Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

surna pomoc nb plny korejskych vecí

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
marilynman
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 14 bře 2006 22:25
Bydliště: bratislava

surna pomoc nb plny korejskych vecí

#1 Příspěvek od marilynman »

zdravím vas na chvilu som pustil neterku notebooku a plný je teraz roznych aplikacii ktore neviem zmazat, dokonca som chcel na rychlo nainstalovat antivirus ale ani ma to nepusti dalej. dakujem
Logfile of random's system information tool 1.10 (written by random/random)
Run by marilynman at 2016-01-11 16:25:28
Microsoft Windows 10 Pro
System drive C: has 228 GB (78%) free of 294 GB
Total RAM: 2558 MB (37% free)


======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
winlogon.exe
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\atiesrxx.exe
atieclxx
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-be8ec706-9ae3-41be-8f74-53c362d990fb -SystemEventPortName:HostProcess-d0027512-4890-4993-a00f-e1aa7bfd5e2e -IoCancelEventPortName:HostProcess-789cf751-84a7-4d56-a247-880475bec136 -NonStateChangingEventPortName:HostProcess-bc276171-c7ae-4fda-84cb-ddf5ce23908e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5882177b-a5d3-4896-b662-c8aca181d377 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\KMSpico\Service_KMS.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe" -mini
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\HTC\HTC Sync Manager\HTCSyncManager.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-935c29ec-f734-4fb3-a06d-68a0ca2187cc -SystemEventPortName:HostProcess-1b7ac5af-1ae6-47bb-8f0f-e011ca16cfe9 -IoCancelEventPortName:HostProcess-1254a8e4-981b-49a1-b960-9d8d481bab7a -NonStateChangingEventPortName:HostProcess-1a4bbf06-889b-4668-b385-60b5d051cc22 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f41a8eab-21b3-4b8b-a40d-81e188812a50 -DeviceGroupId:WudfDefaultDevicePool
adb fork-server server
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\lcstat.exe"
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\tslog.exe" bs
"fontdrvhost.exe"
"C:\Users\marilynman\AppData\Roaming\Tencent\AndroidServer\1.0.0.509\AndroidServer.exe"
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\marilynman\Downloads\ESET NOD32 ANTIVIRUS 7 + CRACK (32 64BIT).rar"

"C:\Program Files\Windows Defender\MSASCui.exe" /enable /as
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\WINDOWS\System32\NetworkUXBroker.exe" -ServerName:Windows.Networking.UX
C:\WINDOWS\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}
"C:\Program Files\trend micro\marilynman.exe" /silentautolog
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\lcstat.exe" "10F070710F1FF138ECD0A9B9C184DAA7D42EA5F32FD890A8B737B79002DB48343CCE57FCECFD226C457921C57675EA01" 5 3329 200 30 1 "" 0 "50F28417003AE303D8F0966451DC3A412A79170A88B7E43810D9E667EEF5FDA9F268BEE7E1237B732E4122A0DD6ABCD6128BC3DF0DEDB50F84F21BE3EA61D991BD364893B44E5062954C04A486CFCC65405A5D26A25B70DE142C71DEC9A4EB5D45C67F8B6C5D8DECC88E9D27BC507C19BCC6B3C6DA01857B62E8FA6405E8D352DDE5802CE4C7806BB9E4F5840ED841D9" 1280 768 40 100 5 3329 200 30
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\marilynman\Downloads\Norton Internet Security 2014+TR.rar"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe17_ Global\UsGthrCtrlFltPipeMssGthrPipe17 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 624 628 636 8192 632
"C:\Users\marilynman\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default

prefs.js - "browser.startup.homepage" - "about:home"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll


C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\extensions\
deskCutv2@gmail.com

C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\searchplugins\
mysites123.xml
Search Provided by Yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30 140344]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-18 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-18 172640]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-01-02 551112]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-12-17 50378880]
"TrainTickets"=C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe [2016-01-06 764344]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]
"MTview"=C:\Program Files (x86)\MTV20151125\MTView.exe -mini []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-11 16:21:13 ----D---- C:\Program Files\trend micro
2016-01-11 16:21:12 ----D---- C:\rsit
2016-01-11 15:42:25 ----D---- C:\Program Files\CCleaner
2016-01-11 13:25:23 ----A---- C:\WINDOWS\system32\drivers\TAOKernelEx64.sys
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files\Tencent
2016-01-10 09:08:39 ----D---- C:\ProgramData\Martau
2016-01-10 09:08:31 ----D---- C:\Program Files\Total Uninstall 6
2016-01-10 08:50:11 ----A---- C:\WINDOWS\system32\Vestris.ResourceLib.dll
2016-01-10 08:50:09 ----D---- C:\Program Files\KMSpico
2016-01-10 07:47:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-01-10 07:16:26 ----A---- C:\WINDOWS\SYSWOW64\drivers\TS888x64.sys
2016-01-06 07:07:04 ----A---- C:\Users\marilynman\AppData\Roaming\GiftBag.db
2016-01-06 07:05:46 ----D---- C:\ProgramData\TXQMPC
2016-01-06 07:04:22 ----D---- C:\ProgramData\Application Data
2016-01-06 07:04:21 ----N---- C:\WINDOWS\system32\drivers\TFsFltX64.sys
2016-01-06 07:03:51 ----D---- C:\Program Files (x86)\Tencent
2016-01-06 07:03:20 ----D---- C:\Users\marilynman\AppData\Roaming\Tencent
2016-01-06 07:03:14 ----D---- C:\ProgramData\Tencent
2016-01-06 06:58:22 ----D---- C:\Program Files (x86)\TrainTickets_201601060658
2016-01-06 06:56:58 ----D---- C:\Program Files (x86)\MTV20151125
2016-01-06 06:54:25 ----D---- C:\Program Files (x86)\Microsoft Toolkit Final
2016-01-03 19:36:31 ----D---- C:\WINDOWS\system32\SleepStudy
2016-01-02 14:39:33 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2016-01-02 14:32:28 ----ASH---- C:\hiberfil.sys
2016-01-02 14:23:04 ----SD---- C:\Users\marilynman\AppData\Roaming\Microsoft
2016-01-02 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-01-02 14:14:12 ----AS---- C:\WINDOWS\bootstat.dat
2016-01-02 14:13:15 ----D---- C:\WINDOWS\Prefetch
2016-01-02 14:12:02 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-02 08:44:14 ----SHD---- C:\Recovery
2016-01-02 08:44:06 ----DC---- C:\WINDOWS\Panther
2016-01-02 08:36:37 ----D---- C:\Windows.old
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\dialserver.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfds.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\EncDump.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2016-01-02 08:33:06 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\jscript.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-01-02 08:33:05 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-02 08:33:04 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iesetup.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iernonce.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\lpk.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\dciman32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwancfg.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wsplib.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wshrm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininet.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimserv.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimgapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifitask.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\twinui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRH.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shell32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\services.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\rilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provtool.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provops.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provhandlers.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provdatastore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\pnidui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mssign32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\catsrvut.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\authui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wups2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\nativemap.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32k.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\cdp.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\dcomp.dll
2016-01-02 08:24:03 ----D---- C:\WINDOWS\system32\Microsoft
2016-01-01 16:04:42 ----D---- C:\Program Files (x86)\OLBPre
2015-12-27 05:30:34 ----D---- C:\Users\marilynman\AppData\Roaming\vlc
2015-12-27 04:03:32 ----D---- C:\Program Files (x86)\VideoLAN
2015-12-24 23:51:01 ----D---- C:\Program Files (x86)\Electronic Arts
2015-12-24 23:50:47 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-24 23:50:47 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-21 23:12:25 ----D---- C:\Users\marilynman\AppData\Roaming\Shark007
2015-12-21 23:12:24 ----D---- C:\ProgramData\Shark007
2015-12-21 23:11:37 ----A---- C:\WINDOWS\AviSplitter.INI
2015-12-21 23:11:29 ----A---- C:\WINDOWS\system32\unrar64.dll
2015-12-21 23:11:25 ----A---- C:\WINDOWS\system32\VSFilter.dll
2015-12-21 23:11:23 ----D---- C:\Program Files\Shark007
2015-12-21 23:10:29 ----D---- C:\Users\marilynman\AppData\Roaming\Standard
2015-12-21 23:10:28 ----D---- C:\Program Files (x86)\Shark007
2015-12-21 23:08:33 ----D---- C:\ProgramData\Standard
2015-12-21 15:18:21 ----D---- C:\Users\marilynman\AppData\Roaming\HTC
2015-12-21 15:16:34 ----D---- C:\Users\marilynman\AppData\Roaming\Apple Computer
2015-12-21 15:16:06 ----D---- C:\ProgramData\HTC
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\Spirent Communications
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\HTC
2015-12-18 15:17:10 ----D---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-18 14:40:28 ----D---- C:\ProgramData\Oracle
2015-12-18 14:40:17 ----D---- C:\Program Files (x86)\Java
2015-12-18 14:35:43 ----D---- C:\Users\marilynman\AppData\Roaming\Sun
2015-12-18 14:35:25 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2015-12-18 11:30:08 ----D---- C:\Users\marilynman\AppData\Roaming\WinRAR
2015-12-18 10:54:35 ----D---- C:\Program Files\WinRAR
2015-12-18 10:33:47 ----D---- C:\Users\marilynman\AppData\Roaming\Macromedia
2015-12-17 14:33:11 ----D---- C:\Users\marilynman\AppData\Roaming\Skype
2015-12-17 14:32:50 ----RD---- C:\Program Files (x86)\Skype
2015-12-17 14:32:26 ----D---- C:\ProgramData\Skype
2015-12-17 14:25:51 ----D---- C:\Users\marilynman\AppData\Roaming\Mozilla
2015-12-17 14:25:32 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-17 14:03:18 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-12-17 14:01:46 ----D---- C:\WINDOWS\system32\MRT
2015-12-17 14:01:39 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-17 13:11:29 ----D---- C:\ProgramData\Microsoft Toolkit
2015-12-17 13:10:02 ----A---- C:\WINDOWS\SECOH-QAD.exe
2015-12-17 13:10:02 ----A---- C:\WINDOWS\SECOH-QAD.dll
2015-12-17 11:50:40 ----A---- C:\WINDOWS\system32\drivers\rimmpx64.sys
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdmv.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\coinst_8.97.100.9001.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atipblag.dat
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6v.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atipblag.dat
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiedu64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\ati2edxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atibtmon.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\amdverag.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\rixdicon.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\drivers\rixdpx64.sys
2015-12-17 11:45:29 ----A---- C:\WINDOWS\system32\drivers\ITEhidCIR.sys
2015-12-17 11:45:06 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-17 11:39:11 ----D---- C:\Users\marilynman\AppData\Roaming\Adobe

======List of files/folders modified in the last 1 month======

2016-01-11 16:21:13 ----RD---- C:\Program Files
2016-01-11 16:08:22 ----RD---- C:\Program Files (x86)
2016-01-11 16:08:22 ----D---- C:\WINDOWS\Temp
2016-01-11 16:03:31 ----D---- C:\Windows
2016-01-11 16:01:39 ----D---- C:\WINDOWS\SoftwareDistribution
2016-01-11 15:52:53 ----D---- C:\WINDOWS\system32\drivers
2016-01-11 15:50:53 ----D---- C:\WINDOWS\INF
2016-01-11 15:50:52 ----D---- C:\WINDOWS\debug
2016-01-11 15:42:31 ----D---- C:\WINDOWS\system32\Tasks
2016-01-11 15:38:50 ----D---- C:\WINDOWS\System32
2016-01-11 15:38:50 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-11 15:33:41 ----D---- C:\WINDOWS\system32\sru
2016-01-11 13:29:10 ----D---- C:\WINDOWS\system32\config
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files
2016-01-11 11:16:00 ----HD---- C:\Program Files\WindowsApps
2016-01-11 11:15:39 ----D---- C:\WINDOWS\AppReadiness
2016-01-11 10:51:01 ----D---- C:\WINDOWS\WinSxS
2016-01-11 10:49:12 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-11 10:48:58 ----RD---- C:\WINDOWS\assembly
2016-01-10 11:53:45 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-01-10 09:59:06 ----SHD---- C:\System Volume Information
2016-01-10 09:37:54 ----D---- C:\WINDOWS\Tasks
2016-01-10 09:08:41 ----HD---- C:\ProgramData
2016-01-10 09:02:30 ----D---- C:\WINDOWS\system32\WDI
2016-01-07 07:43:45 ----D---- C:\WINDOWS\SysWOW64
2016-01-06 14:29:15 ----D---- C:\WINDOWS\CbsTemp
2016-01-06 09:08:16 ----D---- C:\WINDOWS\Logs
2016-01-06 07:04:44 ----RSD---- C:\WINDOWS\Fonts
2016-01-06 07:04:22 ----D---- C:\Program Files (x86)\Common Files
2016-01-03 17:43:45 ----D---- C:\WINDOWS\system32\restore
2016-01-03 16:16:59 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-01-03 14:20:39 ----D---- C:\WINDOWS\appcompat
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-02 15:11:47 ----RD---- C:\WINDOWS\DevicesFlow
2016-01-02 15:02:54 ----D---- C:\WINDOWS\rescache
2016-01-02 14:52:26 ----RD---- C:\WINDOWS\PrintDialog
2016-01-02 14:52:24 ----RD---- C:\WINDOWS\MiracastView
2016-01-02 14:51:38 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-01-02 14:49:07 ----SD---- C:\ProgramData\Microsoft
2016-01-02 14:47:32 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-01-02 14:44:05 ----D---- C:\WINDOWS\Registration
2016-01-02 14:39:22 ----D---- C:\WINDOWS\system32\LogFiles
2016-01-02 14:37:54 ----D---- C:\WINDOWS\system32\drivers\etc
2016-01-02 14:37:43 ----D---- C:\WINDOWS\system32\wbem
2016-01-02 14:35:45 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-02 14:34:14 ----D---- C:\WINDOWS\system32\catroot2
2016-01-02 14:31:34 ----HD---- C:\WINDOWS\Installer
2016-01-02 14:27:15 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-01-02 14:27:12 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2016-01-02 14:27:03 ----D---- C:\WINDOWS\system32\spool
2016-01-02 14:27:01 ----D---- C:\WINDOWS\system32\slmgr
2016-01-02 14:26:39 ----D---- C:\WINDOWS\system32\CatRoot
2016-01-02 14:26:32 ----RD---- C:\WINDOWS\PurchaseDialog
2016-01-02 14:26:31 ----D---- C:\WINDOWS\PolicyDefinitions
2016-01-02 14:26:18 ----RD---- C:\Users
2016-01-02 14:26:18 ----D---- C:\ProgramData\USOPrivate
2016-01-02 14:25:51 ----HD---- C:\WINDOWS\system32\GroupPolicy
2016-01-02 14:25:51 ----D---- C:\WINDOWS\system32\Recovery
2016-01-02 14:22:04 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-01-02 14:21:03 ----D---- C:\WINDOWS\system32\Sysprep
2016-01-02 14:12:20 ----D---- C:\WINDOWS\ServiceProfiles
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-01-02 08:35:49 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\sk-SK
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\oobe
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\migration
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\Dism
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\appraiser
2016-01-02 08:35:47 ----D---- C:\WINDOWS\Provisioning
2016-01-02 08:35:47 ----D---- C:\WINDOWS\bcastdvr
2016-01-02 08:35:47 ----D---- C:\WINDOWS\AppPatch
2016-01-02 08:35:47 ----D---- C:\Program Files\Internet Explorer
2016-01-02 08:35:47 ----D---- C:\Program Files (x86)\Internet Explorer
2016-01-02 08:21:19 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-01-02 08:21:19 ----D---- C:\WINDOWS\system32\en-US
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2016-01-02 04:43:50 ----RASH---- C:\BOOTSECT.BAK
2016-01-02 04:43:47 ----SHD---- C:\Boot
2016-01-02 04:32:16 ----HD---- C:\$WINDOWS.~BT
2015-12-19 11:24:39 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys []
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 rimmptsk;rimmptsk; C:\WINDOWS\System32\drivers\rimmpx64.sys [2015-12-17 52224]
R2 rismxdp;@oem7.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdpx64.sys [2015-12-17 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys []
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-12-17 11922944]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-12-17 359936]
R3 BCM43XX;@netbc63a.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\System32\drivers\bcmwl63al.sys [2015-10-30 5170176]
R3 HTCAND64;@oem0.inf,%HTCAND64.SvcDesc%;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 ITEhidCIR;@oem1.inf,%VHidMini%;ITECIR Hid Driver; C:\WINDOWS\System32\drivers\ITEhidCIR.sys [2015-12-17 33488]
R3 k57nd60a;@netk57a.inf,%SvcDispName%;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\WINDOWS\System32\drivers\k57nd60a.sys [2015-10-30 446464]
R3 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys []
R3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;USB RNDIS Adapter; C:\WINDOWS\System32\drivers\usb8023x.sys [2015-10-30 23040]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2015-10-30 221184]
R4 TAOKernelDriver;Tencent Auto Optimize Platform.; \??\C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys [2016-01-10 128312]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-01-02 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 htcnprot;@oem8.inf,%NDISPROT_Desc%;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2013-10-17 36928]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2015-10-30 67072]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-12-17 238080]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-04-02 87368]
R2 OneSyncSvc_2e51d;Sync Host_2e51d; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
R2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2015-08-09 985280]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_19213b;Sync Host_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2d725;Sync Host_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_66d24;Sync Host_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bb8fa;Sync Host_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bdb193;Sync Host_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-30 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_19213b;MessagingService_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2d725;MessagingService_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2e51d;MessagingService_2e51d; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_66d24;MessagingService_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bb8fa;MessagingService_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bdb193;MessagingService_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-10 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_19213b;Kontaktné údaje_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2d725;Kontaktné údaje_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2e51d;Kontaktné údaje_2e51d; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_66d24;Kontaktné údaje_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bb8fa;Kontaktné údaje_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bdb193;Kontaktné údaje_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_19213b;Ukladací priestor používateľských údajov_19213b; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2d725;Ukladací priestor používateľských údajov_2d725; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2e51d;Ukladací priestor používateľských údajov_2e51d; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_66d24;Ukladací priestor používateľských údajov_66d24; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bb8fa;Ukladací priestor používateľských údajov_bb8fa; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bdb193;Ukladací priestor používateľských údajov_bdb193; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 UserDataSvc_19213b;Prístup k používateľským údajom_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 UserDataSvc_2d725;Prístup k používateľským údajom_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: surna pomoc nb plny korejskych vecí

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

marilynman
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 14 bře 2006 22:25
Bydliště: bratislava

Re: surna pomoc nb plny korejskych vecí

#3 Příspěvek od marilynman »

# AdwCleaner v5.028 - Logfile created 11/01/2016 at 18:25:59
# Updated 04/01/2016 by Xplode
# Database : 2016-01-04.2 [Server]
# Operating system : Windows 10 Pro (x64)
# Username : marilynman - DESKTOP-GEC68RR
# Running from : C:\Users\marilynman\Downloads\adwcleaner_5.028.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : TSDefenseBt
[-] Service Deleted : TSSysKit
[-] Service Deleted : QMUdisk
[-] Service Deleted : TS888x64
[-] Service Deleted : QQSysMonX64
[-] Service Deleted : TFsFlt
[!] Service Not Deleted : TAOKernelDriver
[-] Service Deleted : Service KMSELDI

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\kmspico
[-] Folder Deleted : C:\Program Files (x86)\OLBPre
[-] Folder Deleted : C:\Program Files (x86)\tencent
[-] Folder Deleted : C:\Program Files (x86)\Common Files\tencent
[#] Folder Deleted : C:\Program Files\Common Files\tencent
[-] Folder Deleted : C:\ProgramData\tencent
[-] Folder Deleted : C:\ProgramData\TXQMPC
[#] Folder Deleted : C:\ProgramData\mntemp
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\kmspico
[-] Folder Deleted : C:\Users\marilynman\AppData\Roaming\tencent
[-] Folder Deleted : C:\Users\marilynman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder Deleted : C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\Extensions\deskCutv2@gmail.com
[-] Folder Deleted : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\tencent

***** [ Files ] *****

[-] File Deleted : C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\searchplugins\mysites123.xml
[-] File Deleted : C:\WINDOWS\SysNative\drivers\TFsFltX64.sys
[-] File Deleted : C:\WINDOWS\SysWOW64\drivers\TS888x64.sys

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : LaunchPreSignup

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Mozilla\Extends
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Key Deleted : HKLM\SOFTWARE\CLASSES\METNSD
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{754DF2CE-51E8-4895-B53C-6381418B84AE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKCU\Software\PRODUCTSETUP
[-] Key Deleted : HKCU\Software\undefined
[!] Key Not Deleted : HKCU\Software\Mozilla\Extends
[-] Key Deleted : HKLM\SOFTWARE\mysites123Software
[-] Key Deleted : HKLM\SOFTWARE\TData
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tab]

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [3716 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: surna pomoc nb plny korejskych vecí

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

marilynman
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 14 bře 2006 22:25
Bydliště: bratislava

Re: surna pomoc nb plny korejskych vecí

#5 Příspěvek od marilynman »

Logfile of random's system information tool 1.10 (written by random/random)
Run by marilynman at 2016-01-11 18:57:49
Microsoft Windows 10 Pro
System drive C: has 228 GB (77%) free of 294 GB
Total RAM: 2558 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:57:58, on 11.01.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\TrainTickets_201601060658\201601060658\lcstat.exe
C:\Program Files (x86)\TrainTickets_201601060658\201601060658\tslog.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files\trend micro\marilynman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 2F6062FBB7
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 2F6062FBB7
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MTview] C:\Program Files (x86)\MTV20151125\MTView.exe -mini
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [TrainTickets] C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe -mini
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8659 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
winlogon.exe
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\atiesrxx.exe
atieclxx
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ef5c5379-4f36-4294-a09d-cfc009b026f6 -SystemEventPortName:HostProcess-6bbf9f87-311f-4a56-8e65-362b5b9607c4 -IoCancelEventPortName:HostProcess-5d866d9a-a0aa-4779-a4bb-239b51a201a0 -NonStateChangingEventPortName:HostProcess-33899202-51f7-4ffc-9ab8-6347038e82ae -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5dc03fa4-39d4-4da6-9edb-89fd484cec87 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-551994f7-c52a-403a-a03e-a20da01f0179 -SystemEventPortName:HostProcess-12210863-85b6-4e1a-b6f2-bc4cc2911742 -IoCancelEventPortName:HostProcess-e5861782-8cdc-4991-9e74-c003a7ce445e -NonStateChangingEventPortName:HostProcess-969d1fdd-3bb5-48ac-bab0-e05237814b7e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:38111e78-270d-4a3b-bc9b-8d02746fd6f3 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\Explorer.EXE
adb fork-server server
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe" -mini
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"fontdrvhost.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\lcstat.exe"
"C:\Program Files (x86)\TrainTickets_201601060658\201601060658\tslog.exe" bs
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\marilynman\Downloads\brtte.mkv"

C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Users\marilynman\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default

prefs.js - "browser.startup.homepage" - "about:home"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll


C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\searchplugins\
Search Provided by Yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-01-11 885152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-18 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-11 664184]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-18 172640]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-01-02 551112]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-12-17 50378880]
"TrainTickets"=C:\Program Files (x86)\TrainTickets_201601060658\201601060658\TrainTickets.exe [2016-01-06 764344]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]
"MTview"=C:\Program Files (x86)\MTV20151125\MTView.exe -mini []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-01-11 7021880]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-11 18:17:28 ----D---- C:\AdwCleaner
2016-01-11 16:46:13 ----A---- C:\WINDOWS\system32\aswBoot.exe
2016-01-11 16:42:34 ----D---- C:\Users\marilynman\AppData\Roaming\AVAST Software
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswStm.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswRdr2.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2016-01-11 16:41:10 ----A---- C:\WINDOWS\avastSS.scr
2016-01-11 16:36:44 ----D---- C:\Program Files\AVAST Software
2016-01-11 16:31:45 ----D---- C:\ProgramData\AVAST Software
2016-01-11 16:21:13 ----D---- C:\Program Files\trend micro
2016-01-11 16:21:12 ----D---- C:\rsit
2016-01-11 15:42:25 ----D---- C:\Program Files\CCleaner
2016-01-11 13:25:23 ----A---- C:\WINDOWS\system32\drivers\TAOKernelEx64.sys
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files\Tencent
2016-01-10 09:08:39 ----D---- C:\ProgramData\Martau
2016-01-10 09:08:31 ----D---- C:\Program Files\Total Uninstall 6
2016-01-10 08:50:11 ----A---- C:\WINDOWS\system32\Vestris.ResourceLib.dll
2016-01-10 07:47:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-01-06 07:07:04 ----A---- C:\Users\marilynman\AppData\Roaming\GiftBag.db
2016-01-06 07:04:22 ----D---- C:\ProgramData\Application Data
2016-01-06 06:58:22 ----D---- C:\Program Files (x86)\TrainTickets_201601060658
2016-01-06 06:56:58 ----D---- C:\Program Files (x86)\MTV20151125
2016-01-06 06:54:25 ----D---- C:\Program Files (x86)\Microsoft Toolkit Final
2016-01-03 19:36:31 ----D---- C:\WINDOWS\system32\SleepStudy
2016-01-02 14:39:33 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2016-01-02 14:32:28 ----ASH---- C:\hiberfil.sys
2016-01-02 14:23:04 ----SD---- C:\Users\marilynman\AppData\Roaming\Microsoft
2016-01-02 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-01-02 14:14:12 ----AS---- C:\WINDOWS\bootstat.dat
2016-01-02 14:13:15 ----D---- C:\WINDOWS\Prefetch
2016-01-02 14:12:02 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-02 08:44:14 ----SHD---- C:\Recovery
2016-01-02 08:44:06 ----DC---- C:\WINDOWS\Panther
2016-01-02 08:36:37 ----D---- C:\Windows.old
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\dialserver.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfds.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\EncDump.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2016-01-02 08:33:06 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\jscript.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-01-02 08:33:05 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-02 08:33:04 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iesetup.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iernonce.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\lpk.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\dciman32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwancfg.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wsplib.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wshrm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininet.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimserv.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimgapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifitask.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\twinui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRH.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shell32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\services.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\rilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provtool.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provops.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provhandlers.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provdatastore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\pnidui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mssign32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\catsrvut.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\authui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wups2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\nativemap.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32k.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\cdp.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\dcomp.dll
2016-01-02 08:24:03 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-27 05:30:34 ----D---- C:\Users\marilynman\AppData\Roaming\vlc
2015-12-27 04:03:32 ----D---- C:\Program Files (x86)\VideoLAN
2015-12-24 23:51:01 ----D---- C:\Program Files (x86)\Electronic Arts
2015-12-24 23:50:47 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-24 23:50:47 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-21 23:12:25 ----D---- C:\Users\marilynman\AppData\Roaming\Shark007
2015-12-21 23:12:24 ----D---- C:\ProgramData\Shark007
2015-12-21 23:11:37 ----A---- C:\WINDOWS\AviSplitter.INI
2015-12-21 23:11:29 ----A---- C:\WINDOWS\system32\unrar64.dll
2015-12-21 23:11:25 ----A---- C:\WINDOWS\system32\VSFilter.dll
2015-12-21 23:11:23 ----D---- C:\Program Files\Shark007
2015-12-21 23:10:29 ----D---- C:\Users\marilynman\AppData\Roaming\Standard
2015-12-21 23:10:28 ----D---- C:\Program Files (x86)\Shark007
2015-12-21 23:08:33 ----D---- C:\ProgramData\Standard
2015-12-21 15:18:21 ----D---- C:\Users\marilynman\AppData\Roaming\HTC
2015-12-21 15:16:34 ----D---- C:\Users\marilynman\AppData\Roaming\Apple Computer
2015-12-21 15:16:06 ----D---- C:\ProgramData\HTC
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\Spirent Communications
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\HTC
2015-12-18 15:17:10 ----D---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-18 14:40:28 ----D---- C:\ProgramData\Oracle
2015-12-18 14:40:17 ----D---- C:\Program Files (x86)\Java
2015-12-18 14:35:43 ----D---- C:\Users\marilynman\AppData\Roaming\Sun
2015-12-18 14:35:25 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2015-12-18 11:30:08 ----D---- C:\Users\marilynman\AppData\Roaming\WinRAR
2015-12-18 10:54:35 ----D---- C:\Program Files\WinRAR
2015-12-18 10:33:47 ----D---- C:\Users\marilynman\AppData\Roaming\Macromedia
2015-12-17 14:33:11 ----D---- C:\Users\marilynman\AppData\Roaming\Skype
2015-12-17 14:32:50 ----RD---- C:\Program Files (x86)\Skype
2015-12-17 14:32:26 ----D---- C:\ProgramData\Skype
2015-12-17 14:25:51 ----D---- C:\Users\marilynman\AppData\Roaming\Mozilla
2015-12-17 14:25:32 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-17 14:03:18 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-12-17 14:01:46 ----D---- C:\WINDOWS\system32\MRT
2015-12-17 14:01:39 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-17 13:11:29 ----D---- C:\ProgramData\Microsoft Toolkit
2015-12-17 13:10:02 ----A---- C:\WINDOWS\SECOH-QAD.exe
2015-12-17 13:10:02 ----A---- C:\WINDOWS\SECOH-QAD.dll
2015-12-17 11:50:40 ----A---- C:\WINDOWS\system32\drivers\rimmpx64.sys
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdmv.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\coinst_8.97.100.9001.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atipblag.dat
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6v.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atipblag.dat
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiedu64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\ati2edxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atibtmon.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\amdverag.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\rixdicon.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\drivers\rixdpx64.sys
2015-12-17 11:45:29 ----A---- C:\WINDOWS\system32\drivers\ITEhidCIR.sys
2015-12-17 11:45:06 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-17 11:39:11 ----D---- C:\Users\marilynman\AppData\Roaming\Adobe

======List of files/folders modified in the last 1 month======

2016-01-11 18:38:16 ----D---- C:\WINDOWS\Temp
2016-01-11 18:36:07 ----D---- C:\WINDOWS\System32
2016-01-11 18:36:07 ----D---- C:\WINDOWS\INF
2016-01-11 18:36:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-11 18:30:52 ----D---- C:\WINDOWS\system32\sru
2016-01-11 18:28:08 ----D---- C:\WINDOWS\system32\drivers
2016-01-11 18:28:06 ----D---- C:\Windows
2016-01-11 18:26:18 ----D---- C:\WINDOWS\system32\Tasks
2016-01-11 18:26:16 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-01-11 18:26:12 ----HD---- C:\ProgramData
2016-01-11 18:26:09 ----RD---- C:\Program Files (x86)
2016-01-11 18:26:09 ----D---- C:\Program Files (x86)\Common Files
2016-01-11 18:26:07 ----RD---- C:\Program Files
2016-01-11 16:41:24 ----D---- C:\WINDOWS\WinSxS
2016-01-11 16:01:39 ----D---- C:\WINDOWS\SoftwareDistribution
2016-01-11 15:50:52 ----D---- C:\WINDOWS\debug
2016-01-11 13:29:10 ----D---- C:\WINDOWS\system32\config
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files
2016-01-11 11:16:01 ----D---- C:\WINDOWS\AppReadiness
2016-01-11 11:16:00 ----HD---- C:\Program Files\WindowsApps
2016-01-11 10:49:12 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-11 10:48:58 ----RD---- C:\WINDOWS\assembly
2016-01-10 09:59:06 ----SHD---- C:\System Volume Information
2016-01-10 09:37:54 ----D---- C:\WINDOWS\Tasks
2016-01-10 09:02:30 ----D---- C:\WINDOWS\system32\WDI
2016-01-10 07:19:16 ----D---- C:\WINDOWS\CbsTemp
2016-01-07 07:43:45 ----D---- C:\WINDOWS\SysWOW64
2016-01-06 09:08:16 ----D---- C:\WINDOWS\Logs
2016-01-06 07:04:44 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 17:43:45 ----D---- C:\WINDOWS\system32\restore
2016-01-03 16:16:59 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-01-03 14:20:39 ----D---- C:\WINDOWS\appcompat
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-02 15:11:47 ----RD---- C:\WINDOWS\DevicesFlow
2016-01-02 15:02:54 ----D---- C:\WINDOWS\rescache
2016-01-02 14:52:26 ----RD---- C:\WINDOWS\PrintDialog
2016-01-02 14:52:24 ----RD---- C:\WINDOWS\MiracastView
2016-01-02 14:51:38 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-01-02 14:49:07 ----SD---- C:\ProgramData\Microsoft
2016-01-02 14:47:32 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-01-02 14:44:05 ----D---- C:\WINDOWS\Registration
2016-01-02 14:39:22 ----D---- C:\WINDOWS\system32\LogFiles
2016-01-02 14:37:54 ----D---- C:\WINDOWS\system32\drivers\etc
2016-01-02 14:37:43 ----D---- C:\WINDOWS\system32\wbem
2016-01-02 14:35:45 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-02 14:34:14 ----D---- C:\WINDOWS\system32\catroot2
2016-01-02 14:31:34 ----HD---- C:\WINDOWS\Installer
2016-01-02 14:27:15 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-01-02 14:27:12 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2016-01-02 14:27:03 ----D---- C:\WINDOWS\system32\spool
2016-01-02 14:27:01 ----D---- C:\WINDOWS\system32\slmgr
2016-01-02 14:26:39 ----D---- C:\WINDOWS\system32\CatRoot
2016-01-02 14:26:32 ----RD---- C:\WINDOWS\PurchaseDialog
2016-01-02 14:26:31 ----D---- C:\WINDOWS\PolicyDefinitions
2016-01-02 14:26:18 ----RD---- C:\Users
2016-01-02 14:26:18 ----D---- C:\ProgramData\USOPrivate
2016-01-02 14:25:51 ----HD---- C:\WINDOWS\system32\GroupPolicy
2016-01-02 14:25:51 ----D---- C:\WINDOWS\system32\Recovery
2016-01-02 14:22:04 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-01-02 14:21:03 ----D---- C:\WINDOWS\system32\Sysprep
2016-01-02 14:12:20 ----D---- C:\WINDOWS\ServiceProfiles
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-01-02 08:35:49 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\sk-SK
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\oobe
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\migration
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\Dism
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\appraiser
2016-01-02 08:35:47 ----D---- C:\WINDOWS\Provisioning
2016-01-02 08:35:47 ----D---- C:\WINDOWS\bcastdvr
2016-01-02 08:35:47 ----D---- C:\WINDOWS\AppPatch
2016-01-02 08:35:47 ----D---- C:\Program Files\Internet Explorer
2016-01-02 08:35:47 ----D---- C:\Program Files (x86)\Internet Explorer
2016-01-02 08:21:19 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-01-02 08:21:19 ----D---- C:\WINDOWS\system32\en-US
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2016-01-02 04:43:50 ----RASH---- C:\BOOTSECT.BAK
2016-01-02 04:43:47 ----SHD---- C:\Boot
2016-01-02 04:32:16 ----HD---- C:\$WINDOWS.~BT
2015-12-19 11:24:39 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-01-11 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-01-11 273784]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-01-11 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-01-11 1055560]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-01-11 451040]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-01-11 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-01-11 97648]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-01-11 155304]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 rimmptsk;rimmptsk; C:\WINDOWS\System32\drivers\rimmpx64.sys [2015-12-17 52224]
R2 rismxdp;@oem7.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdpx64.sys [2015-12-17 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-12-17 11922944]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-12-17 359936]
R3 BCM43XX;@netbc63a.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\System32\drivers\bcmwl63al.sys [2015-10-30 5170176]
R3 HTCAND64;@oem0.inf,%HTCAND64.SvcDesc%;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 ITEhidCIR;@oem1.inf,%VHidMini%;ITECIR Hid Driver; C:\WINDOWS\System32\drivers\ITEhidCIR.sys [2015-12-17 33488]
R3 k57nd60a;@netk57a.inf,%SvcDispName%;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\WINDOWS\System32\drivers\k57nd60a.sys [2015-10-30 446464]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys []
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-01-02 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 htcnprot;@oem8.inf,%NDISPROT_Desc%;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2013-10-17 36928]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys []
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2015-10-30 67072]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-12-17 238080]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-01-11 226440]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-04-02 87368]
R2 OneSyncSvc_44d52;Sync Host_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_19213b;Sync Host_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2d725;Sync Host_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_66d24;Sync Host_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bb8fa;Sync Host_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bdb193;Sync Host_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-30 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_19213b;MessagingService_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2d725;MessagingService_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44d52;MessagingService_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_66d24;MessagingService_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bb8fa;MessagingService_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bdb193;MessagingService_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-10 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_19213b;Kontaktné údaje_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2d725;Kontaktné údaje_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44d52;Kontaktné údaje_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_66d24;Kontaktné údaje_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bb8fa;Kontaktné údaje_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bdb193;Kontaktné údaje_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_19213b;Ukladací priestor používateľských údajov_19213b; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2d725;Ukladací priestor používateľských údajov_2d725; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_44d52;Ukladací priestor používateľských údajov_44d52; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_66d24;Ukladací priestor používateľských údajov_66d24; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bb8fa;Ukladací priestor používateľských údajov_bb8fa; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bdb193;Ukladací priestor používateľských údajov_bdb193; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: surna pomoc nb plny korejskych vecí

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\TrainTickets_201601060658\201601060658
C:\Program Files (x86)\Skype\Toolbars
C:\Program Files (x86)\MTV20151125
C:\WINDOWS\SECOH-QAD.exe
C:\WINDOWS\SECOH-QAD.dll

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TrainTickets"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"MTview"=-

:services
c2cautoupdatesvc
c2cpnrsvc
softaal

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

marilynman
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 14 bře 2006 22:25
Bydliště: bratislava

Re: surna pomoc nb plny korejskych vecí

#7 Příspěvek od marilynman »

Logfile of random's system information tool 1.10 (written by random/random)
Run by marilynman at 2016-01-11 20:58:30
Microsoft Windows 10 Pro
System drive C: has 228 GB (77%) free of 294 GB
Total RAM: 2558 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:58:38, on 11.01.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\marilynman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 2F6062FBB7
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 2F6062FBB7
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7900 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
winlogon.exe
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
atieclxx
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6a4248b8-13de-43e4-ba0f-63cf91bd0e20 -SystemEventPortName:HostProcess-f46b6d17-9971-4b00-a8a6-798822e37f54 -IoCancelEventPortName:HostProcess-dcd49fb7-eb38-489b-b8f6-072895a71706 -NonStateChangingEventPortName:HostProcess-2fbd9887-bf78-4942-8f66-fb4b0127bd31 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:20865fa0-3d75-4826-8cc2-63f752d078c3 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d8fcbd5d-ad72-4b76-a437-4d2e57ec3fb4 -SystemEventPortName:HostProcess-906ece8a-76a6-46c0-9746-af437b7b73fc -IoCancelEventPortName:HostProcess-67a734e0-cdb7-49f3-b37d-92694f0a6733 -NonStateChangingEventPortName:HostProcess-2fe6b3e3-f2f2-4188-9209-e9761f293d2c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:33120b97-09e4-4046-b364-09f90536737b -DeviceGroupId:WudfDefaultDevicePool
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe"
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k appmodel
dashost.exe {1c79e6b9-506d-4294-9ea4d5558c2e7f6f}
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\Explorer.EXE
adb fork-server server
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"fontdrvhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wermgr.exe -upload
C:\WINDOWS\system32\wbem\wmiprvse.exe

"C:\WINDOWS\system32\SearchFilterHost.exe" 0 600 604 612 8192 608
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\01112016_204738.log
wmiadap.exe /F /T /R
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-4013335508-3333605070-2584572280-10012_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-4013335508-3333605070-2584572280-10012 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
C:\WINDOWS\system32\DllHost.exe /Processid:{7006698D-2974-4091-A424-85DD0B909E23}
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe -Embedding
taskeng.exe {6D9F1E04-C950-478B-8B33-C4321DAC5191}
"C:\Users\marilynman\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default

prefs.js - "browser.startup.homepage" - "about:home"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.267 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll


C:\Users\marilynman\AppData\Roaming\Mozilla\Firefox\Profiles\ck6ln872.default\searchplugins\
Search Provided by Yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-01-11 885152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-18 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-11 664184]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-18 172640]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\marilynman\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-01-02 551112]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-12-17 50378880]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-01-11 7021880]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-11 20:47:38 ----D---- C:\_OTM
2016-01-11 18:17:28 ----D---- C:\AdwCleaner
2016-01-11 16:46:13 ----A---- C:\WINDOWS\system32\aswBoot.exe
2016-01-11 16:42:34 ----D---- C:\Users\marilynman\AppData\Roaming\AVAST Software
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswStm.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswRdr2.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2016-01-11 16:41:25 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2016-01-11 16:41:10 ----A---- C:\WINDOWS\avastSS.scr
2016-01-11 16:36:44 ----D---- C:\Program Files\AVAST Software
2016-01-11 16:31:45 ----D---- C:\ProgramData\AVAST Software
2016-01-11 16:21:13 ----D---- C:\Program Files\trend micro
2016-01-11 16:21:12 ----D---- C:\rsit
2016-01-11 15:42:25 ----D---- C:\Program Files\CCleaner
2016-01-11 13:25:23 ----A---- C:\WINDOWS\system32\drivers\TAOKernelEx64.sys
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files\Tencent
2016-01-10 09:08:39 ----D---- C:\ProgramData\Martau
2016-01-10 09:08:31 ----D---- C:\Program Files\Total Uninstall 6
2016-01-10 08:50:11 ----A---- C:\WINDOWS\system32\Vestris.ResourceLib.dll
2016-01-10 07:47:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-01-06 07:07:04 ----A---- C:\Users\marilynman\AppData\Roaming\GiftBag.db
2016-01-06 07:04:22 ----D---- C:\ProgramData\Application Data
2016-01-06 06:58:22 ----D---- C:\Program Files (x86)\TrainTickets_201601060658
2016-01-06 06:54:25 ----D---- C:\Program Files (x86)\Microsoft Toolkit Final
2016-01-03 19:36:31 ----D---- C:\WINDOWS\system32\SleepStudy
2016-01-02 14:39:33 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2016-01-02 14:32:28 ----ASH---- C:\hiberfil.sys
2016-01-02 14:23:04 ----SD---- C:\Users\marilynman\AppData\Roaming\Microsoft
2016-01-02 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-01-02 14:14:12 ----AS---- C:\WINDOWS\bootstat.dat
2016-01-02 14:13:15 ----D---- C:\WINDOWS\Prefetch
2016-01-02 14:12:02 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-02 08:44:14 ----SHD---- C:\Recovery
2016-01-02 08:44:06 ----DC---- C:\WINDOWS\Panther
2016-01-02 08:36:37 ----D---- C:\Windows.old
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-01-02 08:33:21 ----A---- C:\WINDOWS\system32\dialserver.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-02 08:33:20 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-01-02 08:33:19 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfds.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-01-02 08:33:18 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\EncDump.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEng.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-02 08:33:17 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-01-02 08:33:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2016-01-02 08:33:06 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\jscript.dll
2016-01-02 08:33:06 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-01-02 08:33:05 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-02 08:33:04 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-01-02 08:33:03 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iesetup.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\iernonce.dll
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-01-02 08:33:02 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\lpk.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\dciman32.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-01-02 08:32:50 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wwancfg.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wsplib.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wshrm.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wininet.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimserv.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wimgapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifitask.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\twinui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SRH.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\shell32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\services.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\rilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provtool.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provops.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provhandlers.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\provdatastore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\pnidui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mssign32.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\catsrvut.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\authui.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-01-02 08:32:49 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wups2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\nativemap.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosResource.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\moshost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mos.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mfpmp.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mf.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\cryptngc.dll
2016-01-02 08:32:40 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\win32k.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\user32.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputService.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\cdp.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-01-02 08:32:39 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2016-01-02 08:32:38 ----A---- C:\WINDOWS\system32\dcomp.dll
2016-01-02 08:24:03 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-27 05:30:34 ----D---- C:\Users\marilynman\AppData\Roaming\vlc
2015-12-27 04:03:32 ----D---- C:\Program Files (x86)\VideoLAN
2015-12-24 23:51:01 ----D---- C:\Program Files (x86)\Electronic Arts
2015-12-24 23:50:47 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-24 23:50:47 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-24 23:50:45 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-24 23:50:44 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-24 23:50:42 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-24 23:50:40 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-24 23:50:39 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-24 23:50:38 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-24 23:50:36 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-24 23:50:33 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-24 23:50:31 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-24 23:50:30 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-24 23:50:28 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-21 23:12:25 ----D---- C:\Users\marilynman\AppData\Roaming\Shark007
2015-12-21 23:12:24 ----D---- C:\ProgramData\Shark007
2015-12-21 23:11:37 ----A---- C:\WINDOWS\AviSplitter.INI
2015-12-21 23:11:29 ----A---- C:\WINDOWS\system32\unrar64.dll
2015-12-21 23:11:25 ----A---- C:\WINDOWS\system32\VSFilter.dll
2015-12-21 23:11:23 ----D---- C:\Program Files\Shark007
2015-12-21 23:10:29 ----D---- C:\Users\marilynman\AppData\Roaming\Standard
2015-12-21 23:10:28 ----D---- C:\Program Files (x86)\Shark007
2015-12-21 23:08:33 ----D---- C:\ProgramData\Standard
2015-12-21 15:18:21 ----D---- C:\Users\marilynman\AppData\Roaming\HTC
2015-12-21 15:16:34 ----D---- C:\Users\marilynman\AppData\Roaming\Apple Computer
2015-12-21 15:16:06 ----D---- C:\ProgramData\HTC
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\Spirent Communications
2015-12-21 15:12:32 ----D---- C:\Program Files (x86)\HTC
2015-12-18 15:17:10 ----D---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-18 14:40:28 ----D---- C:\ProgramData\Oracle
2015-12-18 14:40:17 ----D---- C:\Program Files (x86)\Java
2015-12-18 14:35:43 ----D---- C:\Users\marilynman\AppData\Roaming\Sun
2015-12-18 14:35:25 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2015-12-18 11:30:08 ----D---- C:\Users\marilynman\AppData\Roaming\WinRAR
2015-12-18 10:54:35 ----D---- C:\Program Files\WinRAR
2015-12-18 10:33:47 ----D---- C:\Users\marilynman\AppData\Roaming\Macromedia
2015-12-17 14:33:11 ----D---- C:\Users\marilynman\AppData\Roaming\Skype
2015-12-17 14:32:50 ----RD---- C:\Program Files (x86)\Skype
2015-12-17 14:32:26 ----D---- C:\ProgramData\Skype
2015-12-17 14:25:51 ----D---- C:\Users\marilynman\AppData\Roaming\Mozilla
2015-12-17 14:25:32 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-17 14:03:18 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-12-17 14:01:46 ----D---- C:\WINDOWS\system32\MRT
2015-12-17 14:01:39 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-17 13:11:29 ----D---- C:\ProgramData\Microsoft Toolkit
2015-12-17 11:50:40 ----A---- C:\WINDOWS\system32\drivers\rimmpx64.sys
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdmv.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\coinst_8.97.100.9001.dll
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsvl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsva.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsny.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\ativvsnl.dat
2015-12-17 11:48:49 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atipblag.dat
2015-12-17 11:48:48 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6v.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-12-17 11:48:48 ----A---- C:\WINDOWS\system32\atipblag.dat
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-12-17 11:48:47 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atiedu64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-12-17 11:48:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\SYSWOW64\ati2edxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atibtmon.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-12-17 11:48:45 ----A---- C:\WINDOWS\system32\amdverag.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\rixdicon.dll
2015-12-17 11:46:03 ----A---- C:\WINDOWS\system32\drivers\rixdpx64.sys
2015-12-17 11:45:29 ----A---- C:\WINDOWS\system32\drivers\ITEhidCIR.sys
2015-12-17 11:45:06 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-17 11:39:11 ----D---- C:\Users\marilynman\AppData\Roaming\Adobe

======List of files/folders modified in the last 1 month======

2016-01-11 20:54:10 ----D---- C:\WINDOWS\Temp
2016-01-11 20:51:32 ----D---- C:\WINDOWS\system32\sru
2016-01-11 20:47:40 ----RD---- C:\Program Files (x86)
2016-01-11 20:47:40 ----D---- C:\Windows
2016-01-11 19:10:11 ----D---- C:\WINDOWS\System32
2016-01-11 19:10:11 ----D---- C:\WINDOWS\INF
2016-01-11 19:10:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-11 18:28:08 ----D---- C:\WINDOWS\system32\drivers
2016-01-11 18:26:18 ----D---- C:\WINDOWS\system32\Tasks
2016-01-11 18:26:16 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-01-11 18:26:12 ----HD---- C:\ProgramData
2016-01-11 18:26:09 ----D---- C:\Program Files (x86)\Common Files
2016-01-11 18:26:07 ----RD---- C:\Program Files
2016-01-11 16:41:24 ----D---- C:\WINDOWS\WinSxS
2016-01-11 16:01:39 ----D---- C:\WINDOWS\SoftwareDistribution
2016-01-11 15:50:52 ----D---- C:\WINDOWS\debug
2016-01-11 13:29:10 ----D---- C:\WINDOWS\system32\config
2016-01-11 13:20:19 ----D---- C:\Program Files\Common Files
2016-01-11 11:16:01 ----D---- C:\WINDOWS\AppReadiness
2016-01-11 11:16:00 ----HD---- C:\Program Files\WindowsApps
2016-01-11 10:49:12 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-11 10:48:58 ----RD---- C:\WINDOWS\assembly
2016-01-10 09:59:06 ----SHD---- C:\System Volume Information
2016-01-10 09:37:54 ----D---- C:\WINDOWS\Tasks
2016-01-10 09:02:30 ----D---- C:\WINDOWS\system32\WDI
2016-01-10 07:19:16 ----D---- C:\WINDOWS\CbsTemp
2016-01-07 07:43:45 ----D---- C:\WINDOWS\SysWOW64
2016-01-06 09:08:16 ----D---- C:\WINDOWS\Logs
2016-01-06 07:04:44 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 17:43:45 ----D---- C:\WINDOWS\system32\restore
2016-01-03 16:16:59 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-01-03 14:20:39 ----D---- C:\WINDOWS\appcompat
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-02 15:11:47 ----RD---- C:\WINDOWS\DevicesFlow
2016-01-02 15:02:54 ----D---- C:\WINDOWS\rescache
2016-01-02 14:52:26 ----RD---- C:\WINDOWS\PrintDialog
2016-01-02 14:52:24 ----RD---- C:\WINDOWS\MiracastView
2016-01-02 14:51:38 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-01-02 14:49:07 ----SD---- C:\ProgramData\Microsoft
2016-01-02 14:47:32 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-01-02 14:44:05 ----D---- C:\WINDOWS\Registration
2016-01-02 14:39:22 ----D---- C:\WINDOWS\system32\LogFiles
2016-01-02 14:37:54 ----D---- C:\WINDOWS\system32\drivers\etc
2016-01-02 14:37:43 ----D---- C:\WINDOWS\system32\wbem
2016-01-02 14:35:45 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-02 14:34:14 ----D---- C:\WINDOWS\system32\catroot2
2016-01-02 14:31:34 ----HD---- C:\WINDOWS\Installer
2016-01-02 14:27:15 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-01-02 14:27:12 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2016-01-02 14:27:03 ----D---- C:\WINDOWS\system32\spool
2016-01-02 14:27:01 ----D---- C:\WINDOWS\system32\slmgr
2016-01-02 14:26:39 ----D---- C:\WINDOWS\system32\CatRoot
2016-01-02 14:26:32 ----RD---- C:\WINDOWS\PurchaseDialog
2016-01-02 14:26:31 ----D---- C:\WINDOWS\PolicyDefinitions
2016-01-02 14:26:18 ----RD---- C:\Users
2016-01-02 14:26:18 ----D---- C:\ProgramData\USOPrivate
2016-01-02 14:25:51 ----HD---- C:\WINDOWS\system32\GroupPolicy
2016-01-02 14:25:51 ----D---- C:\WINDOWS\system32\Recovery
2016-01-02 14:22:04 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-01-02 14:21:03 ----D---- C:\WINDOWS\system32\Sysprep
2016-01-02 14:12:20 ----D---- C:\WINDOWS\ServiceProfiles
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-01-02 08:35:50 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-01-02 08:35:49 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\sk-SK
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\oobe
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\migration
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\Dism
2016-01-02 08:35:48 ----D---- C:\WINDOWS\system32\appraiser
2016-01-02 08:35:47 ----D---- C:\WINDOWS\Provisioning
2016-01-02 08:35:47 ----D---- C:\WINDOWS\bcastdvr
2016-01-02 08:35:47 ----D---- C:\WINDOWS\AppPatch
2016-01-02 08:35:47 ----D---- C:\Program Files\Internet Explorer
2016-01-02 08:35:47 ----D---- C:\Program Files (x86)\Internet Explorer
2016-01-02 08:21:19 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-01-02 08:21:19 ----D---- C:\WINDOWS\system32\en-US
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnet.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2016-01-02 08:21:14 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2016-01-02 08:21:13 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2016-01-02 04:43:50 ----RASH---- C:\BOOTSECT.BAK
2016-01-02 04:43:47 ----SHD---- C:\Boot
2016-01-02 04:32:16 ----HD---- C:\$WINDOWS.~BT
2015-12-19 11:24:39 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-01-11 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-01-11 273784]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-01-11 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-01-11 1055560]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-01-11 451040]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-01-11 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-01-11 97648]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-01-11 155304]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 rimmptsk;rimmptsk; C:\WINDOWS\System32\drivers\rimmpx64.sys [2015-12-17 52224]
R2 rismxdp;@oem7.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdpx64.sys [2015-12-17 55296]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-12-17 11922944]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-12-17 359936]
R3 BCM43XX;@netbc63a.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\System32\drivers\bcmwl63al.sys [2015-10-30 5170176]
R3 HTCAND64;@oem0.inf,%HTCAND64.SvcDesc%;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 ITEhidCIR;@oem1.inf,%VHidMini%;ITECIR Hid Driver; C:\WINDOWS\System32\drivers\ITEhidCIR.sys [2015-12-17 33488]
R3 k57nd60a;@netk57a.inf,%SvcDispName%;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\WINDOWS\System32\drivers\k57nd60a.sys [2015-10-30 446464]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys []
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-01-02 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 htcnprot;@oem8.inf,%NDISPROT_Desc%;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2013-10-17 36928]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2015-10-30 67072]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-12-17 238080]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-01-11 226440]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-04-02 87368]
R2 OneSyncSvc_39852;Sync Host_39852; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_19213b;Sync Host_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2d725;Sync Host_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_44d52;Sync Host_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_66d24;Sync Host_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bb8fa;Sync Host_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bdb193;Sync Host_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-30 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_19213b;MessagingService_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2d725;MessagingService_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_39852;MessagingService_39852; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44d52;MessagingService_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_66d24;MessagingService_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bb8fa;MessagingService_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bdb193;MessagingService_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-10 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_19213b;Kontaktné údaje_19213b; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2d725;Kontaktné údaje_2d725; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_39852;Kontaktné údaje_39852; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44d52;Kontaktné údaje_44d52; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_66d24;Kontaktné údaje_66d24; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bb8fa;Kontaktné údaje_bb8fa; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_bdb193;Kontaktné údaje_bdb193; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_19213b;Ukladací priestor používateľských údajov_19213b; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2d725;Ukladací priestor používateľských údajov_2d725; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_39852;Ukladací priestor používateľských údajov_39852; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_44d52;Ukladací priestor používateľských údajov_44d52; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_66d24;Ukladací priestor používateľských údajov_66d24; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bb8fa;Ukladací priestor používateľských údajov_bb8fa; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_bdb193;Ukladací priestor používateľských údajov_bdb193; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: surna pomoc nb plny korejskych vecí

#8 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\marilynman.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět