noInstallation --dre
"C:\Users\Be\AppData\Local\Temp\TeamViewer\tv_w32.exe" --action hooks --log C:\Users\Be\AppData\Roaming\TeamViewer\TeamViewer10_Logfile.log
"C:\Users\Be\AppData\Local\Temp\TeamViewer\tv_x64.exe" --action hooks --log C:\Users\Be\AppData\Roaming\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
taskeng.exe {2D100AA6-E9EE-4031-80DD-94749D18A2A1}
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\sppsvc.exe
taskeng.exe {9E10D5B5-807F-4602-ADC2-AA2D102DD5DF}
"c:\users\be\appdata\local\temp\teamviewer\TeamViewer_Desktop.exe" --IPCport 6039

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3804.0.107315810\1859478998" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x0000 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1002.1008 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3804.2.1885217632\1062241354" --font-cache-shared-handle=2368 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3804.3.1899883715\598314331" --font-cache-shared-handle=2572 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3804.5.1840621770\358048394" --font-cache-shared-handle=4524 /prefetch:673131151

C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Be\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20 153768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"hola"=C:\Program Files\Hola\app\hola.exe --silent []
"egui"=C:\Program Files\ESET\ESET Endpoint Security\egui.exe [2015-08-05 4150472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe [2015-11-08 1822048]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-06-18 4468056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Camera Driver_Monitor"=C:\Program Files (x86)\HP Camera Driver\monitor.exe []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-04-10 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-08-25 293872]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-25 23:23:01 ----D---- C:\AdwCleaner
2015-11-20 00:18:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-11-19 20:29:53 ----A---- C:\Windows\system32\win32k.sys
2015-11-12 00:44:03 ----D---- C:\Windows\system32\MRT
2015-11-12 00:43:41 ----A---- C:\Windows\system32\MRT.exe
2015-11-12 00:34:07 ----D---- C:\Program Files\Microsoft.NET
2015-11-11 23:42:15 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2015-11-11 23:42:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDBASH.DLL
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\iernonce.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-11 23:34:03 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 23:34:02 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\urlmon.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\occache.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 23:34:00 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\iesetup.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-11 23:33:58 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-11 23:33:58 ----A---- C:\Windows\system32\iertutil.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-11 23:33:57 ----A---- C:\Windows\system32\vbscript.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieui.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieframe.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\wininet.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\webcheck.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\msrating.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\mshtml.dll
2015-11-11 23:32:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2015-11-11 23:32:52 ----A---- C:\Windows\system32\d2d1.dll
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\bthport.sys
2015-11-11 23:28:47 ----A---- C:\Windows\system32\fsutil.exe
2015-11-11 23:28:47 ----A---- C:\Windows\system32\esent.dll
2015-11-11 23:28:47 ----A---- C:\Windows\system32\drivers\amdxata.sys
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\esent.dll
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvstor.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvraid.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\amdsata.sys
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\FntCache.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-11 22:39:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-11 22:39:26 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-11 22:39:10 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-11 22:39:10 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-11 21:49:05 ----SD---- C:\Windows\system32\CompatTel
2015-11-11 21:49:05 ----D---- C:\Windows\system32\appraiser
2015-11-11 21:48:55 ----D---- C:\Windows\SYSWOW64\Wat
2015-11-11 21:48:55 ----D---- C:\Windows\system32\Wat
2015-11-11 21:48:46 ----SD---- C:\Windows\SYSWOW64\GWX
2015-11-11 21:48:46 ----SD---- C:\Windows\system32\GWX
2015-11-11 21:48:46 ----D---- C:\Windows\Migration
2015-11-11 03:07:03 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:07:03 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:04:43 ----A---- C:\Windows\system32\IEUDINIT.EXE
2015-11-11 02:56:42 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\msls31.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2015-11-11 02:56:37 ----A---- C:\Windows\system32\elshyph.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\url.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\icardie.dll
2015-11-11 02:56:33 ----A---- C:\Windows\SYSWOW64\inseng.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\wextract.exe
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\mshta.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2015-11-11 02:56:26 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-11-11 02:56:26 ----A---- C:\Windows\system32\jsIntl.dll
2015-11-11 02:56:25 ----A---- C:\Windows\system32\msls31.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedssync.exe
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-11-11 02:56:23 ----A---- C:\Windows\system32\mshtmler.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\iesysprep.dll
2015-11-11 02:56:21 ----A---- C:\Windows\system32\ieapfltr.dat
2015-11-11 02:56:19 ----A---- C:\Windows\system32\url.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\licmgr10.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\icardie.dll
2015-11-11 02:56:18 ----A---- C:\Windows\system32\inseng.dll
2015-11-11 02:56:17 ----A---- C:\Windows\system32\wextract.exe
2015-11-11 02:56:17 ----A---- C:\Windows\system32\iexpress.exe
2015-11-11 02:56:14 ----A---- C:\Windows\system32\pngfilt.dll
2015-11-11 02:56:14 ----A---- C:\Windows\system32\mshta.exe
2015-11-11 02:56:12 ----A---- C:\Windows\system32\imgutil.dll
2015-11-11 02:56:12 ----A---- C:\Windows\system32\iepeers.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:15 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2015-11-11 02:50:13 ----A---- C:\Windows\system32\dxgi.dll
2015-11-11 02:50:12 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10.dll
2015-11-11 02:50:09 ----A---- C:\Windows\system32\d3d10level9.dll
2015-11-11 02:50:08 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-11-11 02:50:07 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2015-11-11 02:50:07 ----A---- C:\Windows\system32\UIAnimation.dll
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFSvc.dll
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFPlatform.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFx.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFHost.exe
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2015-11-11 00:51:14 ----A---- C:\Windows\SYSWOW64\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups2.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wucltux.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-11 00:35:44 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\powertracker.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\perftrack.dll
2015-11-11 00:34:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\schannel.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\kerberos.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-11 00:34:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\kernel32.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-11 00:34:37 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-11 00:34:36 ----A---- C:\Windows\system32\wow64.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\winsrv.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\srcore.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\conhost.exe
2015-11-11 00:34:35 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-11 00:34:35 ----A---- C:\Windows\system32\rstrui.exe
2015-11-11 00:34:35 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-11 00:34:34 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\wdigest.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\sspicli.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\smss.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\srclient.dll
2015-11-11 00:34:33 ----A---- C:\Windows\system32\lsass.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\auditpol.exe
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64win.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-11 00:34:32 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\credssp.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-11 00:34:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-11 00:34:25 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-11 00:34:23 ----A---- C:\Windows\system32\adtschema.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msaudite.dll
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-11 00:21:44 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\aelupsvc.dll
2015-11-11 00:12:45 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-11 00:12:20 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-11 00:12:20 ----A---- C:\Windows\system32\InkEd.dll
2015-11-11 00:12:19 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-10 23:18:30 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-11-10 23:18:30 ----A---- C:\Windows\system32\ntshrui.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\CPFilters.dll
2015-11-10 23:18:08 ----A---- C:\Windows\system32\blackbox.dll
2015-11-10 23:18:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-10 23:18:06 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-10 23:18:05 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-10 23:17:59 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-10 23:17:59 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-10 23:17:57 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-10 23:17:56 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-10 23:17:55 ----A---- C:\Windows\system32\quartz.dll
2015-11-10 23:17:54 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\qdvd.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\mfplat.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\cryptui.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\EncDump.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\msscp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\pcadm.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\audiodg.exe
2015-11-10 23:17:49 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcalua.exe
2015-11-10 23:17:48 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\mferror.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\sysmain.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-10 23:17:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-10 23:16:34 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2015-11-10 23:16:34 ----A---- C:\Windows\system32\rdpcore.dll
2015-11-10 23:16:33 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2015-11-10 23:16:31 ----A---- C:\Windows\system32\drivers\tcpip.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\netio.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2015-11-10 23:16:05 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcore6.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmapi.dll
2015-11-10 23:15:33 ----A---- C:\Windows\system32\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-11-10 23:15:32 ----A---- C:\Windows\system32\mfc42.dll
2015-11-10 23:15:30 ----A---- C:\Windows\system32\localspl.dll
2015-11-10 23:15:16 ----A---- C:\Windows\system32\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\system32\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\logman.exe
2015-11-10 23:15:14 ----A---- C:\Windows\system32\diskperf.exe
2015-11-10 23:15:12 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-11-10 23:14:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-11-10 23:14:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-11-10 23:14:46 ----A---- C:\Windows\system32\drivers\fvevol.sys
2015-11-10 23:13:48 ----A---- C:\Windows\SYSWOW64\webio.dll
2015-11-10 23:13:48 ----A---- C:\Windows\system32\webio.dll
2015-11-10 23:13:44 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2015-11-10 23:13:44 ----A---- C:\Windows\system32\xmllite.dll
2015-11-10 23:13:42 ----A---- C:\Windows\system32\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\aaclient.dll
2015-11-10 23:13:24 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-10 23:13:24 ----A---- C:\Windows\system32\certcli.dll
2015-11-10 23:13:03 ----A---- C:\Windows\system32\termsrv.dll
2015-11-10 23:12:52 ----A---- C:\Windows\SYSWOW64\usp10.dll
2015-11-10 23:12:52 ----A---- C:\Windows\system32\usp10.dll
2015-11-10 23:12:48 ----A---- C:\Windows\system32\wmp.dll
2015-11-10 23:12:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\system32\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-10 23:12:28 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2015-11-10 23:12:28 ----A---- C:\Windows\system32\msieftp.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwansvc.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwanprotdim.dll
2015-11-10 23:12:21 ----A---- C:\Windows\system32\winlogon.exe
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdrmemptylst.exe
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdpwsx.dll
2015-11-10 23:12:19 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-10 23:11:58 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-10 23:11:58 ----A---- C:\Windows\system32\ubpm.dll
2015-11-10 23:11:57 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-10 23:11:54 ----A---- C:\Windows\system32\mscorier.dll
2015-11-10 23:11:53 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\dfshim.dll
2015-11-10 23:11:42 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-10 23:11:42 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-10 23:11:40 ----A---- C:\Windows\system32\drivers\ataport.sys
2015-11-10 23:11:38 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-11-10 23:11:26 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2015-11-10 23:11:26 ----A---- C:\Windows\system32\oleacc.dll
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\cdd.dll
2015-11-10 23:11:14 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2015-11-10 23:11:14 ----A---- C:\Windows\system32\prevhost.exe
2015-11-10 23:11:04 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-10 23:11:04 ----A---- C:\Windows\system32\rastls.dll
2015-11-10 23:11:02 ----A---- C:\Windows\system32\FXSCOVER.exe
2015-11-10 23:10:55 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfs.sys
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccu32.dll
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbccp32.dll
2015-11-10 23:09:57 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\tquery.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-11-10 23:09:57 ----A---- C:\Windows\system32\mssrch.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchFilterHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssphtb.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssph.dll
2015-11-10 23:09:55 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2015-11-10 23:09:55 ----A---- C:\Windows\system32\msscntrs.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2015-11-10 23:09:39 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-10 23:09:39 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-10 23:09:26 ----A---- C:\Windows\system32\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-10 23:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\portcls.sys
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\drmk.sys
2015-11-10 23:09:22 ----A---- C:\Windows\system32\profsvc.dll
2015-11-10 23:09:05 ----A---- C:\Windows\system32\basesrv.dll
2015-11-10 23:08:33 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-10 23:08:33 ----A---- C:\Windows\system32\tzres.dll
2015-11-10 23:08:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2015-11-10 23:08:20 ----A---- C:\Windows\system32\WMVDECOD.DLL
2015-11-10 23:08:17 ----A---- C:\Windows\SYSWOW64\osk.exe
2015-11-10 23:08:17 ----A---- C:\Windows\system32\osk.exe
2015-11-10 23:08:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winresume.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winload.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidapi.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-10 23:08:08 ----A---- C:\Windows\system32\ci.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-10 23:07:35 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2015-11-10 23:07:35 ----A---- C:\Windows\system32\d3d11.dll
2015-11-10 23:07:28 ----A---- C:\Windows\system32\comctl32.dll
2015-11-10 23:07:27 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-10 23:07:24 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-10 23:06:54 ----A---- C:\Windows\SYSWOW64\qedit.dll
2015-11-10 23:06:54 ----A---- C:\Windows\system32\qedit.dll
2015-11-10 23:06:44 ----A---- C:\Windows\system32\msi.dll
2015-11-10 23:06:43 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msiexec.exe
2015-11-10 23:06:19 ----A---- C:\Windows\system32\UtcResources.dll
2015-11-10 23:06:19 ----A---- C:\Windows\system32\diagtrack.dll
2015-11-10 23:06:16 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\advapi32.dll
2015-11-10 23:06:15 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\ucrtbase.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:04:26 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2015-11-10 23:04:26 ----A---- C:\Windows\system32\dpnet.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\gameux.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\gameux.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dpapiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\capiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\adprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\system32\wincredprovider.dll
2015-11-10 23:03:33 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2015-11-10 23:02:40 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\system32\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\notepad.exe
2015-11-10 23:02:29 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-10 23:02:29 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-10 23:02:26 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2015-11-10 23:02:26 ----A---- C:\Windows\system32\mswsock.dll
2015-11-10 23:02:24 ----A---- C:\Windows\system32\drivers\partmgr.sys
2015-11-10 23:02:19 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2015-11-10 23:02:19 ----A---- C:\Windows\system32\psisdecd.dll
2015-11-10 23:01:27 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\storport.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2015-11-10 23:01:13 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-10 23:01:13 ----A---- C:\Windows\system32\pku2u.dll
2015-11-10 23:01:01 ----A---- C:\Windows\SYSWOW64\synceng.dll
2015-11-10 23:01:01 ----A---- C:\Windows\system32\synceng.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdusb.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdcom.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kd1394.dll
2015-11-10 23:00:48 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2015-11-10 23:00:48 ----A---- C:\Windows\system32\shdocvw.dll
2015-11-10 23:00:33 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2015-11-10 23:00:33 ----A---- C:\Windows\system32\WsmSvc.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2015-11-10 23:00:28 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-10 23:00:28 ----A---- C:\Windows\system32\msctf.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3.dll
2015-11-10 23:00:08 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-10 23:00:08 ----A---- C:\Windows\system32\packager.dll
2015-11-10 23:00:07 ----A---- C:\Windows\system32\scesrv.dll
2015-11-10 23:00:06 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-10 23:00:05 ----A---- C:\Windows\SYSWOW64\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\scrrun.dll
2015-11-10 23:00:05 ----A---- C:\Windows\system32\cscript.exe
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\cscript.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devobj.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2015-11-10 22:59:44 ----A---- C:\Windows\system32\umpnpmgr.dll
2015-11-10 22:59:34 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2015-11-10 22:59:34 ----A---- C:\Windows\system32\cryptdlg.dll
2015-11-10 22:58:38 ----A---- C:\Windows\system32\drivers\bowser.sys
2015-11-10 22:58:25 ----A---- C:\Windows\SYSWOW64\certutil.exe
2015-11-10 22:58:25 ----A---- C:\Windows\system32\certutil.exe
2015-11-10 22:58:23 ----A---- C:\Windows\SYSWOW64\certenc.dll
2015-11-10 22:58:23 ----A---- C:\Windows\system32\certenc.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\browcli.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browser.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browcli.dll
2015-11-10 22:56:25 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-10 22:56:25 ----A---- C:\Windows\system32\poqexec.exe
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmfd.dll
2015-11-10 22:46:24 ----A---- C:\Windows\system32\wer.dll
2015-11-10 22:46:23 ----A---- C:\Windows\SYSWOW64\wer.dll
2015-11-10 22:45:08 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2015-11-10 22:45:08 ----A---- C:\Windows\system32\imagehlp.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-10 22:43:40 ----A---- C:\Windows\SYSWOW64\charmap.exe
2015-11-10 22:43:40 ----A---- C:\Windows\system32\charmap.exe
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\davclnt.dll
2015-11-10 22:43:26 ----A---- C:\Windows\system32\drivers\usb8023.sys
2015-11-10 22:43:08 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-10 22:42:41 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-10 22:42:41 ----A---- C:\Windows\system32\crypt32.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-10 22:42:06 ----A---- C:\Windows\system32\wpdshext.dll
2015-11-10 22:42:05 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-11-10 22:41:18 ----A---- C:\Windows\system32\OxpsConverter.exe
2015-11-10 22:40:40 ----A---- C:\Windows\system32\drivers\stream.sys
2015-11-10 22:39:34 ----A---- C:\Windows\system32\taskhost.exe
2015-11-10 22:36:02 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2015-11-10 22:36:02 ----A---- C:\Windows\system32\EncDec.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\generaltel.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\devinv.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-11-10 22:33:04 ----A---- C:\Windows\system32\aitstatic.exe
2015-11-10 22:33:03 ----A---- C:\Windows\system32\invagent.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\appraiser.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\aepic.dll

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#8 Příspěvek od Brigit900 »

2015-11-10 22:33:03 ----A---- C:\Windows\system32\acmigration.dll
2015-11-10 22:33:02 ----A---- C:\Windows\system32\aeinv.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\credui.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\credui.dll
2015-11-10 22:05:15 ----A---- C:\Windows\system32\drivers\usbcir.sys
2015-11-10 22:04:18 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-10 22:04:18 ----A---- C:\Windows\system32\ole32.dll
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsrslvr.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsapi.dll
2015-11-10 21:02:15 ----A---- C:\Windows\system32\TSWorkspace.dll
2015-11-10 21:02:14 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2015-11-10 20:53:11 ----A---- C:\Windows\system32\gdi32.dll
2015-11-10 20:53:10 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbport.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbehci.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbd.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2015-11-10 20:39:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2015-11-10 20:37:33 ----D---- C:\Program Files\trend micro
2015-11-10 20:37:17 ----D---- C:\rsit
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidparse.sys
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidclass.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv.sys
2015-11-10 20:04:19 ----A---- C:\Windows\system32\drivers\srvnet.sys
2015-11-10 19:51:33 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2015-11-10 19:51:33 ----A---- C:\Windows\system32\win32spl.dll
2015-11-10 19:49:39 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2015-11-10 19:49:39 ----A---- C:\Windows\system32\msvcrt.dll
2015-11-10 19:47:57 ----D---- C:\Windows\AutoKMS
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2015-11-10 19:41:24 ----A---- C:\Windows\system32\services.exe
2015-11-10 19:40:47 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\consent.exe
2015-11-10 19:40:43 ----A---- C:\Windows\system32\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\appinfo.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\nlaapi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\ncsi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\iphlpsvc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2015-11-10 19:39:51 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2015-11-10 19:39:48 ----A---- C:\Windows\system32\cdosys.dll
2015-11-10 19:39:27 ----A---- C:\Windows\system32\scavengeui.dll
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files\DESIGNER
2015-11-10 19:19:01 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-11-10 19:18:20 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-11-10 19:17:15 ----D---- C:\Windows\PCHEALTH
2015-11-10 19:17:15 ----D---- C:\Program Files\Microsoft SQL Server
2015-11-10 19:12:28 ----D---- C:\Program Files\Microsoft Analysis Services
2015-11-10 19:12:28 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-11-10 19:12:00 ----D---- C:\Program Files (x86)\Microsoft Office
2015-11-10 19:11:48 ----D---- C:\Program Files\Microsoft Office
2015-11-10 19:11:46 ----D---- C:\ProgramData\Microsoft Help
2015-11-10 19:10:14 ----RHD---- C:\MSOCache
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2015-11-08 21:46:36 ----A---- C:\Windows\system32\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\system32\icardagt.exe
2015-11-08 21:46:35 ----A---- C:\Windows\SYSWOW64\icardres.dll
2015-11-08 21:46:35 ----A---- C:\Windows\system32\icardres.dll
2015-11-08 21:46:26 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2015-11-08 21:46:26 ----A---- C:\Windows\system32\TsWpfWrp.exe
2015-11-08 21:45:32 ----D---- C:\Users\Be\AppData\Roaming\WinRAR
2015-11-08 21:03:45 ----A---- C:\Windows\system32\Wdfres.dll
2015-11-08 21:03:45 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2015-11-08 20:50:08 ----D---- C:\Program Files\WinRAR
2015-11-08 19:42:42 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\msdrm.dll
2015-11-08 19:34:27 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-08 19:16:56 ----D---- C:\Users\Be\AppData\Roaming\ESET
2015-11-08 19:07:39 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2015-11-08 18:56:40 ----D---- C:\Program Files\ESET
2015-11-08 18:56:39 ----D---- C:\ProgramData\ESET
2015-11-08 18:45:11 ----D---- C:\Users\Be\AppData\Roaming\ATI
2015-11-08 18:45:11 ----D---- C:\ProgramData\ATI
2015-11-08 18:39:40 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-11-08 18:32:37 ----D---- C:\ProgramData\AMD
2015-11-08 18:32:31 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\AMD AVT
2015-11-08 18:30:33 ----D---- C:\Program Files (x86)\ATI Technologies
2015-11-08 18:26:05 ----D---- C:\Users\Be\AppData\Roaming\AVG
2015-11-08 18:25:52 ----D---- C:\Program Files (x86)\AVG
2015-11-08 18:24:32 ----D---- C:\Program Files\AMD
2015-11-08 18:23:03 ----A---- C:\Windows\un_dext.exe
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.src
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.ini
2015-11-08 18:23:03 ----A---- C:\Windows\SYSWOW64\VCamPPage.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\VCamPPage_x64.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\drivers\SPUVCBv_x64.sys
2015-11-08 18:23:02 ----D---- C:\Program Files (x86)\HP Camera Driver
2015-11-08 18:23:02 ----A---- C:\Windows\system32\CoInstaller_x64.dll
2015-11-08 18:23:02 ----A---- C:\Windows\SPRemove_x64.exe
2015-11-08 18:23:02 ----A---- C:\Windows\remove.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_36.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_31.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_30.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_29.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_27.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_25.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_24.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_22.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_21.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_2052.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_20.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_19.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_18.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_17.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_16.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_14.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_13.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_12.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_11.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_1046.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_10.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_09.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_08.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_07.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_06.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_05.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_04.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_02.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_01.ini
2015-11-08 18:21:35 ----HD---- C:\ProgramData\Common Files
2015-11-08 18:21:34 ----D---- C:\ProgramData\AVG
2015-11-08 18:18:45 ----D---- C:\Users\Be\AppData\Roaming\Opera Software
2015-11-08 18:14:16 ----D---- C:\Program Files (x86)\Opera
2015-11-08 18:13:52 ----D---- C:\Program Files (x86)\Disc Soft
2015-11-08 18:12:46 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-11-08 18:12:45 ----D---- C:\Users\Be\AppData\Roaming\DAEMON Tools Lite
2015-11-08 18:12:43 ----D---- C:\Program Files\DAEMON Tools Lite
2015-11-08 18:12:22 ----D---- C:\ProgramData\DAEMON Tools Lite
2015-11-08 18:11:50 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-08 18:09:02 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-11-08 18:07:13 ----D---- C:\b28b719981fddbf1baa95a
2015-11-08 18:06:18 ----D---- C:\Program Files\ATI Technologies
2015-11-08 18:06:14 ----D---- C:\Program Files\ATI
2015-11-08 18:05:42 ----D---- C:\Users\Be\AppData\Roaming\Adobe
2015-11-08 18:01:20 ----D---- C:\Users\Be\AppData\Roaming\IrfanView
2015-11-08 18:01:20 ----D---- C:\Program Files (x86)\IrfanView
2015-11-08 18:00:25 ----D---- C:\Program Files (x86)\Adobe
2015-11-08 17:59:15 ----D---- C:\ProgramData\Adobe
2015-11-08 17:57:31 ----D---- C:\Users\Be\AppData\Roaming\vlc
2015-11-08 17:56:57 ----D---- C:\Program Files (x86)\VideoLAN
2015-11-08 17:53:40 ----D---- C:\Program Files (x86)\Intel
2015-11-08 17:53:11 ----D---- C:\Program Files\Intel
2015-11-08 17:50:15 ----D---- C:\Intel
2015-11-08 17:42:12 ----D---- C:\Program Files (x86)\Google
2015-11-08 00:16:10 ----D---- C:\Users\Be\AppData\Roaming\TeamViewer
2015-11-08 00:05:01 ----D---- C:\Users\Be\AppData\Roaming\uTorrent
2015-11-08 00:04:12 ----HD---- C:\Windows\AxInstSV
2015-11-08 00:01:30 ----SHD---- C:\Windows\Installer
2015-11-08 00:01:25 ----D---- C:\ProgramData\Package Cache
2015-11-08 00:00:15 ----HD---- C:\system.sav
2015-11-07 23:26:23 ----D---- C:\ProgramData\Qualcomm Atheros
2015-11-07 23:12:05 ----A---- C:\Windows\HPSetLog.txt
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RTNUninst64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RtNicProp64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2015-11-07 23:01:08 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-11-07 23:01:08 ----D---- C:\Program Files (x86)\Realtek
2015-11-07 23:00:49 ----D---- C:\SWSetup
2015-11-07 22:45:15 ----D---- C:\Users\Be\AppData\Roaming\Identities
2015-11-07 22:44:55 ----SD---- C:\Users\Be\AppData\Roaming\Microsoft
2015-11-07 22:44:55 ----D---- C:\Users\Be\AppData\Roaming\Media Center Programs
2015-11-07 22:44:42 ----SHD---- C:\Recovery
2015-11-07 22:39:23 ----D---- C:\Windows\SoftwareDistribution
2015-11-07 22:36:42 ----D---- C:\Windows\Prefetch
2015-11-07 22:35:45 ----ASH---- C:\pagefile.sys
2015-11-07 22:35:44 ----SHD---- C:\System Volume Information
2015-11-07 22:35:44 ----ASH---- C:\hiberfil.sys
2015-11-07 22:35:18 ----D---- C:\Windows\Panther
2015-11-07 22:35:06 ----RASH---- C:\BOOTSECT.BAK
2015-11-07 22:35:03 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 month======

2015-11-26 20:30:34 ----D---- C:\Windows\Temp
2015-11-26 20:20:07 ----D---- C:\Windows\system32\config
2015-11-25 23:24:45 ----RD---- C:\Program Files
2015-11-25 23:20:55 ----D---- C:\Windows\system32\wdi
2015-11-25 21:14:46 ----RD---- C:\Program Files (x86)
2015-11-25 21:14:45 ----HD---- C:\ProgramData
2015-11-25 21:01:21 ----D---- C:\Windows\system32\drivers
2015-11-24 21:30:09 ----D---- C:\Windows\System32
2015-11-24 21:30:09 ----D---- C:\Windows\inf
2015-11-24 21:30:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-11-23 21:01:27 ----D---- C:\Windows\winsxs
2015-11-20 00:42:44 ----RSD---- C:\Windows\assembly
2015-11-20 00:37:39 ----A---- C:\Windows\win.ini
2015-11-19 23:13:59 ----D---- C:\Windows\rescache
2015-11-19 23:07:59 ----D---- C:\Windows\Logs
2015-11-18 20:56:50 ----D---- C:\Windows\AppCompat
2015-11-18 20:46:15 ----D---- C:\Windows\system32\Tasks
2015-11-18 20:44:49 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-11-18 20:44:49 ----D---- C:\Windows\SysWOW64
2015-11-18 20:44:48 ----D---- C:\Windows\system32\sk-SK
2015-11-18 20:44:48 ----D---- C:\Windows\PolicyDefinitions
2015-11-18 20:44:41 ----RSD---- C:\Windows\Fonts
2015-11-18 20:44:40 ----D---- C:\Windows\tracing
2015-11-18 20:44:39 ----D---- C:\Program Files\Internet Explorer
2015-11-18 20:44:38 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-18 20:44:36 ----D---- C:\Windows\system32\en-US
2015-11-18 20:44:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-18 20:44:16 ----D---- C:\Windows\AppPatch
2015-11-18 20:44:09 ----D---- C:\Windows\system32\migration
2015-11-18 20:44:06 ----D---- C:\Windows\system32\DriverStore
2015-11-12 00:44:03 ----D---- C:\Windows\debug
2015-11-12 00:42:14 ----D---- C:\Windows\Microsoft.NET
2015-11-12 00:34:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-11-11 23:40:43 ----D---- C:\Program Files\Windows Journal
2015-11-11 23:32:11 ----D---- C:\Windows\system32\catroot2
2015-11-11 22:09:22 ----D---- C:\Windows
2015-11-11 21:51:21 ----D---- C:\Windows\ehome
2015-11-11 21:51:15 ----D---- C:\Program Files\Windows Media Player
2015-11-11 21:51:15 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-11 21:51:12 ----D---- C:\Program Files\Common Files\System
2015-11-11 21:51:00 ----D---- C:\Windows\SYSWOW64\migration
2015-11-11 21:50:38 ----D---- C:\Windows\SYSWOW64\pt-BR
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\pt-PT
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\it-IT
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\pl-PL
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\ko-KR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-TW
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-HK
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\tr-TR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\sv-SE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\nl-NL
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\hu-HU
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fr-FR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fi-FI
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\es-ES
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\el-GR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\de-DE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\zh-CN
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ru-RU
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\nb-NO
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ja-JP
2015-11-11 21:50:33 ----D---- C:\Windows\SYSWOW64\da-DK
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-PT
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-BR
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pl-PL
2015-11-11 21:50:29 ----D---- C:\Windows\system32\it-IT
2015-11-11 21:50:28 ----D---- C:\Windows\system32\zh-HK
2015-11-11 21:50:28 ----D---- C:\Windows\system32\ko-KR
2015-11-11 21:50:28 ----D---- C:\Windows\system32\hu-HU
2015-11-11 21:50:28 ----D---- C:\Windows\system32\el-GR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\zh-TW
2015-11-11 21:50:27 ----D---- C:\Windows\system32\tr-TR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\sv-SE
2015-11-11 21:50:27 ----D---- C:\Windows\system32\nl-NL
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fr-FR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fi-FI
2015-11-11 21:50:27 ----D---- C:\Windows\system32\es-ES
2015-11-11 21:50:27 ----D---- C:\Windows\system32\de-DE
2015-11-11 21:50:25 ----D---- C:\Windows\system32\zh-CN
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ru-RU
2015-11-11 21:50:25 ----D---- C:\Windows\system32\nb-NO
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ja-JP
2015-11-11 21:50:25 ----D---- C:\Windows\system32\cs-CZ
2015-11-11 21:50:24 ----D---- C:\Windows\system32\da-DK
2015-11-11 21:50:17 ----D---- C:\Windows\system32\drivers\en-US
2015-11-11 21:50:07 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-11 21:50:01 ----D---- C:\Windows\system32\Dism
2015-11-11 21:49:15 ----D---- C:\Windows\system32\AdvancedInstallers
2015-11-11 21:49:09 ----D---- C:\Program Files (x86)\Windows Defender
2015-11-11 21:49:08 ----D---- C:\Program Files\Windows Defender
2015-11-11 21:49:05 ----D---- C:\Windows\system32\wbem
2015-11-11 21:49:01 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-11 21:49:01 ----D---- C:\Windows\system32\Boot
2015-11-11 21:48:51 ----SD---- C:\ProgramData\Microsoft
2015-11-11 21:46:41 ----D---- C:\Windows\system32\drivers\UMDF
2015-11-11 03:30:52 ----D---- C:\Windows\system32\catroot
2015-11-10 19:20:07 ----D---- C:\Windows\ShellNew
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files
2015-11-08 20:48:56 ----D---- C:\Windows\SYSWOW64\drivers
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\Common Files
2015-11-08 18:25:42 ----D---- C:\Windows\twain_32
2015-11-08 17:42:18 ----D---- C:\Windows\Tasks
2015-11-07 23:00:52 ----D---- C:\Windows\system32\restore
2015-11-07 22:45:11 ----SHD---- C:\$Recycle.Bin
2015-11-07 22:44:54 ----RD---- C:\Users
2015-11-07 22:41:39 ----D---- C:\Windows\system32\sysprep
2015-11-07 22:36:37 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2013-12-14 36608]
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 67792]
R0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2014-08-25 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-08-11 249544]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 179544]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 49240]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 222256]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-04-10 16751616]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-04-10 579584]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2015-11-08 30264]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-02-03 4860856]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2014-08-25 383984]
R3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2014-08-25 795120]
R3 NETwNs64;___ Intel(R) Wireless Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw02.sys [2014-12-08 3437848]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-03-28 918232]
R3 SPUVCbv;SPUVCb Driver Service; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2014-10-07 674592]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-02-09 455440]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-04-10 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [2015-08-05 1042064]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-02-03 344976]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1268568]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-02-03 279952]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [2015-08-05 44744]
S3 ESHASRV;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [2015-08-05 192200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-01-25 178760]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-11-11 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: zdetekovane rovnake IP

#9 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\AutoKMS
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#10 Příspěvek od Brigit900 »

All processes killed
========== FILES ==========
C:\Windows\AutoKMS folder moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Be
->Temp folder emptied: 215370386 bytes
->Temporary Internet Files folder emptied: 90456969 bytes
->Google Chrome cache emptied: 359382311 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 154960083 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 58525348 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 838,00 mb


[EMPTYFLASH]

User: All Users

User: Be

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 11262015_213929

Files moved on Reboot...
C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer10_Logfile.log moved successfully.
C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer_Service.exe moved successfully.
C:\Users\Be\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#11 Příspěvek od Brigit900 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Be at 2015-11-26 21:54:42
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 898 GB (94%) free of 954 GB
Total RAM: 3987 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:54:44, on 26. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Be.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [HP Camera Driver_Monitor] "C:\Program Files (x86)\HP Camera Driver\monitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.hola.org
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9186 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {A9EB4ABA-DBCC-46B1-A676-389A3C04BC1D}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\11262015_213929.log
"C:\Program Files\ESET\ESET Endpoint Security\egui.exe" /hide /waitservice
"C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1400_0393DC10_325698357 µTorrent4823DF041B09 uTorrent
"C:\Users\Be\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe" uTorrent_1400_0393E240_867724803 µTorrent4823DF041B09 uTorrent
"C:\Users\Be\AppData\Local\Temp\TeamViewer\TeamViewer.exe" --noInstallation --dre
"C:\Users\Be\AppData\Local\Temp\TeamViewer\tv_w32.exe" --action hooks --log C:\Users\Be\AppData\Roaming\TeamViewer\TeamViewer10_Logfile.log
"C:\Users\Be\AppData\Local\Temp\TeamViewer\tv_x64.exe" --action hooks --log C:\Users\Be\AppData\Roaming\TeamViewer\TeamViewer10_Logfile.log
"c:\users\be\appdata\local\temp\teamviewer\TeamViewer_Desktop.exe" --IPCport 6039
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3888.0.901450017\149565546" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x0000 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1002.1008 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3888.2.1156179255\1224477206" --font-cache-shared-handle=2080 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3888.3.441216433\901199110" --font-cache-shared-handle=2716 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3888.5.603526544\2008523930" --font-cache-shared-handle=4160 /prefetch:673131151
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Be\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20 153768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"hola"=C:\Program Files\Hola\app\hola.exe --silent []
"egui"=C:\Program Files\ESET\ESET Endpoint Security\egui.exe [2015-08-05 4150472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\Be\AppData\Roaming\uTorrent\uTorrent.exe [2015-11-08 1822048]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-06-18 4468056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Camera Driver_Monitor"=C:\Program Files (x86)\HP Camera Driver\monitor.exe []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-04-10 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-08-25 293872]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-26 21:39:29 ----D---- C:\_OTM
2015-11-25 23:23:01 ----D---- C:\AdwCleaner
2015-11-20 00:18:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-11-19 20:29:53 ----A---- C:\Windows\system32\win32k.sys
2015-11-12 00:44:03 ----D---- C:\Windows\system32\MRT
2015-11-12 00:43:41 ----A---- C:\Windows\system32\MRT.exe
2015-11-12 00:34:07 ----D---- C:\Program Files\Microsoft.NET
2015-11-11 23:42:15 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2015-11-11 23:42:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDYAK.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDTAT.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU1.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDRU.DLL
2015-11-11 23:34:31 ----A---- C:\Windows\system32\KBDBASH.DLL
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\iernonce.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-11 23:34:04 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-11 23:34:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-11 23:34:03 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 23:34:02 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-11 23:34:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-11 23:34:00 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\urlmon.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\occache.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 23:34:00 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-11 23:34:00 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-11 23:33:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\iesetup.dll
2015-11-11 23:33:59 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-11 23:33:58 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-11 23:33:58 ----A---- C:\Windows\system32\iertutil.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-11 23:33:57 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-11 23:33:57 ----A---- C:\Windows\system32\vbscript.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-11 23:33:57 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieui.dll
2015-11-11 23:33:56 ----A---- C:\Windows\system32\ieframe.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\wininet.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\webcheck.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript9.dll
2015-11-11 23:33:55 ----A---- C:\Windows\system32\jscript.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\msrating.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-11 23:33:54 ----A---- C:\Windows\system32\mshtml.dll
2015-11-11 23:32:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2015-11-11 23:32:52 ----A---- C:\Windows\system32\d2d1.dll
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-11-11 23:32:50 ----A---- C:\Windows\system32\drivers\bthport.sys
2015-11-11 23:28:47 ----A---- C:\Windows\system32\fsutil.exe
2015-11-11 23:28:47 ----A---- C:\Windows\system32\esent.dll
2015-11-11 23:28:47 ----A---- C:\Windows\system32\drivers\amdxata.sys
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2015-11-11 23:28:46 ----A---- C:\Windows\SYSWOW64\esent.dll
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvstor.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\nvraid.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2015-11-11 23:28:46 ----A---- C:\Windows\system32\drivers\amdsata.sys
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\FntCache.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\DWrite.dll
2015-11-11 22:39:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-11 22:39:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-11 22:39:26 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-11 22:39:10 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-11 22:39:10 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-11 21:49:05 ----SD---- C:\Windows\system32\CompatTel
2015-11-11 21:49:05 ----D---- C:\Windows\system32\appraiser
2015-11-11 21:48:55 ----D---- C:\Windows\SYSWOW64\Wat
2015-11-11 21:48:55 ----D---- C:\Windows\system32\Wat
2015-11-11 21:48:46 ----SD---- C:\Windows\SYSWOW64\GWX
2015-11-11 21:48:46 ----SD---- C:\Windows\system32\GWX
2015-11-11 21:48:46 ----D---- C:\Windows\Migration
2015-11-11 03:07:03 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:07:03 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-11 03:04:43 ----A---- C:\Windows\system32\IEUDINIT.EXE
2015-11-11 02:56:42 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\msls31.dll
2015-11-11 02:56:37 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2015-11-11 02:56:37 ----A---- C:\Windows\system32\elshyph.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\url.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2015-11-11 02:56:34 ----A---- C:\Windows\SYSWOW64\icardie.dll
2015-11-11 02:56:33 ----A---- C:\Windows\SYSWOW64\inseng.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\wextract.exe
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2015-11-11 02:56:32 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\mshta.exe
2015-11-11 02:56:30 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2015-11-11 02:56:29 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2015-11-11 02:56:28 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2015-11-11 02:56:27 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2015-11-11 02:56:26 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-11-11 02:56:26 ----A---- C:\Windows\system32\jsIntl.dll
2015-11-11 02:56:25 ----A---- C:\Windows\system32\msls31.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedssync.exe
2015-11-11 02:56:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-11-11 02:56:24 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-11-11 02:56:23 ----A---- C:\Windows\system32\mshtmler.dll
2015-11-11 02:56:23 ----A---- C:\Windows\system32\iesysprep.dll
2015-11-11 02:56:21 ----A---- C:\Windows\system32\ieapfltr.dat
2015-11-11 02:56:19 ----A---- C:\Windows\system32\url.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\licmgr10.dll
2015-11-11 02:56:19 ----A---- C:\Windows\system32\icardie.dll
2015-11-11 02:56:18 ----A---- C:\Windows\system32\inseng.dll
2015-11-11 02:56:17 ----A---- C:\Windows\system32\wextract.exe
2015-11-11 02:56:17 ----A---- C:\Windows\system32\iexpress.exe
2015-11-11 02:56:14 ----A---- C:\Windows\system32\pngfilt.dll
2015-11-11 02:56:14 ----A---- C:\Windows\system32\mshta.exe
2015-11-11 02:56:12 ----A---- C:\Windows\system32\imgutil.dll
2015-11-11 02:56:12 ----A---- C:\Windows\system32\iepeers.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-11-11 02:50:16 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-11-11 02:50:15 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-11-11 02:50:14 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsPrint.dll
2015-11-11 02:50:14 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2015-11-11 02:50:13 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2015-11-11 02:50:13 ----A---- C:\Windows\system32\dxgi.dll
2015-11-11 02:50:12 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10_1.dll
2015-11-11 02:50:11 ----A---- C:\Windows\system32\d3d10.dll
2015-11-11 02:50:09 ----A---- C:\Windows\system32\d3d10level9.dll
2015-11-11 02:50:08 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-11-11 02:50:07 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2015-11-11 02:50:07 ----A---- C:\Windows\system32\UIAnimation.dll
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2015-11-11 01:07:22 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFSvc.dll
2015-11-11 01:07:21 ----A---- C:\Windows\system32\WUDFPlatform.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFx.dll
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFHost.exe
2015-11-11 01:07:20 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2015-11-11 00:51:14 ----A---- C:\Windows\SYSWOW64\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\wmi.dll
2015-11-11 00:51:14 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups2.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wups.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wudriver.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wucltux.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapp.exe
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wuapi.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 00:37:12 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-11 00:35:44 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\wdi.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\powertracker.dll
2015-11-11 00:35:44 ----A---- C:\Windows\system32\perftrack.dll
2015-11-11 00:34:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-11 00:34:40 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\schannel.dll
2015-11-11 00:34:40 ----A---- C:\Windows\system32\kerberos.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-11 00:34:39 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-11 00:34:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\ntdll.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\kernel32.dll
2015-11-11 00:34:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-11 00:34:37 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-11 00:34:36 ----A---- C:\Windows\system32\wow64.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\winsrv.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\srcore.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-11 00:34:36 ----A---- C:\Windows\system32\conhost.exe
2015-11-11 00:34:35 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-11 00:34:35 ----A---- C:\Windows\system32\rstrui.exe
2015-11-11 00:34:35 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-11 00:34:34 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\wdigest.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\sspicli.dll
2015-11-11 00:34:34 ----A---- C:\Windows\system32\smss.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-11 00:34:33 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\srclient.dll
2015-11-11 00:34:33 ----A---- C:\Windows\system32\lsass.exe
2015-11-11 00:34:33 ----A---- C:\Windows\system32\auditpol.exe
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64win.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\secur32.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-11 00:34:32 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-11 00:34:32 ----A---- C:\Windows\system32\credssp.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-11 00:34:31 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-11 00:34:31 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-11 00:34:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 00:34:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 00:34:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 00:34:26 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 00:34:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 00:34:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-11 00:34:25 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 00:34:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 00:34:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-11 00:34:23 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-11 00:34:23 ----A---- C:\Windows\system32\adtschema.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msobjs.dll
2015-11-11 00:34:22 ----A---- C:\Windows\system32\msaudite.dll
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-11 00:28:19 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-11 00:21:44 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\shimeng.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\sdbinst.exe
2015-11-11 00:21:43 ----A---- C:\Windows\system32\apphelp.dll
2015-11-11 00:21:43 ----A---- C:\Windows\system32\aelupsvc.dll
2015-11-11 00:12:45 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-11 00:12:20 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-11 00:12:20 ----A---- C:\Windows\system32\InkEd.dll
2015-11-11 00:12:19 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-10 23:18:30 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2015-11-10 23:18:30 ----A---- C:\Windows\system32\ntshrui.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\sbe.dll
2015-11-10 23:18:26 ----A---- C:\Windows\system32\CPFilters.dll
2015-11-10 23:18:08 ----A---- C:\Windows\system32\blackbox.dll
2015-11-10 23:18:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-10 23:18:06 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-10 23:18:05 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\mf.dll
2015-11-10 23:18:01 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-10 23:17:59 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-10 23:17:59 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-10 23:17:57 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-10 23:17:56 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-10 23:17:55 ----A---- C:\Windows\system32\quartz.dll
2015-11-10 23:17:54 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\qdvd.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\mfplat.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\evr.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\cryptui.dll
2015-11-10 23:17:54 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-10 23:17:53 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\EncDump.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-10 23:17:53 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-10 23:17:52 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\msscp.dll
2015-11-10 23:17:52 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\pcadm.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfps.dll
2015-11-10 23:17:50 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-10 23:17:50 ----A---- C:\Windows\system32\audiodg.exe
2015-11-10 23:17:49 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-10 23:17:49 ----A---- C:\Windows\system32\pcalua.exe
2015-11-10 23:17:48 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-10 23:17:48 ----A---- C:\Windows\system32\mferror.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\sysmain.dll
2015-11-10 23:17:11 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-10 23:17:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-10 23:16:34 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2015-11-10 23:16:34 ----A---- C:\Windows\system32\rdpcore.dll
2015-11-10 23:16:33 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2015-11-10 23:16:31 ----A---- C:\Windows\system32\drivers\tcpip.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\netio.sys
2015-11-10 23:16:30 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2015-11-10 23:16:05 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2015-11-10 23:15:41 ----A---- C:\Windows\system32\dhcpcore6.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-11-10 23:15:35 ----A---- C:\Windows\system32\dwmapi.dll
2015-11-10 23:15:33 ----A---- C:\Windows\system32\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-11-10 23:15:32 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-11-10 23:15:32 ----A---- C:\Windows\system32\mfc42.dll
2015-11-10 23:15:30 ----A---- C:\Windows\system32\localspl.dll
2015-11-10 23:15:16 ----A---- C:\Windows\system32\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\typeperf.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\sechost.dll
2015-11-10 23:15:15 ----A---- C:\Windows\system32\relog.exe
2015-11-10 23:15:15 ----A---- C:\Windows\system32\logman.exe
2015-11-10 23:15:14 ----A---- C:\Windows\system32\diskperf.exe
2015-11-10 23:15:12 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-11-10 23:14:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-11-10 23:14:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-11-10 23:14:46 ----A---- C:\Windows\system32\drivers\fvevol.sys
2015-11-10 23:13:48 ----A---- C:\Windows\SYSWOW64\webio.dll
2015-11-10 23:13:48 ----A---- C:\Windows\system32\webio.dll
2015-11-10 23:13:44 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2015-11-10 23:13:44 ----A---- C:\Windows\system32\xmllite.dll
2015-11-10 23:13:42 ----A---- C:\Windows\system32\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-10 23:13:41 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-10 23:13:41 ----A---- C:\Windows\system32\aaclient.dll
2015-11-10 23:13:24 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-10 23:13:24 ----A---- C:\Windows\system32\certcli.dll
2015-11-10 23:13:03 ----A---- C:\Windows\system32\termsrv.dll
2015-11-10 23:12:52 ----A---- C:\Windows\SYSWOW64\usp10.dll
2015-11-10 23:12:52 ----A---- C:\Windows\system32\usp10.dll
2015-11-10 23:12:48 ----A---- C:\Windows\system32\wmp.dll
2015-11-10 23:12:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-10 23:12:40 ----A---- C:\Windows\system32\spwmp.dll
2015-11-10 23:12:40 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-10 23:12:28 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2015-11-10 23:12:28 ----A---- C:\Windows\system32\msieftp.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwansvc.dll
2015-11-10 23:12:27 ----A---- C:\Windows\system32\wwanprotdim.dll
2015-11-10 23:12:21 ----A---- C:\Windows\system32\winlogon.exe
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\winsta.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-10 23:12:20 ----A---- C:\Windows\system32\mstsc.exe
2015-11-10 23:12:20 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdrmemptylst.exe
2015-11-10 23:12:19 ----A---- C:\Windows\system32\rdpwsx.dll
2015-11-10 23:12:19 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-10 23:11:58 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-10 23:11:58 ----A---- C:\Windows\system32\ubpm.dll
2015-11-10 23:11:57 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-10 23:11:54 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-10 23:11:54 ----A---- C:\Windows\system32\mscorier.dll
2015-11-10 23:11:53 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\mscories.dll
2015-11-10 23:11:53 ----A---- C:\Windows\system32\dfshim.dll
2015-11-10 23:11:42 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-10 23:11:42 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-10 23:11:40 ----A---- C:\Windows\system32\drivers\ataport.sys
2015-11-10 23:11:38 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-11-10 23:11:26 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2015-11-10 23:11:26 ----A---- C:\Windows\system32\oleacc.dll
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-11-10 23:11:16 ----A---- C:\Windows\system32\cdd.dll
2015-11-10 23:11:14 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2015-11-10 23:11:14 ----A---- C:\Windows\system32\prevhost.exe
2015-11-10 23:11:04 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-10 23:11:04 ----A---- C:\Windows\system32\rastls.dll
2015-11-10 23:11:02 ----A---- C:\Windows\system32\FXSCOVER.exe
2015-11-10 23:10:55 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-10 23:10:55 ----A---- C:\Windows\system32\clfs.sys
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccu32.dll
2015-11-10 23:10:01 ----A---- C:\Windows\system32\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbctrac.dll
2015-11-10 23:10:00 ----A---- C:\Windows\system32\odbccp32.dll
2015-11-10 23:09:57 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\tquery.dll
2015-11-10 23:09:57 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-11-10 23:09:57 ----A---- C:\Windows\system32\mssrch.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\SearchFilterHost.exe
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssvp.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssphtb.dll
2015-11-10 23:09:56 ----A---- C:\Windows\system32\mssph.dll
2015-11-10 23:09:55 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2015-11-10 23:09:55 ----A---- C:\Windows\system32\msscntrs.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2015-11-10 23:09:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2015-11-10 23:09:39 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-10 23:09:39 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-10 23:09:26 ----A---- C:\Windows\system32\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-10 23:09:25 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-10 23:09:25 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\portcls.sys
2015-11-10 23:09:23 ----A---- C:\Windows\system32\drivers\drmk.sys
2015-11-10 23:09:22 ----A---- C:\Windows\system32\profsvc.dll
2015-11-10 23:09:05 ----A---- C:\Windows\system32\basesrv.dll
2015-11-10 23:08:33 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-10 23:08:33 ----A---- C:\Windows\system32\tzres.dll
2015-11-10 23:08:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2015-11-10 23:08:20 ----A---- C:\Windows\system32\WMVDECOD.DLL
2015-11-10 23:08:17 ----A---- C:\Windows\SYSWOW64\osk.exe
2015-11-10 23:08:17 ----A---- C:\Windows\system32\osk.exe
2015-11-10 23:08:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winresume.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\winload.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-10 23:08:09 ----A---- C:\Windows\system32\appidapi.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-10 23:08:08 ----A---- C:\Windows\system32\ci.dll
2015-11-10 23:08:08 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-10 23:07:35 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2015-11-10 23:07:35 ----A---- C:\Windows\system32\d3d11.dll
2015-11-10 23:07:28 ----A---- C:\Windows\system32\comctl32.dll
2015-11-10 23:07:27 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-10 23:07:24 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-10 23:06:54 ----A---- C:\Windows\SYSWOW64\qedit.dll
2015-11-10 23:06:54 ----A---- C:\Windows\system32\qedit.dll
2015-11-10 23:06:44 ----A---- C:\Windows\system32\msi.dll
2015-11-10 23:06:43 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msimsg.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msihnd.dll
2015-11-10 23:06:42 ----A---- C:\Windows\system32\msiexec.exe
2015-11-10 23:06:19 ----A---- C:\Windows\system32\UtcResources.dll
2015-11-10 23:06:19 ----A---- C:\Windows\system32\diagtrack.dll
2015-11-10 23:06:16 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\tdh.dll
2015-11-10 23:06:16 ----A---- C:\Windows\system32\advapi32.dll
2015-11-10 23:06:15 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\ucrtbase.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-11-10 23:05:46 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2015-11-10 23:05:45 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-11-10 23:05:45 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-11-10 23:04:26 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2015-11-10 23:04:26 ----A---- C:\Windows\system32\dpnet.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\SYSWOW64\gameux.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\Wpc.dll
2015-11-10 23:04:20 ----A---- C:\Windows\system32\gameux.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\objsel.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dpapiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\dimsroam.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\cngprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\capiprovider.dll
2015-11-10 23:03:35 ----A---- C:\Windows\system32\adprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2015-11-10 23:03:34 ----A---- C:\Windows\system32\wincredprovider.dll
2015-11-10 23:03:33 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll

Brigit900
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 25 lis 2015 21:23

Re: zdetekovane rovnake IP

#12 Příspěvek od Brigit900 »

2015-11-10 23:02:40 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\system32\notepad.exe
2015-11-10 23:02:40 ----A---- C:\Windows\notepad.exe
2015-11-10 23:02:29 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-10 23:02:29 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-10 23:02:26 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2015-11-10 23:02:26 ----A---- C:\Windows\system32\mswsock.dll
2015-11-10 23:02:24 ----A---- C:\Windows\system32\drivers\partmgr.sys
2015-11-10 23:02:19 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2015-11-10 23:02:19 ----A---- C:\Windows\system32\psisdecd.dll
2015-11-10 23:01:27 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\iologmsg.dll
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\storport.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2015-11-10 23:01:27 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2015-11-10 23:01:13 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-10 23:01:13 ----A---- C:\Windows\system32\pku2u.dll
2015-11-10 23:01:01 ----A---- C:\Windows\SYSWOW64\synceng.dll
2015-11-10 23:01:01 ----A---- C:\Windows\system32\synceng.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdusb.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kdcom.dll
2015-11-10 23:00:57 ----A---- C:\Windows\system32\kd1394.dll
2015-11-10 23:00:48 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2015-11-10 23:00:48 ----A---- C:\Windows\system32\shdocvw.dll
2015-11-10 23:00:33 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2015-11-10 23:00:33 ----A---- C:\Windows\system32\WsmSvc.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmWmiPl.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WsmAuto.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2015-11-10 23:00:31 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2015-11-10 23:00:28 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-10 23:00:28 ----A---- C:\Windows\system32\msctf.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml6.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-10 23:00:24 ----A---- C:\Windows\system32\msxml3.dll
2015-11-10 23:00:08 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-10 23:00:08 ----A---- C:\Windows\system32\packager.dll
2015-11-10 23:00:07 ----A---- C:\Windows\system32\scesrv.dll
2015-11-10 23:00:06 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-10 23:00:05 ----A---- C:\Windows\SYSWOW64\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\wscript.exe
2015-11-10 23:00:05 ----A---- C:\Windows\system32\scrrun.dll
2015-11-10 23:00:05 ----A---- C:\Windows\system32\cscript.exe
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2015-11-10 23:00:04 ----A---- C:\Windows\SYSWOW64\cscript.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\devobj.dll
2015-11-10 22:59:44 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2015-11-10 22:59:44 ----A---- C:\Windows\system32\umpnpmgr.dll
2015-11-10 22:59:34 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2015-11-10 22:59:34 ----A---- C:\Windows\system32\cryptdlg.dll
2015-11-10 22:58:38 ----A---- C:\Windows\system32\drivers\bowser.sys
2015-11-10 22:58:25 ----A---- C:\Windows\SYSWOW64\certutil.exe
2015-11-10 22:58:25 ----A---- C:\Windows\system32\certutil.exe
2015-11-10 22:58:23 ----A---- C:\Windows\SYSWOW64\certenc.dll
2015-11-10 22:58:23 ----A---- C:\Windows\system32\certenc.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\SYSWOW64\browcli.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\netapi32.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browser.dll
2015-11-10 22:58:01 ----A---- C:\Windows\system32\browcli.dll
2015-11-10 22:56:25 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-10 22:56:25 ----A---- C:\Windows\system32\poqexec.exe
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\lpk.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\fontsub.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\dciman32.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmlib.dll
2015-11-10 22:46:53 ----A---- C:\Windows\system32\atmfd.dll
2015-11-10 22:46:24 ----A---- C:\Windows\system32\wer.dll
2015-11-10 22:46:23 ----A---- C:\Windows\SYSWOW64\wer.dll
2015-11-10 22:45:08 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2015-11-10 22:45:08 ----A---- C:\Windows\system32\imagehlp.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-10 22:43:58 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-10 22:43:40 ----A---- C:\Windows\SYSWOW64\charmap.exe
2015-11-10 22:43:40 ----A---- C:\Windows\system32\charmap.exe
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-10 22:43:38 ----A---- C:\Windows\system32\davclnt.dll
2015-11-10 22:43:26 ----A---- C:\Windows\system32\drivers\usb8023.sys
2015-11-10 22:43:08 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-10 22:42:41 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-10 22:42:41 ----A---- C:\Windows\system32\crypt32.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\wintrust.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-10 22:42:40 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-10 22:42:06 ----A---- C:\Windows\system32\wpdshext.dll
2015-11-10 22:42:05 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-11-10 22:41:18 ----A---- C:\Windows\system32\OxpsConverter.exe
2015-11-10 22:40:40 ----A---- C:\Windows\system32\drivers\stream.sys
2015-11-10 22:39:34 ----A---- C:\Windows\system32\taskhost.exe
2015-11-10 22:36:02 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2015-11-10 22:36:02 ----A---- C:\Windows\system32\EncDec.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\generaltel.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\devinv.dll
2015-11-10 22:33:04 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-11-10 22:33:04 ----A---- C:\Windows\system32\aitstatic.exe
2015-11-10 22:33:03 ----A---- C:\Windows\system32\invagent.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\appraiser.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\aepic.dll
2015-11-10 22:33:03 ----A---- C:\Windows\system32\acmigration.dll
2015-11-10 22:33:02 ----A---- C:\Windows\system32\aeinv.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\SYSWOW64\credui.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2015-11-10 22:13:00 ----A---- C:\Windows\system32\credui.dll
2015-11-10 22:05:15 ----A---- C:\Windows\system32\drivers\usbcir.sys
2015-11-10 22:04:18 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-10 22:04:18 ----A---- C:\Windows\system32\ole32.dll
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsrslvr.dll
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnscacheugc.exe
2015-11-10 21:43:46 ----A---- C:\Windows\system32\dnsapi.dll
2015-11-10 21:02:15 ----A---- C:\Windows\system32\TSWorkspace.dll
2015-11-10 21:02:14 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2015-11-10 20:53:11 ----A---- C:\Windows\system32\gdi32.dll
2015-11-10 20:53:10 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbport.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbhub.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbehci.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbd.sys
2015-11-10 20:53:05 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2015-11-10 20:39:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2015-11-10 20:37:33 ----D---- C:\Program Files\trend micro
2015-11-10 20:37:17 ----D---- C:\rsit
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidparse.sys
2015-11-10 20:29:09 ----A---- C:\Windows\system32\drivers\hidclass.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2015-11-10 20:04:20 ----A---- C:\Windows\system32\drivers\srv.sys
2015-11-10 20:04:19 ----A---- C:\Windows\system32\drivers\srvnet.sys
2015-11-10 19:51:33 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2015-11-10 19:51:33 ----A---- C:\Windows\system32\win32spl.dll
2015-11-10 19:49:39 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2015-11-10 19:49:39 ----A---- C:\Windows\system32\msvcrt.dll
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\nshwfp.dll
2015-11-10 19:42:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2015-11-10 19:42:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2015-11-10 19:41:24 ----A---- C:\Windows\system32\services.exe
2015-11-10 19:40:47 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\consent.exe
2015-11-10 19:40:43 ----A---- C:\Windows\system32\authui.dll
2015-11-10 19:40:43 ----A---- C:\Windows\system32\appinfo.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\nlaapi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netevent.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\netcorehc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\ncsi.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\iphlpsvc.dll
2015-11-10 19:40:36 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2015-11-10 19:39:51 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2015-11-10 19:39:48 ----A---- C:\Windows\system32\cdosys.dll
2015-11-10 19:39:27 ----A---- C:\Windows\system32\scavengeui.dll
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files\DESIGNER
2015-11-10 19:19:01 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2015-11-10 19:18:20 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-11-10 19:17:15 ----D---- C:\Windows\PCHEALTH
2015-11-10 19:17:15 ----D---- C:\Program Files\Microsoft SQL Server
2015-11-10 19:12:28 ----D---- C:\Program Files\Microsoft Analysis Services
2015-11-10 19:12:28 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-11-10 19:12:00 ----D---- C:\Program Files (x86)\Microsoft Office
2015-11-10 19:11:48 ----D---- C:\Program Files\Microsoft Office
2015-11-10 19:11:46 ----D---- C:\ProgramData\Microsoft Help
2015-11-10 19:10:14 ----RHD---- C:\MSOCache
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2015-11-08 21:46:36 ----A---- C:\Windows\system32\infocardapi.dll
2015-11-08 21:46:36 ----A---- C:\Windows\system32\icardagt.exe
2015-11-08 21:46:35 ----A---- C:\Windows\SYSWOW64\icardres.dll
2015-11-08 21:46:35 ----A---- C:\Windows\system32\icardres.dll
2015-11-08 21:46:26 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2015-11-08 21:46:26 ----A---- C:\Windows\system32\TsWpfWrp.exe
2015-11-08 21:45:32 ----D---- C:\Users\Be\AppData\Roaming\WinRAR
2015-11-08 21:03:45 ----A---- C:\Windows\system32\Wdfres.dll
2015-11-08 21:03:45 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2015-11-08 20:50:08 ----D---- C:\Program Files\WinRAR
2015-11-08 19:42:42 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2015-11-08 19:42:12 ----A---- C:\Windows\system32\RMActivate.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_ssp.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc_isv.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\secproc.dll
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2015-11-08 19:42:11 ----A---- C:\Windows\system32\msdrm.dll
2015-11-08 19:34:27 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-08 19:16:56 ----D---- C:\Users\Be\AppData\Roaming\ESET
2015-11-08 19:07:39 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2015-11-08 18:56:40 ----D---- C:\Program Files\ESET
2015-11-08 18:56:39 ----D---- C:\ProgramData\ESET
2015-11-08 18:45:11 ----D---- C:\Users\Be\AppData\Roaming\ATI
2015-11-08 18:45:11 ----D---- C:\ProgramData\ATI
2015-11-08 18:39:40 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2015-11-08 18:32:37 ----D---- C:\ProgramData\AMD
2015-11-08 18:32:31 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\AMD AVT
2015-11-08 18:30:33 ----D---- C:\Program Files (x86)\ATI Technologies
2015-11-08 18:26:05 ----D---- C:\Users\Be\AppData\Roaming\AVG
2015-11-08 18:25:52 ----D---- C:\Program Files (x86)\AVG
2015-11-08 18:24:32 ----D---- C:\Program Files\AMD
2015-11-08 18:23:03 ----A---- C:\Windows\un_dext.exe
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.src
2015-11-08 18:23:03 ----A---- C:\Windows\TWAIN2080.ini
2015-11-08 18:23:03 ----A---- C:\Windows\SYSWOW64\VCamPPage.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\VCamPPage_x64.dll
2015-11-08 18:23:03 ----A---- C:\Windows\system32\drivers\SPUVCBv_x64.sys
2015-11-08 18:23:02 ----D---- C:\Program Files (x86)\HP Camera Driver
2015-11-08 18:23:02 ----A---- C:\Windows\system32\CoInstaller_x64.dll
2015-11-08 18:23:02 ----A---- C:\Windows\SPRemove_x64.exe
2015-11-08 18:23:02 ----A---- C:\Windows\remove.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_36.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_31.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_30.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_29.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_27.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_25.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_24.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_22.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_21.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_2052.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_20.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_19.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_18.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_17.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_16.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_14.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_13.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_12.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_11.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_1046.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_10.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_09.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_08.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_07.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_06.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_05.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_04.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_02.ini
2015-11-08 18:23:02 ----A---- C:\Windows\Dext_01.ini
2015-11-08 18:21:35 ----HD---- C:\ProgramData\Common Files
2015-11-08 18:21:34 ----D---- C:\ProgramData\AVG
2015-11-08 18:18:45 ----D---- C:\Users\Be\AppData\Roaming\Opera Software
2015-11-08 18:14:16 ----D---- C:\Program Files (x86)\Opera
2015-11-08 18:13:52 ----D---- C:\Program Files (x86)\Disc Soft
2015-11-08 18:12:46 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-11-08 18:12:45 ----D---- C:\Users\Be\AppData\Roaming\DAEMON Tools Lite
2015-11-08 18:12:43 ----D---- C:\Program Files\DAEMON Tools Lite
2015-11-08 18:12:22 ----D---- C:\ProgramData\DAEMON Tools Lite
2015-11-08 18:11:50 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-08 18:09:02 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-11-08 18:07:13 ----D---- C:\b28b719981fddbf1baa95a
2015-11-08 18:06:18 ----D---- C:\Program Files\ATI Technologies
2015-11-08 18:06:14 ----D---- C:\Program Files\ATI
2015-11-08 18:05:42 ----D---- C:\Users\Be\AppData\Roaming\Adobe
2015-11-08 18:01:20 ----D---- C:\Users\Be\AppData\Roaming\IrfanView
2015-11-08 18:01:20 ----D---- C:\Program Files (x86)\IrfanView
2015-11-08 18:00:25 ----D---- C:\Program Files (x86)\Adobe
2015-11-08 17:59:15 ----D---- C:\ProgramData\Adobe
2015-11-08 17:57:31 ----D---- C:\Users\Be\AppData\Roaming\vlc
2015-11-08 17:56:57 ----D---- C:\Program Files (x86)\VideoLAN
2015-11-08 17:53:40 ----D---- C:\Program Files (x86)\Intel
2015-11-08 17:53:11 ----D---- C:\Program Files\Intel
2015-11-08 17:50:15 ----D---- C:\Intel
2015-11-08 17:42:12 ----D---- C:\Program Files (x86)\Google
2015-11-08 00:16:10 ----D---- C:\Users\Be\AppData\Roaming\TeamViewer
2015-11-08 00:05:01 ----D---- C:\Users\Be\AppData\Roaming\uTorrent
2015-11-08 00:04:12 ----HD---- C:\Windows\AxInstSV
2015-11-08 00:01:30 ----SHD---- C:\Windows\Installer
2015-11-08 00:01:25 ----D---- C:\ProgramData\Package Cache
2015-11-08 00:00:15 ----HD---- C:\system.sav
2015-11-07 23:26:23 ----D---- C:\ProgramData\Qualcomm Atheros
2015-11-07 23:12:05 ----A---- C:\Windows\HPSetLog.txt
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RTNUninst64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\RtNicProp64.dll
2015-11-07 23:01:12 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2015-11-07 23:01:08 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-11-07 23:01:08 ----D---- C:\Program Files (x86)\Realtek
2015-11-07 23:00:49 ----D---- C:\SWSetup
2015-11-07 22:45:15 ----D---- C:\Users\Be\AppData\Roaming\Identities
2015-11-07 22:44:55 ----SD---- C:\Users\Be\AppData\Roaming\Microsoft
2015-11-07 22:44:55 ----D---- C:\Users\Be\AppData\Roaming\Media Center Programs
2015-11-07 22:44:42 ----SHD---- C:\Recovery
2015-11-07 22:39:23 ----D---- C:\Windows\SoftwareDistribution
2015-11-07 22:36:42 ----D---- C:\Windows\Prefetch
2015-11-07 22:35:45 ----ASH---- C:\pagefile.sys
2015-11-07 22:35:44 ----SHD---- C:\System Volume Information
2015-11-07 22:35:44 ----ASH---- C:\hiberfil.sys
2015-11-07 22:35:18 ----D---- C:\Windows\Panther
2015-11-07 22:35:06 ----RASH---- C:\BOOTSECT.BAK
2015-11-07 22:35:03 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 month======

2015-11-26 21:54:43 ----D---- C:\Windows\Temp
2015-11-26 21:43:05 ----D---- C:\Windows\system32\config
2015-11-26 21:39:31 ----D---- C:\Windows\Tasks
2015-11-26 21:39:30 ----D---- C:\Windows
2015-11-26 20:34:32 ----D---- C:\Windows\system32\drivers
2015-11-26 20:34:19 ----D---- C:\Windows\inf
2015-11-26 20:34:17 ----D---- C:\Windows\system32\DriverStore
2015-11-25 23:24:45 ----RD---- C:\Program Files
2015-11-25 23:20:55 ----D---- C:\Windows\system32\wdi
2015-11-25 21:14:46 ----RD---- C:\Program Files (x86)
2015-11-25 21:14:45 ----HD---- C:\ProgramData
2015-11-24 21:30:09 ----D---- C:\Windows\System32
2015-11-24 21:30:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-11-23 21:01:27 ----D---- C:\Windows\winsxs
2015-11-20 00:42:44 ----RSD---- C:\Windows\assembly
2015-11-20 00:37:39 ----A---- C:\Windows\win.ini
2015-11-19 23:13:59 ----D---- C:\Windows\rescache
2015-11-19 23:07:59 ----D---- C:\Windows\Logs
2015-11-18 20:56:50 ----D---- C:\Windows\AppCompat
2015-11-18 20:46:15 ----D---- C:\Windows\system32\Tasks
2015-11-18 20:44:49 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-11-18 20:44:49 ----D---- C:\Windows\SysWOW64
2015-11-18 20:44:48 ----D---- C:\Windows\system32\sk-SK
2015-11-18 20:44:48 ----D---- C:\Windows\PolicyDefinitions
2015-11-18 20:44:41 ----RSD---- C:\Windows\Fonts
2015-11-18 20:44:40 ----D---- C:\Windows\tracing
2015-11-18 20:44:39 ----D---- C:\Program Files\Internet Explorer
2015-11-18 20:44:38 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-18 20:44:36 ----D---- C:\Windows\system32\en-US
2015-11-18 20:44:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-18 20:44:16 ----D---- C:\Windows\AppPatch
2015-11-18 20:44:09 ----D---- C:\Windows\system32\migration
2015-11-12 00:44:03 ----D---- C:\Windows\debug
2015-11-12 00:42:14 ----D---- C:\Windows\Microsoft.NET
2015-11-12 00:34:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-11-11 23:40:43 ----D---- C:\Program Files\Windows Journal
2015-11-11 23:32:11 ----D---- C:\Windows\system32\catroot2
2015-11-11 21:51:21 ----D---- C:\Windows\ehome
2015-11-11 21:51:15 ----D---- C:\Program Files\Windows Media Player
2015-11-11 21:51:15 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-11 21:51:12 ----D---- C:\Program Files\Common Files\System
2015-11-11 21:51:00 ----D---- C:\Windows\SYSWOW64\migration
2015-11-11 21:50:38 ----D---- C:\Windows\SYSWOW64\pt-BR
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\pt-PT
2015-11-11 21:50:37 ----D---- C:\Windows\SYSWOW64\it-IT
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\pl-PL
2015-11-11 21:50:36 ----D---- C:\Windows\SYSWOW64\ko-KR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-TW
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\zh-HK
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\tr-TR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\sv-SE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\nl-NL
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\hu-HU
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fr-FR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\fi-FI
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\es-ES
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\el-GR
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\de-DE
2015-11-11 21:50:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\zh-CN
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ru-RU
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\nb-NO
2015-11-11 21:50:34 ----D---- C:\Windows\SYSWOW64\ja-JP
2015-11-11 21:50:33 ----D---- C:\Windows\SYSWOW64\da-DK
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-PT
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pt-BR
2015-11-11 21:50:29 ----D---- C:\Windows\system32\pl-PL
2015-11-11 21:50:29 ----D---- C:\Windows\system32\it-IT
2015-11-11 21:50:28 ----D---- C:\Windows\system32\zh-HK
2015-11-11 21:50:28 ----D---- C:\Windows\system32\ko-KR
2015-11-11 21:50:28 ----D---- C:\Windows\system32\hu-HU
2015-11-11 21:50:28 ----D---- C:\Windows\system32\el-GR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\zh-TW
2015-11-11 21:50:27 ----D---- C:\Windows\system32\tr-TR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\sv-SE
2015-11-11 21:50:27 ----D---- C:\Windows\system32\nl-NL
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fr-FR
2015-11-11 21:50:27 ----D---- C:\Windows\system32\fi-FI
2015-11-11 21:50:27 ----D---- C:\Windows\system32\es-ES
2015-11-11 21:50:27 ----D---- C:\Windows\system32\de-DE
2015-11-11 21:50:25 ----D---- C:\Windows\system32\zh-CN
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ru-RU
2015-11-11 21:50:25 ----D---- C:\Windows\system32\nb-NO
2015-11-11 21:50:25 ----D---- C:\Windows\system32\ja-JP
2015-11-11 21:50:25 ----D---- C:\Windows\system32\cs-CZ
2015-11-11 21:50:24 ----D---- C:\Windows\system32\da-DK
2015-11-11 21:50:17 ----D---- C:\Windows\system32\drivers\en-US
2015-11-11 21:50:07 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-11 21:50:01 ----D---- C:\Windows\system32\Dism
2015-11-11 21:49:15 ----D---- C:\Windows\system32\AdvancedInstallers
2015-11-11 21:49:09 ----D---- C:\Program Files (x86)\Windows Defender
2015-11-11 21:49:08 ----D---- C:\Program Files\Windows Defender
2015-11-11 21:49:05 ----D---- C:\Windows\system32\wbem
2015-11-11 21:49:01 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-11 21:49:01 ----D---- C:\Windows\system32\Boot
2015-11-11 21:48:51 ----SD---- C:\ProgramData\Microsoft
2015-11-11 21:46:41 ----D---- C:\Windows\system32\drivers\UMDF
2015-11-11 03:30:52 ----D---- C:\Windows\system32\catroot
2015-11-10 19:20:07 ----D---- C:\Windows\ShellNew
2015-11-10 19:19:53 ----D---- C:\Program Files\Common Files
2015-11-08 20:48:56 ----D---- C:\Windows\SYSWOW64\drivers
2015-11-08 18:32:31 ----D---- C:\Program Files (x86)\Common Files
2015-11-08 18:25:42 ----D---- C:\Windows\twain_32
2015-11-07 23:00:52 ----D---- C:\Windows\system32\restore
2015-11-07 22:45:11 ----SHD---- C:\$Recycle.Bin
2015-11-07 22:44:54 ----RD---- C:\Users
2015-11-07 22:41:39 ----D---- C:\Windows\system32\sysprep
2015-11-07 22:36:37 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2013-12-14 36608]
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 67792]
R0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2014-08-25 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-08-11 249544]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 179544]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 49240]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 222256]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-04-10 16751616]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-04-10 579584]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2015-11-08 30264]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-02-03 4860856]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2014-08-25 383984]
R3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2014-08-25 795120]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-10-10 129312]
R3 NETwNs64;___ Intel(R) Wireless Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw02.sys [2014-12-08 3437848]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-03-28 918232]
R3 SPUVCbv;SPUVCb Driver Service; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2014-10-07 674592]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IntcDAud;Intel(R) Zvuk pre obrazovky; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-02-09 455440]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-04-10 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [2015-08-05 1042064]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-02-03 344976]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1268568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-02-03 279952]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [2015-08-05 44744]
S3 ESHASRV;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [2015-08-05 192200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-08 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-01-25 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-11-11 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: zdetekovane rovnake IP

#13 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět