Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

malware v prohlížeči

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

malware v prohlížeči

#1 Příspěvek od Sergeii »

Dobrý den,
prosím o kontrolu logu, vyskakovací okna v prohlížeči (chrome,IE) - přesměrování na jiné stránky po kliknutí, změna výchozích vyhledavačů. Moc díky

Logfile of random's system information tool 1.16 (written by random/random)
Run by Aneta at 2017-04-14 14:53:44
Microsoft Windows 10 Home
System drive C: has 347 GB (76%) free of 458 GB
Total RAM: 3982 MB (49% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:53:48, on 14. 4. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Games\World_of_Tanks\WargamingGameUpdater.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files\trend micro\Aneta_RSITx64.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com?pc=HPNTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://no-stop.org/wpad.dat?08e95538214 ... 9d20988269
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: PDF Architect 5 Helper - {AEA429F3-D2D4-4BD7-A03E-5357DA017733} - C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll
O3 - Toolbar: PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [WarThunderLauncher] C:\WarThunder\launcher.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [World of Tanks] "C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LavasoftTcpService - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Architect 5 - pdfforge GmbH - C:\Program Files\PDF Architect 5\ws.exe
O23 - Service: PDF Architect 5 CrashHandler - pdfforge GmbH - C:\Program Files\PDF Architect 5\crash-handler-ws.exe
O23 - Service: PDF Architect 5 Creator - pdfforge GmbH - C:\Program Files\PDF Architect 5\creator-ws.exe
O23 - Service: PDF Architect 5 Manager - © pdfforge GmbH. - C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9762 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\WLANExt.exe 2611761008128
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe"
"C:\Program Files\PDF Architect 5\creator-ws.exe"
C:\WINDOWS\system32\dashost.exe
"C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\igfxEM.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64.exe"
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\iPod\bin\iPodService.exe"
C:\WINDOWS\system32\AUDIODG.EXE 0x2dc
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Aneta\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=57.0.2987.133 --initial-client-data=0x1ac,0x1b0,0x1b4,0x1a8,0x1b8,0x7fff72b33970,0x7fff72b33960,0x7fff72b33980
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=8624 --on-initialized-event-handle=616 --parent-handle=620 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1328 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,19,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4358 --gpu-driver-date=12-21-2015 --service-request-channel-token=1834FB45293E9396003EF90847FF67A2 --mojo-platform-channel-handle=1340 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --lang=cs --service-request-channel-token=A839012744F90603A0E88CB70D32D36B --mojo-platform-channel-handle=2472 --ignored=" --type=renderer " /prefetch:8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1328 --primordial-pipe-token=E6EE828F51C242DAC3117E68F6C21478 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=E6EE828F51C242DAC3117E68F6C21478 --renderer-client-id=4 --mojo-platform-channel-handle=3076 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1328 --primordial-pipe-token=4CE7C1AE99541385C80B3B399F989A4B --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=4CE7C1AE99541385C80B3B399F989A4B --renderer-client-id=13 --mojo-platform-channel-handle=5468 /prefetch:1
C:\WINDOWS\system32\fontdrvhost.exe
"C:\WINDOWS\System32\Taskmgr.exe" /2
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 612 616 624 8192 620
"C:\Users\Aneta\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW
\??\C:\WINDOWS\system32\conhost.exe 0x4

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\WINDOWS\system32\tasks\CLMLSvc_P2G8 - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\WINDOWS\system32\tasks\CLVDLauncher - C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task - C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\SafeZone scheduled Autoupdate 1475551016 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\Synaptics TouchPad Enhancements - "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{5AAA2B1C-3699-4CD1-B63F-491927679E49} - C:\Windows\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\YCMServiceAgent - C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe RebootDialog
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemovalTools\MRT_HB - C:\Windows\system32\MRT.exe /EHB /Q
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
C:\WINDOWS\system32\tasks\Apple\AppleSoftwareUpdate - C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task

=========Google Chrome=========

C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 2 Avast SafePrice 12.0.102
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension fheoggkfdfchfphceeifdbepaooicaho 2 McAfee® WebAdvisor 5.0.331.0
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gomekmidlodglbbmalcneegieacbdmki 1 Avast Online Security 12.0.209
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5717.116.0.4
Homepage:
default_search_provider.search_url:
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTer ... c=CPNTDFJS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{765B91BB-63FC-4B65-831A-B229EA3C8E56}]
"URL"=http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTer ... c=CPNTDFJS
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{765B91BB-63FC-4B65-831A-B229EA3C8E56}]
"URL"=http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733}]
PDF Architect 5 Helper - C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll [2017-02-10 43400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{84F23192-A475-4038-B5C0-8584777F2DF4} - PDF Architect 5 Toolbar - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll [2017-02-10 553352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-01-14 7510896]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2016-05-03 391648]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2017-01-19 176440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WarThunderLauncher"=C:\WarThunder\launcher.exe [2016-03-10 6021168]
"OneDrive"=C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-04-09 1518808]
"World of Tanks"=C:\Games\World_of_Tanks\WargamingGameUpdater.exe [2017-02-28 3135752]
"iCloudServices"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2017-01-17 67384]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2017-04-04 7946656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2013-10-08 1045304]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-12 205512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1
"PromptOnSecureDesktop"=0
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath" = %SystemRoot%\inf\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-04-14 14:48:38 ----D---- C:\rsit
2017-04-14 14:48:38 ----D---- C:\Program Files\trend micro
2017-04-14 14:44:54 ----D---- C:\ProgramData\SWCUTemp
2017-04-14 14:40:23 ----A---- C:\WINDOWS\SYSWOW64\LavasoftTcpServiceOff.ini
2017-04-14 14:40:23 ----A---- C:\WINDOWS\system32\LavasoftTcpServiceOff.ini
2017-04-14 14:40:20 ----A---- C:\WINDOWS\system32\LavasoftTcpService64.dll
2017-04-14 14:40:19 ----A---- C:\WINDOWS\SYSWOW64\LavasoftTcpService.dll
2017-04-14 14:37:10 ----D---- C:\AdwCleaner
2017-04-14 14:31:27 ----HD---- C:\OneDriveTemp
2017-04-13 16:20:04 ----D---- C:\Users\Aneta\AppData\Roaming\SUPERAntiSpyware.com
2017-04-13 16:19:48 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2017-04-13 16:19:48 ----D---- C:\Program Files\SUPERAntiSpyware
2017-04-11 00:49:39 ----D---- C:\Users\Aneta\AppData\Roaming\TS3Client
2017-04-11 00:36:17 ----AD---- C:\Program Files\TeamSpeak 3 Client
2017-04-03 22:24:09 ----D---- C:\ProgramData\Application Data
2017-04-03 22:23:49 ----D---- C:\Users\Aneta\AppData\Roaming\Lavasoft
2017-04-03 22:23:36 ----D---- C:\Program Files (x86)\Lavasoft
2017-04-03 22:22:31 ----D---- C:\ProgramData\Lavasoft
2017-04-03 22:22:09 ----D---- C:\Users\Aneta\AppData\Roaming\Seznam.cz
2017-04-03 22:21:45 ----D---- C:\ProgramData\pdfforge
2017-04-03 22:18:26 ----D---- C:\Users\Aneta\AppData\Roaming\PDF Architect 5
2017-04-03 22:18:07 ----AD---- C:\Program Files\PDF Architect 5
2017-04-03 22:18:07 ----AD---- C:\Program Files (x86)\PDF Architect 5
2017-04-03 22:15:39 ----D---- C:\ProgramData\PDF Architect 5
2017-04-03 22:15:34 ----A---- C:\WINDOWS\system32\pdfcmon.dll
2017-04-03 22:15:00 ----D---- C:\Program Files\PDFCreator
2017-04-02 11:24:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-04-02 11:24:43 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-04-02 11:24:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-04-02 11:24:42 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-04-02 11:24:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-04-02 11:24:39 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-04-02 11:24:39 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-04-02 11:24:38 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-04-02 11:24:38 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-04-02 11:24:37 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-04-02 11:24:36 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-04-02 11:24:35 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-04-02 11:24:34 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-04-02 11:24:33 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-04-02 11:24:33 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-04-02 11:24:32 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-04-02 11:24:32 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-04-02 11:24:32 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-04-02 11:24:31 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-04-02 11:24:31 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-04-02 11:24:30 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-04-02 11:24:30 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-04-02 11:24:29 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-04-02 11:24:29 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-04-02 11:24:29 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-04-02 11:24:29 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-04-02 11:24:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-04-02 11:24:28 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-04-02 11:24:27 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-04-02 11:24:27 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-04-02 11:24:27 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-04-02 11:24:26 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-04-02 11:24:26 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-04-02 11:24:26 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-04-02 11:24:25 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-04-02 11:24:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-04-02 11:24:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-04-02 11:24:25 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-04-02 11:24:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-04-02 11:24:24 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-04-02 11:24:24 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-04-02 11:24:24 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-04-02 11:24:23 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-04-02 11:24:23 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-04-02 11:24:23 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-04-02 11:24:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-04-02 11:24:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-04-02 11:24:22 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-04-02 11:24:22 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-04-02 11:24:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-04-02 11:24:21 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-04-02 11:24:21 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-04-02 11:24:21 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-04-02 11:24:21 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-04-02 11:24:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-04-02 11:24:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-04-02 11:24:20 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-04-02 11:24:20 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-04-02 11:24:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-04-02 11:24:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-04-02 11:24:19 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-04-02 11:24:19 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-04-02 11:24:19 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-04-02 11:24:18 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-04-02 11:24:17 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-04-02 11:24:17 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-04-02 11:24:17 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-04-02 11:24:16 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-04-02 11:24:15 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-04-02 11:24:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-04-02 11:24:15 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-04-02 11:24:15 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-04-02 11:24:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-04-02 11:24:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-04-02 11:24:14 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-04-02 11:24:14 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-04-02 11:24:14 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-04-02 11:24:13 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-04-02 11:24:12 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-04-02 11:24:12 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-04-02 11:24:12 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-04-02 11:24:12 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-04-02 11:24:12 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2017-04-02 11:24:11 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-04-02 11:24:11 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-04-02 11:24:11 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-04-02 11:24:11 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-04-02 11:24:11 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-04-02 11:24:10 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-04-02 11:24:10 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-04-02 11:24:10 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-04-02 11:24:09 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2017-04-02 11:24:09 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-04-02 11:24:09 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2017-04-02 11:24:08 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-04-02 11:24:08 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-04-02 11:24:08 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2017-04-02 11:24:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-04-02 11:24:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-04-02 11:24:07 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-04-02 11:24:06 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-04-02 11:24:06 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2017-04-02 11:24:06 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-04-02 11:24:05 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-04-02 11:24:05 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-04-02 11:24:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-04-02 11:24:05 ----A---- C:\WINDOWS\SYSWOW64\PCPTpm12.dll
2017-04-02 11:24:05 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-04-02 11:24:04 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-04-02 11:24:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-04-02 11:24:04 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-04-02 11:24:04 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-04-02 11:24:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-04-02 11:24:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-04-02 11:24:03 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-04-02 11:24:03 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2017-04-02 11:24:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-04-02 11:24:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-04-02 11:24:02 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-04-02 11:24:01 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-04-02 11:24:00 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-04-02 11:23:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-04-02 11:23:59 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-04-02 11:23:59 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-04-02 11:23:59 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-04-02 11:23:59 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-04-02 11:23:58 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2017-04-02 11:23:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-04-02 11:23:58 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-04-02 11:23:58 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\netiohlp.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-04-02 11:23:57 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-04-02 11:23:56 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-04-02 11:23:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-04-02 11:23:56 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-04-02 11:23:55 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-04-02 11:23:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-04-02 11:23:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-04-02 11:23:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-04-02 11:23:54 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\MCCSEngineShared.dll
2017-04-02 11:23:53 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-04-02 11:23:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-04-02 11:23:52 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-04-02 11:23:52 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-04-02 11:23:52 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-04-02 11:23:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-04-02 11:23:51 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-04-02 11:23:51 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2017-04-02 11:23:50 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-04-02 11:23:49 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2017-04-02 11:23:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-04-02 11:23:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-04-02 11:23:48 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\Pimstore.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2017-04-02 11:23:47 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\msutb.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-04-02 11:23:46 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-04-02 11:23:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-02 11:23:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-04-02 11:23:45 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-04-02 11:23:45 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2017-04-02 11:23:44 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\wlanui.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-04-02 11:23:43 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-04-02 11:23:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-04-02 11:23:42 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-04-02 11:23:42 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-04-02 11:23:42 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\regedit.exe
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-04-02 11:23:41 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-04-02 11:23:41 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2017-04-02 11:23:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Search.dll
2017-04-02 11:23:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-04-02 11:23:40 ----A---- C:\WINDOWS\SYSWOW64\MSPhotography.dll
2017-04-02 11:23:40 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-04-02 11:23:39 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-04-02 11:23:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-04-02 11:23:39 ----A---- C:\WINDOWS\SYSWOW64\wcnwiz.dll
2017-04-02 11:23:39 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-04-02 11:23:39 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2017-04-02 11:23:38 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-04-02 11:23:38 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2017-04-02 11:23:38 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-04-02 11:23:38 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2017-04-02 11:23:37 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2017-04-02 11:23:37 ----A---- C:\WINDOWS\SYSWOW64\mscandui.dll
2017-04-02 11:23:37 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-04-02 11:23:37 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.UI.GameBar.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\DavSyncProvider.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-04-02 11:23:36 ----A---- C:\WINDOWS\SYSWOW64\BrowserSettingSync.dll
2017-04-02 11:23:35 ----A---- C:\WINDOWS\SYSWOW64\XInputUap.dll
2017-04-02 11:23:35 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-04-02 11:23:35 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-04-02 11:23:35 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2017-04-02 11:23:35 ----A---- C:\WINDOWS\SYSWOW64\accountaccessor.dll
2017-04-02 11:23:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-04-02 11:23:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-04-02 11:23:34 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2017-04-02 11:23:34 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-04-02 11:23:34 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2017-04-02 11:23:33 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-04-02 11:23:33 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-04-02 11:23:33 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\msctfui.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-04-02 11:23:32 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-04-02 11:23:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-04-02 11:23:31 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-04-02 11:23:31 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-04-02 11:23:30 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2017-04-02 11:23:30 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2017-04-02 11:23:30 ----A---- C:\WINDOWS\SYSWOW64\ddrawex.dll
2017-04-02 11:23:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-04-02 11:23:29 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-04-02 11:23:29 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-04-02 11:23:28 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-04-02 11:23:28 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-04-02 11:23:28 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-04-02 11:23:27 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-04-02 11:23:27 ----A---- C:\WINDOWS\SYSWOW64\GamePanelExternalHook.dll
2017-04-02 11:23:27 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2017-04-02 11:23:17 ----A---- C:\WINDOWS\system32\tquery.dll
2017-04-02 11:23:16 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-04-02 11:23:16 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-04-02 11:23:15 ----A---- C:\WINDOWS\SYSWOW64\wmpmde.dll
2017-04-02 11:23:15 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-04-02 11:23:15 ----A---- C:\WINDOWS\system32\wmpmde.dll
2017-04-02 11:23:13 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-04-02 11:23:13 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-04-02 11:23:12 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2017-04-02 11:23:12 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-04-02 11:23:12 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-04-02 11:23:11 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-04-02 11:23:11 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-04-02 11:23:09 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-04-02 11:23:05 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-04-02 11:23:04 ----A---- C:\WINDOWS\system32\XblGameSaveExt.dll
2017-04-02 11:22:55 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2017-04-02 11:22:54 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-04-02 11:22:54 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-04-02 11:22:53 ----A---- C:\WINDOWS\system32\mssph.dll
2017-04-02 11:22:52 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-04-02 11:22:52 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-04-02 11:22:52 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-04-02 11:22:52 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-04-02 11:22:51 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-04-02 11:22:51 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-04-02 11:22:51 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-04-02 11:22:51 ----A---- C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-04-02 11:22:51 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-04-02 11:22:50 ----A---- C:\WINDOWS\SYSWOW64\WPDShServiceObj.dll
2017-04-02 11:22:50 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-04-02 11:22:50 ----A---- C:\WINDOWS\system32\wlanui.dll
2017-04-02 11:22:50 ----A---- C:\WINDOWS\system32\wcnwiz.dll
2017-04-02 11:22:49 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-04-02 11:22:49 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-04-02 11:22:49 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-04-02 11:22:49 ----A---- C:\WINDOWS\system32\mssitlb.dll
2017-04-02 11:22:48 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-04-02 11:22:48 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-04-02 11:22:48 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-04-02 11:22:47 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-04-02 11:22:45 ----A---- C:\WINDOWS\system32\wmp.dll
2017-04-02 11:22:44 ----A---- C:\WINDOWS\system32\shell32.dll
2017-04-02 11:22:42 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-04-02 11:22:41 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-04-02 11:22:40 ----A---- C:\WINDOWS\system32\mos.dll
2017-04-02 11:22:39 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-04-02 11:22:38 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-04-02 11:22:37 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-04-02 11:22:36 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2017-04-02 11:22:36 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-04-02 11:22:35 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-04-02 11:22:35 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-04-02 11:22:35 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-04-02 11:22:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-04-02 11:22:34 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2017-04-02 11:22:33 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-04-02 11:22:33 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-04-02 11:22:33 ----A---- C:\WINDOWS\system32\MapGeocoder.dll
2017-04-02 11:22:32 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-04-02 11:22:32 ----A---- C:\WINDOWS\system32\MapRouter.dll
2017-04-02 11:22:32 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-04-02 11:22:31 ----A---- C:\WINDOWS\system32\Wpc.dll
2017-04-02 11:22:31 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-04-02 11:22:31 ----A---- C:\WINDOWS\system32\MapsStore.dll
2017-04-02 11:22:30 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-04-02 11:22:30 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-04-02 11:22:30 ----A---- C:\WINDOWS\system32\ContactApis.dll
2017-04-02 11:22:29 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-04-02 11:22:29 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-04-02 11:22:28 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-04-02 11:22:28 ----A---- C:\WINDOWS\system32\mfplat.dll
2017-04-02 11:22:28 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-04-02 11:22:27 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-04-02 11:22:27 ----A---- C:\WINDOWS\system32\localspl.dll
2017-04-02 11:22:26 ----A---- C:\WINDOWS\system32\wpncore.dll
2017-04-02 11:22:26 ----A---- C:\WINDOWS\system32\mmc.exe
2017-04-02 11:22:26 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-04-02 11:22:25 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-04-02 11:22:25 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-04-02 11:22:25 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2017-04-02 11:22:24 ----A---- C:\WINDOWS\system32\WpcMon.exe
2017-04-02 11:22:24 ----A---- C:\WINDOWS\system32\wlansec.dll
2017-04-02 11:22:24 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-04-02 11:22:24 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-04-02 11:22:24 ----A---- C:\WINDOWS\system32\LockAppBroker.dll
2017-04-02 11:22:23 ----A---- C:\WINDOWS\system32\SpeechPal.dll
2017-04-02 11:22:23 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-04-02 11:22:23 ----A---- C:\WINDOWS\system32\msxml3.dll
2017-04-02 11:22:23 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-04-02 11:22:22 ----A---- C:\WINDOWS\system32\wlansvc.dll
2017-04-02 11:22:22 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-04-02 11:22:22 ----A---- C:\WINDOWS\system32\mprddm.dll
2017-04-02 11:22:22 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-04-02 11:22:21 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-04-02 11:22:21 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-04-02 11:22:21 ----A---- C:\WINDOWS\system32\ntshrui.dll
2017-04-02 11:22:21 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2017-04-02 11:22:21 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-04-02 11:22:20 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2017-04-02 11:22:20 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-04-02 11:22:20 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2017-04-02 11:22:20 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-04-02 11:22:20 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2017-04-02 11:22:20 ----A---- C:\WINDOWS\system32\mf.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\usocore.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-04-02 11:22:19 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-04-02 11:22:18 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-04-02 11:22:18 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-04-02 11:22:18 ----A---- C:\WINDOWS\system32\Pimstore.dll
2017-04-02 11:22:17 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-04-02 11:22:17 ----A---- C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-04-02 11:22:17 ----A---- C:\WINDOWS\system32\rasgcw.dll
2017-04-02 11:22:17 ----A---- C:\WINDOWS\system32\ChatApis.dll
2017-04-02 11:22:17 ----A---- C:\WINDOWS\system32\AuthHost.exe
2017-04-02 11:22:16 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-04-02 11:22:16 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-04-02 11:22:16 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-04-02 11:22:16 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2017-04-02 11:22:16 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2017-04-02 11:22:15 ----A---- C:\WINDOWS\system32\wlanapi.dll
2017-04-02 11:22:15 ----A---- C:\WINDOWS\system32\UserDataService.dll
2017-04-02 11:22:15 ----A---- C:\WINDOWS\system32\mfds.dll
2017-04-02 11:22:15 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2017-04-02 11:22:15 ----A---- C:\WINDOWS\system32\InputService.dll
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\WlanMediaManager.dll
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\moshost.dll
2017-04-02 11:22:14 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2017-04-02 11:22:13 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-04-02 11:22:13 ----A---- C:\WINDOWS\system32\mfsvr.dll
2017-04-02 11:22:13 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-04-02 11:22:13 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2017-04-02 11:22:13 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2017-04-02 11:22:12 ----A---- C:\WINDOWS\system32\RADCUI.dll
2017-04-02 11:22:12 ----A---- C:\WINDOWS\system32\MCCSEngineShared.dll
2017-04-02 11:22:12 ----A---- C:\WINDOWS\system32\internetmail.dll
2017-04-02 11:22:12 ----A---- C:\WINDOWS\system32\FrameServer.dll
2017-04-02 11:22:11 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-04-02 11:22:11 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-04-02 11:22:11 ----A---- C:\WINDOWS\system32\usoapi.dll
2017-04-02 11:22:11 ----A---- C:\WINDOWS\system32\MSPhotography.dll
2017-04-02 11:22:10 ----A---- C:\WINDOWS\system32\RelPost.exe
2017-04-02 11:22:10 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-04-02 11:22:10 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-04-02 11:22:10 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-04-02 11:22:10 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-04-02 11:22:09 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-02 11:22:09 ----A---- C:\WINDOWS\system32\wfdprov.dll
2017-04-02 11:22:09 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2017-04-02 11:22:09 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-04-02 11:22:08 ----A---- C:\WINDOWS\system32\netshell.dll
2017-04-02 11:22:08 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2017-04-02 11:22:08 ----A---- C:\WINDOWS\system32\ExSMime.dll
2017-04-02 11:22:07 ----A---- C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-04-02 11:22:07 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-04-02 11:22:07 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-04-02 11:22:07 ----A---- C:\WINDOWS\system32\sdengin2.dll
2017-04-02 11:22:07 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2017-04-02 11:22:06 ----A---- C:\WINDOWS\system32\Unistore.dll
2017-04-02 11:22:06 ----A---- C:\WINDOWS\system32\PrintRenderAPIHost.DLL
2017-04-02 11:22:06 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2017-04-02 11:22:06 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\wpninprc.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\puiapi.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\DavSyncProvider.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\cemapi.dll
2017-04-02 11:22:05 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2017-04-02 11:22:04 ----A---- C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-04-02 11:22:04 ----A---- C:\WINDOWS\system32\tapi32.dll
2017-04-02 11:22:04 ----A---- C:\WINDOWS\system32\sdshext.dll
2017-04-02 11:22:04 ----A---- C:\WINDOWS\system32\pnidui.dll
2017-04-02 11:22:04 ----A---- C:\WINDOWS\system32\DuCsps.dll
2017-04-02 11:22:03 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-04-02 11:22:03 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-04-02 11:22:03 ----A---- C:\WINDOWS\system32\netiougc.exe
2017-04-02 11:22:02 ----A---- C:\WINDOWS\system32\VCardParser.dll
2017-04-02 11:22:00 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-04-02 11:21:58 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-04-02 11:21:56 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-04-02 11:21:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-04-02 11:21:53 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-04-02 11:21:50 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-04-02 11:21:48 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-04-02 11:21:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-04-02 11:21:45 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2017-04-02 11:21:44 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-04-02 11:21:43 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-04-02 11:21:43 ----A---- C:\WINDOWS\system32\wininet.dll
2017-04-02 11:21:41 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-04-02 11:21:41 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-04-02 11:21:40 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-04-02 11:21:40 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-04-02 11:21:40 ----A---- C:\WINDOWS\system32\d3d11.dll
2017-04-02 11:21:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-04-02 11:21:38 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-04-02 11:21:37 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2017-04-02 11:21:37 ----A---- C:\WINDOWS\system32\comsvcs.dll
2017-04-02 11:21:36 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-04-02 11:21:36 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-04-02 11:21:36 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-04-02 11:21:36 ----A---- C:\WINDOWS\system32\dxgi.dll
2017-04-02 11:21:35 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-04-02 11:21:35 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-04-02 11:21:35 ----A---- C:\WINDOWS\system32\inetcomm.dll
2017-04-02 11:21:35 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-04-02 11:21:35 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2017-04-02 11:21:34 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-04-02 11:21:34 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-04-02 11:21:34 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-04-02 11:21:34 ----A---- C:\WINDOWS\system32\schannel.dll
2017-04-02 11:21:34 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll
2017-04-02 11:21:33 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-04-02 11:21:33 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-04-02 11:21:33 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-04-02 11:21:33 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-04-02 11:21:32 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-04-02 11:21:32 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-04-02 11:21:31 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-04-02 11:21:31 ----A---- C:\WINDOWS\system32\winmde.dll
2017-04-02 11:21:31 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-04-02 11:21:31 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-04-02 11:21:30 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-04-02 11:21:30 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\vpnike.dll
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-04-02 11:21:29 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2017-04-02 11:21:28 ----A---- C:\WINDOWS\system32\uDWM.dll
2017-04-02 11:21:28 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-04-02 11:21:27 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-04-02 11:21:27 ----A---- C:\WINDOWS\HelpPane.exe
2017-04-02 11:21:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2017-04-02 11:21:26 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-04-02 11:21:26 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2017-04-02 11:21:25 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-04-02 11:21:25 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-04-02 11:21:25 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2017-04-02 11:21:25 ----A---- C:\WINDOWS\system32\DMRServer.dll
2017-04-02 11:21:24 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-04-02 11:21:24 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-04-02 11:21:24 ----A---- C:\WINDOWS\system32\SettingSync.dll
2017-04-02 11:21:24 ----A---- C:\WINDOWS\system32\quartz.dll
2017-04-02 11:21:23 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2017-04-02 11:21:23 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-04-02 11:21:23 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-04-02 11:21:22 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-04-02 11:21:21 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-04-02 11:21:21 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-04-02 11:21:19 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-04-02 11:21:19 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-04-02 11:21:19 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-04-02 11:21:18 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-04-02 11:21:18 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-04-02 11:21:18 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-04-02 11:21:18 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2017-04-02 11:21:18 ----A---- C:\WINDOWS\system32\evr.dll
2017-04-02 11:21:17 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-04-02 11:21:15 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-04-02 11:21:13 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-04-02 11:21:13 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-04-02 11:21:13 ----A---- C:\WINDOWS\system32\thumbcache.dll
2017-04-02 11:21:13 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-04-02 11:21:13 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-04-02 11:21:12 ----A---- C:\WINDOWS\system32\PhotoScreensaver.scr
2017-04-02 11:21:12 ----A---- C:\WINDOWS\system32\MFPlay.dll
2017-04-02 11:21:12 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-04-02 11:21:12 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-04-02 11:21:11 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-04-02 11:21:10 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-04-02 11:21:10 ----A---- C:\WINDOWS\system32\Tabbtn.dll
2017-04-02 11:21:10 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-04-02 11:21:10 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-04-02 11:21:10 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2017-04-02 11:21:09 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-02 11:21:09 ----A---- C:\WINDOWS\system32\icm32.dll
2017-04-02 11:21:09 ----A---- C:\WINDOWS\system32\dialclient.dll
2017-04-02 11:21:08 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-04-02 11:21:08 ----A---- C:\WINDOWS\system32\shutdownux.dll
2017-04-02 11:21:08 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-04-02 11:21:08 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2017-04-02 11:21:07 ----A---- C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2017-04-02 11:21:07 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-04-02 11:21:07 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-04-02 11:21:06 ----A---- C:\WINDOWS\SYSWOW64\PhotoScreensaver.scr
2017-04-02 11:21:06 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-04-02 11:21:06 ----A---- C:\WINDOWS\system32\drivers\mskssrv.sys
2017-04-02 11:21:05 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-04-02 11:21:05 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-04-02 11:21:05 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-04-02 11:21:04 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2017-04-02 11:21:04 ----A---- C:\WINDOWS\system32\WorkFolders.exe
2017-04-02 11:21:04 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-04-02 11:21:04 ----A---- C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-04-02 11:21:03 ----A---- C:\WINDOWS\system32\tbauth.dll
2017-04-02 11:21:03 ----A---- C:\WINDOWS\system32\fhcfg.dll
2017-04-02 11:21:03 ----A---- C:\WINDOWS\system32\BrowserSettingSync.dll
2017-04-02 11:21:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-04-02 11:21:02 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-04-02 11:21:02 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2017-04-02 11:21:02 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-04-02 11:21:02 ----A---- C:\WINDOWS\system32\CameraCaptureUI.dll
2017-04-02 11:21:02 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-04-02 11:21:01 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-04-02 11:21:01 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-04-02 11:21:00 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2017-04-02 11:20:59 ----A---- C:\WINDOWS\system32\ddrawex.dll
2017-04-02 11:20:58 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-04-02 11:20:58 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2017-04-02 11:20:58 ----A---- C:\WINDOWS\system32\ddraw.dll
2017-04-02 11:20:45 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-04-02 11:20:42 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-04-02 11:20:41 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-04-02 11:20:41 ----A---- C:\WINDOWS\system32\twinui.dll
2017-04-02 11:20:41 ----A---- C:\WINDOWS\system32\aepic.dll
2017-04-02 11:20:40 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2017-04-02 11:20:40 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-04-02 11:20:40 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-04-02 11:20:40 ----A---- C:\WINDOWS\explorer.exe
2017-04-02 11:20:39 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-04-02 11:20:39 ----A---- C:\WINDOWS\system32\bisrv.dll
2017-04-02 11:20:38 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-04-02 11:20:38 ----A---- C:\WINDOWS\system32\mispace.dll
2017-04-02 11:20:37 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-04-02 11:20:37 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-04-02 11:20:36 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-04-02 11:20:35 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-04-02 11:20:35 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-04-02 11:20:34 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-04-02 11:20:34 ----A---- C:\WINDOWS\system32\msctf.dll
2017-04-02 11:20:34 ----A---- C:\WINDOWS\system32\devinv.dll
2017-04-02 11:20:33 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-04-02 11:20:33 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-04-02 11:20:33 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\dcntel.dll
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\CspCellularSettings.dll
2017-04-02 11:20:32 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-04-02 11:20:31 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2017-04-02 11:20:31 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-04-02 11:20:31 ----A---- C:\WINDOWS\system32\generaltel.dll
2017-04-02 11:20:30 ----A---- C:\WINDOWS\system32\winload.exe
2017-04-02 11:20:29 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-04-02 11:20:29 ----A---- C:\WINDOWS\system32\invagent.dll
2017-04-02 11:20:28 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2017-04-02 11:20:28 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-04-02 11:20:28 ----A---- C:\WINDOWS\system32\clusapi.dll
2017-04-02 11:20:26 ----A---- C:\WINDOWS\system32\winresume.exe
2017-04-02 11:20:26 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-04-02 11:20:25 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-04-02 11:20:25 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-04-02 11:20:24 ----A---- C:\WINDOWS\system32\twinapi.dll
2017-04-02 11:20:24 ----A---- C:\WINDOWS\system32\resutils.dll
2017-04-02 11:20:24 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-04-02 11:20:23 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-04-02 11:20:23 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-04-02 11:20:22 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-04-02 11:20:22 ----A---- C:\WINDOWS\system32\imapi2fs.dll
2017-04-02 11:20:22 ----A---- C:\WINDOWS\system32\gameux.dll
2017-04-02 11:20:21 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-04-02 11:20:21 ----A---- C:\WINDOWS\system32\wer.dll
2017-04-02 11:20:21 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-04-02 11:20:21 ----A---- C:\WINDOWS\system32\uReFS.dll
2017-04-02 11:20:20 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-04-02 11:20:20 ----A---- C:\WINDOWS\system32\UIRibbon.dll
2017-04-02 11:20:20 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-04-02 11:20:20 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-04-02 11:20:19 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-04-02 11:20:19 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-04-02 11:20:18 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-04-02 11:20:18 ----A---- C:\WINDOWS\system32\themecpl.dll
2017-04-02 11:20:18 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-04-02 11:20:18 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-04-02 11:20:17 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-04-02 11:20:17 ----A---- C:\WINDOWS\system32\ubpm.dll
2017-04-02 11:20:17 ----A---- C:\WINDOWS\system32\authui.dll
2017-04-02 11:20:17 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-04-02 11:20:17 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-04-02 11:20:16 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-04-02 11:20:16 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-04-02 11:20:15 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-04-02 11:20:15 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2017-04-02 11:20:15 ----A---- C:\WINDOWS\system32\bootux.dll
2017-04-02 11:20:14 ----A---- C:\WINDOWS\system32\reseteng.dll
2017-04-02 11:20:14 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-04-02 11:20:14 ----A---- C:\WINDOWS\system32\ci.dll
2017-04-02 11:20:13 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-04-02 11:20:13 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-04-02 11:20:13 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-04-02 11:20:12 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-04-02 11:20:12 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-04-02 11:20:12 ----A---- C:\WINDOWS\system32\stobject.dll
2017-04-02 11:20:12 ----A---- C:\WINDOWS\system32\dui70.dll
2017-04-02 11:20:11 ----A---- C:\WINDOWS\system32\VSSVC.exe
2017-04-02 11:20:11 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-04-02 11:20:11 ----A---- C:\WINDOWS\system32\PCPTpm12.dll
2017-04-02 11:20:11 ----A---- C:\WINDOWS\system32\icsvcext.dll
2017-04-02 11:20:10 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2017-04-02 11:20:10 ----A---- C:\WINDOWS\system32\DXP.dll
2017-04-02 11:20:10 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2017-04-02 11:20:09 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-04-02 11:20:09 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-04-02 11:20:09 ----A---- C:\WINDOWS\system32\SensorDataService.exe
2017-04-02 11:20:08 ----A---- C:\WINDOWS\system32\vssapi.dll
2017-04-02 11:20:08 ----A---- C:\WINDOWS\system32\drivers\vmbkmcl.sys
2017-04-02 11:20:08 ----A---- C:\WINDOWS\system32\combase.dll
2017-04-02 11:20:08 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2017-04-02 11:20:08 ----A---- C:\WINDOWS\system32\basecsp.dll
2017-04-02 11:20:07 ----A---- C:\WINDOWS\system32\systemreset.exe
2017-04-02 11:20:07 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2017-04-02 11:20:07 ----A---- C:\WINDOWS\system32\CompPkgSup.dll
2017-04-02 11:20:07 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\sud.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\icfupgd.dll
2017-04-02 11:20:06 ----A---- C:\WINDOWS\system32\certprop.dll
2017-04-02 11:20:05 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-04-02 11:20:05 ----A---- C:\WINDOWS\system32\drivers\hvsocket.sys
2017-04-02 11:20:05 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-04-02 11:20:05 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-04-02 11:20:04 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-04-02 11:20:04 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-04-02 11:20:04 ----A---- C:\WINDOWS\system32\wbengine.exe
2017-04-02 11:20:04 ----A---- C:\WINDOWS\system32\gpapi.dll
2017-04-02 11:20:04 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-04-02 11:20:03 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-04-02 11:20:03 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-04-02 11:20:03 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-04-02 11:20:03 ----A---- C:\WINDOWS\system32\input.dll
2017-04-02 11:20:03 ----A---- C:\WINDOWS\system32\drivers\vmbkmclr.sys
2017-04-02 11:20:02 ----A---- C:\WINDOWS\system32\netiohlp.dll
2017-04-02 11:20:02 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-04-02 11:20:02 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-04-02 11:20:02 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-04-02 11:20:02 ----A---- C:\WINDOWS\system32\AudioSes.dll
2017-04-02 11:20:01 ----A---- C:\WINDOWS\system32\spaceman.exe
2017-04-02 11:20:01 ----A---- C:\WINDOWS\system32\scksp.dll
2017-04-02 11:20:00 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-04-02 11:20:00 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-04-02 11:20:00 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-04-02 11:20:00 ----A---- C:\WINDOWS\system32\appinfo.dll
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\tabcal.exe
2017-04-02 11:19:59 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\hgcpl.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\gpsvc.dll
2017-04-02 11:19:58 ----A---- C:\WINDOWS\system32\ApplicationFrame.dll
2017-04-02 11:19:57 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2017-04-02 11:19:57 ----A---- C:\WINDOWS\system32\msutb.dll
2017-04-02 11:19:57 ----A---- C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-04-02 11:19:57 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-04-02 11:19:56 ----A---- C:\WINDOWS\system32\wups.dll
2017-04-02 11:19:56 ----A---- C:\WINDOWS\system32\MultiDigiMon.exe
2017-04-02 11:19:55 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-02 11:19:54 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-04-02 11:19:54 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-04-02 11:19:54 ----A---- C:\WINDOWS\regedit.exe
2017-04-02 11:19:53 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-04-02 11:19:53 ----A---- C:\WINDOWS\system32\werui.dll
2017-04-02 11:19:53 ----A---- C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
2017-04-02 11:19:52 ----A---- C:\WINDOWS\system32\XInputUap.dll
2017-04-02 11:19:52 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-04-02 11:19:52 ----A---- C:\WINDOWS\system32\mscandui.dll
2017-04-02 11:19:51 ----A---- C:\WINDOWS\system32\vds.exe
2017-04-02 11:19:51 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-04-02 11:19:51 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-04-02 11:19:50 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-04-02 11:19:50 ----A---- C:\WINDOWS\system32\mspaint.exe
2017-04-02 11:19:49 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-04-02 11:19:49 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-04-02 11:19:49 ----A---- C:\WINDOWS\system32\msctfui.dll
2017-04-02 11:19:49 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-04-02 11:19:48 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-04-02 11:19:48 ----A---- C:\WINDOWS\system32\msctfp.dll
2017-04-02 11:19:48 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-04-02 11:19:48 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-04-02 11:19:47 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2017-04-02 11:19:47 ----A---- C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-04-02 11:19:46 ----A---- C:\WINDOWS\system32\cdp.dll
2017-04-02 11:19:40 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-04-02 11:19:40 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-04-02 11:18:13 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSetup.exe

====== List of files/folders modified in the last 1 month ======

2017-04-14 14:53:25 ----D---- C:\WINDOWS\Prefetch
2017-04-14 14:53:12 ----HD---- C:\Program Files\WindowsApps
2017-04-14 14:53:05 ----D---- C:\WINDOWS\Temp
2017-04-14 14:48:38 ----RD---- C:\Program Files
2017-04-14 14:44:54 ----HD---- C:\ProgramData
2017-04-14 14:44:16 ----D---- C:\WINDOWS\AppReadiness
2017-04-14 14:42:43 ----D---- C:\WINDOWS\system32\sru
2017-04-14 14:41:51 ----D---- C:\WINDOWS\System32
2017-04-14 14:41:51 ----D---- C:\Windows
2017-04-14 14:41:41 ----RD---- C:\Program Files (x86)
2017-04-14 14:40:23 ----D---- C:\WINDOWS\SysWOW64
2017-04-14 14:34:05 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-14 14:30:37 ----D---- C:\WINDOWS\system32\Tasks
2017-04-14 14:25:46 ----D---- C:\WINDOWS\system32\catroot2
2017-04-14 14:22:47 ----D---- C:\WINDOWS\system32\SleepStudy
2017-04-13 16:19:05 ----D---- C:\WINDOWS\system32\drivers
2017-04-13 07:59:29 ----D---- C:\WINDOWS\system32\config
2017-04-13 07:52:52 ----RD---- C:\WINDOWS\Microsoft.NET
2017-04-12 00:45:03 ----D---- C:\WINDOWS\CbsTemp
2017-04-12 00:39:05 ----D---- C:\WINDOWS\WinSxS
2017-04-11 23:54:14 ----SHD---- C:\WINDOWS\Installer
2017-04-11 02:02:43 ----AD---- C:\KMPlayer
2017-04-11 00:42:51 ----D---- C:\ProgramData\Package Cache
2017-04-11 00:42:13 ----SHD---- C:\System Volume Information
2017-04-09 23:20:39 ----D---- C:\WINDOWS\rescache
2017-04-09 22:23:08 ----RSD---- C:\WINDOWS\assembly
2017-04-09 22:14:51 ----D---- C:\WINDOWS\system32\appraiser
2017-04-04 23:18:27 ----D---- C:\WINDOWS\INF
2017-04-04 23:16:20 ----D---- C:\WINDOWS\system32\DriverStore
2017-04-04 23:09:13 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-04-04 23:09:13 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-04-04 23:09:13 ----D---- C:\WINDOWS\SYSWOW64\migration
2017-04-04 23:09:12 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-04-04 23:09:12 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-04-04 23:09:12 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-04-04 23:08:50 ----D---- C:\WINDOWS\system32\wbem
2017-04-04 23:08:49 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-04-04 23:08:49 ----D---- C:\WINDOWS\system32\setup
2017-04-04 23:08:49 ----D---- C:\WINDOWS\system32\oobe
2017-04-04 23:08:49 ----D---- C:\WINDOWS\system32\migration
2017-04-04 23:08:48 ----SD---- C:\WINDOWS\system32\F12
2017-04-04 23:08:48 ----D---- C:\WINDOWS\system32\en-US
2017-04-04 23:08:48 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2017-04-04 23:08:45 ----D---- C:\WINDOWS\system32\cs-CZ
2017-04-04 23:08:45 ----D---- C:\WINDOWS\system32\Boot
2017-04-04 23:08:21 ----RD---- C:\WINDOWS\PrintDialog
2017-04-04 23:08:21 ----D---- C:\WINDOWS\ShellExperiences
2017-04-04 23:08:17 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-04-04 23:08:17 ----D---- C:\WINDOWS\bcastdvr
2017-04-04 23:08:17 ----D---- C:\WINDOWS\AppPatch
2017-04-04 23:08:16 ----RD---- C:\Program Files\Windows Defender
2017-04-04 23:08:16 ----D---- C:\Program Files\Windows Photo Viewer
2017-04-04 23:08:16 ----D---- C:\Program Files\Windows Mail
2017-04-04 23:08:16 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-04-04 23:08:16 ----D---- C:\Program Files (x86)\Windows Mail
2017-04-04 23:08:16 ----D---- C:\Program Files (x86)\Windows Defender
2017-04-04 23:08:16 ----D---- C:\Program Files (x86)\Internet Explorer
2017-04-04 23:08:12 ----D---- C:\Program Files\Internet Explorer
2017-04-03 23:06:58 ----D---- C:\WINDOWS\system32\MRT
2017-04-03 23:01:07 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-04-03 22:18:07 ----D---- C:\Program Files (x86)\Common Files
2017-03-26 09:56:26 ----D---- C:\WINDOWS\system32\LogFiles
2017-03-26 09:54:58 ----D---- C:\WINDOWS\system32\NDF

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#2 Příspěvek od Sergeii »

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2017-01-31 173472]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; %windir%\system32\svchost.exe -k apphost;"ServiceDll" = %windir%\system32\inetsrv\apphostsvc.dll
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-12 262736]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPUserSvc_3c88c;CDPUserSvc_3c88c; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2013-10-08 1039160]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2016-05-03 337888]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 LavasoftTcpService;LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2017-04-14 2759784]
R2 OneSyncSvc_3c88c;Hostitel synchronizace_3c88c; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 PDF Architect 5 Creator;PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [2017-02-10 856976]
R2 PDF Architect 5 Manager;PDF Architect 5 Manager; C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [2017-02-28 985904]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-10-05 269400]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-12 7147320]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2017-01-19 651576]
R3 PimIndexMaintenanceSvc_3c88c;Data kontaktů_3c88c; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\TimeBrokerServer.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_3c88c;Služba zasílání zpráv_3c88c; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 PDF Architect 5 CrashHandler;PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [2017-02-10 1048976]
S3 PDF Architect 5;PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2017-02-10 2706824]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#4 Příspěvek od Sergeii »

dekuji, podle navodu log nize
# AdwCleaner v6.045 - Log vytvořen 15/04/2017 v 17:15:22
# Aktualizováno dne 28/03/2017 z Malwarebytes
# Databáze : 2017-04-14.1 [Server]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : Aneta - PCAJA
# Spuštěno z : C:\Users\Aneta\Desktop\adwcleaner_6.045.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****

[-] Služba smazána: LavasoftTcpService


***** [ Složky ] *****

[#] Složka smazána po restartu: C:\Program Files (x86)\lavasoft\web companion
[-] Složka smazána: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\LavasoftTcpService


***** [ Soubory ] *****

[-] Soubor smazán: C:\WINDOWS\SysNative\LavasoftTcpService64.dll
[-] Soubor smazán: C:\WINDOWS\SysNative\LavasoftTcpServiceOff.ini
[-] Soubor smazán: C:\WINDOWS\SysWOW64\lavasofttcpservice.dll
[-] Soubor smazán: C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController
[-] Klíč smazán: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1
[-] Klíč smazán: HKLM\SOFTWARE\Classes\AppID\{2CE0F1DC-C504-4B7B-A385-D94A2531DFFB}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057}


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [10543 Bajty] - [14/04/2017 14:42:19]
C:\AdwCleaner\AdwCleaner[C2].txt - [5007 Bajty] - [15/04/2017 17:15:22]
C:\AdwCleaner\AdwCleaner[S0].txt - [11256 Bajty] - [14/04/2017 14:40:59]
C:\AdwCleaner\AdwCleaner[S1].txt - [5122 Bajty] - [15/04/2017 17:14:29]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [5227 Bajty] ##########
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#5 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#6 Příspěvek od Sergeii »

tu je
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 (ATTENTION: ====> FRSTversion is 31 days old and could be outdated)
Ran by Aneta (administrator) on PCAJA (15-04-2017 19:53:29)
Running from C:\Users\Aneta\Desktop
Loaded Profiles: Aneta (Available Profiles: Aneta)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect 5\creator-ws.exe
(© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Wargaming.net) C:\Games\World_of_Tanks\WargamingGameUpdater.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(forum.viry.cz) C:\Users\Aneta\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510896 2014-01-14] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-12] (AVAST Software)
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\...\Run: [WarThunderLauncher] => C:\WarThunder\launcher.exe [6021168 2016-03-10] (Gaijin Entertainment)
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3135752 2017-02-28] (Wargaming.net)
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-01-17] (Apple Inc.)
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7946656 2017-04-04] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-12] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-12] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-2808533366-2824297521-463841363-1001] => hxxp://no-stop.org/wpad.dat?08e95538214102da8198cb9acbe4109d20988269
Tcpip\Parameters: [DhcpNameServer] 77.48.254.254 77.48.100.254
Tcpip\..\Interfaces\{f2e3a008-43d8-4cb3-aa4f-95a0b8127c70}: [DhcpNameServer] 77.48.254.254 77.48.100.254
ManualProxies: 0hxxp://no-stop.org/wpad.dat?08e95538214102da8198cb9acbe4109d20988269

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130970096538815667&GUID=D78FC04B-35D8-ABF0-D563-214895381BD3
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {765B91BB-63FC-4B65-831A-B229EA3C8E56} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {765B91BB-63FC-4B65-831A-B229EA3C8E56} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> DefaultScope {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL =
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: PDF Architect 5 Helper -> {AEA429F3-D2D4-4BD7-A03E-5357DA017733} -> C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll [2017-02-10] (pdfforge GmbH)
Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll [2017-02-10] (pdfforge GmbH)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-10-04]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-10-04]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [2017-02-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default [2017-04-15]
CHR Extension: (Prezentace Google) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-12]
CHR Extension: (Dokumenty Google) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-12]
CHR Extension: (Tabulky Google) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-12]
CHR Extension: (Avast Online Security) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-10]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Chrome Media Router) - C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-09]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-12] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-12] (AVAST Software)
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S3 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2706824 2017-02-10] (pdfforge GmbH)
S3 PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [1048976 2017-02-10] (pdfforge GmbH)
R2 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [856976 2017-02-10] (pdfforge GmbH)
R2 PDF Architect 5 Manager; C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985904 2017-02-28] (© pdfforge GmbH.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2016-10-05] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-03-04] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [309272 2017-03-12] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [189768 2017-03-12] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334600 2017-03-12] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [48528 2017-03-12] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-03-12] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32088 2017-03-12] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [126600 2017-03-12] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [100640 2017-03-12] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-03-12] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [993608 2017-03-12] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [548928 2017-04-02] (AVAST Software)
S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [162528 2017-03-12] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [337592 2017-03-21] (AVAST Software)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283064 2015-01-06] (Disc Soft Ltd)
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
R0 MBI; C:\WINDOWS\System32\drivers\MBI.sys [29464 2014-01-23] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [6294016 2017-02-01] (Realtek Semiconductor Corporation )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [29936 2013-12-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-07-17] (Synaptics Incorporated)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-15 19:53 - 2017-04-15 19:55 - 00017075 _____ C:\Users\Aneta\Desktop\FRST.txt
2017-04-15 19:52 - 2017-04-15 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Aneta\Desktop\FRSTLauncher.exe
2017-04-15 19:52 - 2017-04-15 19:47 - 02424832 _____ (Farbar) C:\Users\Aneta\Desktop\FRST64.exe
2017-04-15 19:50 - 2017-04-15 19:51 - 00112640 _____ (forum.viry.cz) C:\Users\Aneta\Downloads\FRSTLauncher.exe
2017-04-15 19:50 - 2017-04-15 19:50 - 00112640 _____ (forum.viry.cz) C:\Users\Aneta\Downloads\Nepotvrzeno 603444.crdownload
2017-04-15 19:48 - 2017-04-15 19:53 - 00000000 ____D C:\FRST
2017-04-15 19:42 - 2017-04-15 19:47 - 02424832 _____ (Farbar) C:\Users\Aneta\Downloads\FRST64.exe
2017-04-15 17:17 - 2017-04-15 17:17 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-15 17:10 - 2017-04-15 17:10 - 04089296 _____ C:\Users\Aneta\Downloads\adwcleaner_6.045.exe
2017-04-15 17:10 - 2017-04-15 17:10 - 04089296 _____ C:\Users\Aneta\Desktop\adwcleaner_6.045.exe
2017-04-14 14:48 - 2017-04-14 14:53 - 00000000 ____D C:\Program Files\trend micro
2017-04-14 14:48 - 2017-04-14 14:49 - 00000000 ____D C:\rsit
2017-04-14 14:48 - 2017-04-14 14:48 - 01329152 _____ C:\Users\Aneta\Downloads\RSITx64.exe
2017-04-14 14:37 - 2017-04-15 17:15 - 00000000 ____D C:\AdwCleaner
2017-04-14 14:31 - 2017-04-14 14:31 - 00000000 ___HD C:\OneDriveTemp
2017-04-13 16:20 - 2017-04-13 16:20 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\SUPERAntiSpyware.com
2017-04-13 16:19 - 2017-04-13 16:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-04-13 16:19 - 2017-04-13 16:19 - 00001856 _____ C:\Users\Aneta\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-04-13 16:19 - 2017-04-13 16:19 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-04-13 16:19 - 2017-04-13 16:19 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2017-04-13 16:18 - 2017-04-13 16:19 - 29685432 _____ (SUPERAntiSpyware) C:\Users\Aneta\Downloads\SUPERAntiSpyware.exe
2017-04-11 00:53 - 2017-04-11 00:53 - 00000000 ____D C:\Users\Aneta\AppData\Local\TeamSpeak 3
2017-04-11 00:53 - 2017-04-11 00:53 - 00000000 ____D C:\Users\Aneta\.TeamSpeak 3
2017-04-11 00:53 - 2017-04-11 00:53 - 00000000 ____D C:\Users\Aneta\.QtWebEngineProcess
2017-04-11 00:49 - 2017-04-11 01:33 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\TS3Client
2017-04-11 00:36 - 2017-04-11 00:36 - 00001015 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2017-04-11 00:36 - 2017-04-11 00:36 - 00000977 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-04-11 00:36 - 2017-04-11 00:36 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-04-11 00:12 - 2017-04-11 00:17 - 77586344 _____ (TeamSpeak Systems GmbH) C:\Users\Aneta\Downloads\TeamSpeak3-Client-win64-3.1.3.exe
2017-04-04 23:17 - 2017-04-06 23:18 - 00004002 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1475551016
2017-04-03 22:24 - 2017-04-14 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2017-04-03 22:24 - 2017-04-03 22:24 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2017-04-03 22:24 - 2017-04-03 22:24 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2017-04-03 22:24 - 2017-04-03 22:24 - 00000000 ____D C:\Users\Aneta\AppData\Local\Lavasoft
2017-04-03 22:23 - 2017-04-14 14:41 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\Lavasoft
2017-04-03 22:23 - 2017-04-03 22:23 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2017-04-03 22:22 - 2017-04-14 14:41 - 00000000 ____D C:\ProgramData\Lavasoft
2017-04-03 22:22 - 2017-04-13 16:14 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\Seznam.cz
2017-04-03 22:21 - 2017-04-03 22:21 - 00000848 _____ C:\Users\Public\Desktop\PDF Architect 5.lnk
2017-04-03 22:21 - 2017-04-03 22:21 - 00000000 ____D C:\ProgramData\pdfforge
2017-04-03 22:20 - 2017-04-03 22:20 - 00000000 ____D C:\Users\Aneta\AppData\Local\PDFCreator
2017-04-03 22:18 - 2017-04-03 22:24 - 00000000 ____D C:\Users\Aneta\AppData\Roaming\PDF Architect 5
2017-04-03 22:18 - 2017-04-03 22:20 - 00000000 ____D C:\Program Files\PDF Architect 5
2017-04-03 22:18 - 2017-04-03 22:20 - 00000000 ____D C:\Program Files (x86)\PDF Architect 5
2017-04-03 22:18 - 2017-04-03 22:18 - 00000000 ____D C:\Users\Aneta\Documents\PDF Architect
2017-04-03 22:18 - 2017-04-03 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 5
2017-04-03 22:15 - 2017-04-03 22:24 - 00000000 ____D C:\ProgramData\PDF Architect 5
2017-04-03 22:15 - 2017-04-03 22:22 - 00000000 ____D C:\Program Files\PDFCreator
2017-04-03 22:15 - 2017-04-03 22:15 - 00115200 _____ (pdfforge GmbH) C:\WINDOWS\system32\pdfcmon.dll
2017-04-03 22:15 - 2017-04-03 22:15 - 00000884 _____ C:\Users\Public\Desktop\PDFCreator.lnk
2017-04-03 22:15 - 2017-04-03 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2017-04-03 22:12 - 2017-04-03 22:14 - 31396248 _____ C:\Users\Aneta\Downloads\PDFCreator-2_5_1-Setup.exe
2017-04-03 22:05 - 2017-04-03 22:06 - 00000167 _____ C:\Users\Aneta\Downloads\pdf%2Fkatalog (1).pdf
2017-04-03 22:05 - 2017-04-03 22:05 - 00000167 _____ C:\Users\Aneta\Downloads\pdf_download.php
2017-04-03 22:04 - 2017-04-03 22:05 - 00000167 _____ C:\Users\Aneta\Downloads\pdf%2Fkatalog.pdf
2017-04-02 11:24 - 2017-03-04 09:57 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-04-02 11:24 - 2017-03-04 09:57 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-04-02 11:24 - 2017-03-04 09:40 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2017-04-02 11:24 - 2017-03-04 09:24 - 00090976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2017-04-02 11:24 - 2017-03-04 09:09 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2017-04-02 11:24 - 2017-03-04 09:09 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2017-04-02 11:24 - 2017-03-04 09:09 - 00497416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-04-02 11:24 - 2017-03-04 09:08 - 00130912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-04-02 11:24 - 2017-03-04 09:07 - 00557400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2017-04-02 11:24 - 2017-03-04 09:02 - 00184416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL
2017-04-02 11:24 - 2017-03-04 08:56 - 00248992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2017-04-02 11:24 - 2017-03-04 08:54 - 02277288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2017-04-02 11:24 - 2017-03-04 08:54 - 00524776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 02256080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 01431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 00781152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-04-02 11:24 - 2017-03-04 08:53 - 00493912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-04-02 11:24 - 2017-03-04 08:53 - 00313568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2017-04-02 11:24 - 2017-03-04 08:53 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2017-04-02 11:24 - 2017-03-04 08:52 - 00549088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2017-04-02 11:24 - 2017-03-04 08:52 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2017-04-02 11:24 - 2017-03-04 08:51 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2017-04-02 11:24 - 2017-03-04 08:51 - 00576408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-04-02 11:24 - 2017-03-04 08:50 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 06667528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 04023000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01853224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01277856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01202384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00981376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00976184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00530480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00352760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2017-04-02 11:24 - 2017-03-04 08:47 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2017-04-02 11:24 - 2017-03-04 08:46 - 04312248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-04-02 11:24 - 2017-03-04 08:46 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2017-04-02 11:24 - 2017-03-04 08:45 - 00173408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2017-04-02 11:24 - 2017-03-04 08:42 - 01415240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-04-02 11:24 - 2017-03-04 08:42 - 01260784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-04-02 11:24 - 2017-03-04 08:42 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-04-02 11:24 - 2017-03-04 08:40 - 00306800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2017-04-02 11:24 - 2017-03-04 08:36 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-04-02 11:24 - 2017-03-04 08:30 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-04-02 11:24 - 2017-03-04 08:24 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-04-02 11:24 - 2017-03-04 08:23 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2017-04-02 11:24 - 2017-03-04 08:22 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-04-02 11:24 - 2017-03-04 08:21 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2017-04-02 11:24 - 2017-03-04 08:21 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2017-04-02 11:24 - 2017-03-04 08:21 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2017-04-02 11:24 - 2017-03-04 08:21 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-04-02 11:24 - 2017-03-04 08:20 - 13873664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-04-02 11:24 - 2017-03-04 08:20 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll
2017-04-02 11:24 - 2017-03-04 08:20 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-04-02 11:24 - 2017-03-04 08:19 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-04-02 11:24 - 2017-03-04 08:19 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-04-02 11:24 - 2017-03-04 08:19 - 00390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2017-04-02 11:24 - 2017-03-04 08:19 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2017-04-02 11:24 - 2017-03-04 08:18 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2017-04-02 11:24 - 2017-03-04 08:17 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-04-02 11:24 - 2017-03-04 08:16 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-04-02 11:24 - 2017-03-04 08:16 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2017-04-02 11:24 - 2017-03-04 08:16 - 00762880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2017-04-02 11:24 - 2017-03-04 08:16 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-04-02 11:24 - 2017-03-04 08:16 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-04-02 11:24 - 2017-03-04 08:15 - 01543680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2017-04-02 11:24 - 2017-03-04 08:15 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-04-02 11:24 - 2017-03-04 08:14 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 04613120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-04-02 11:24 - 2017-03-04 08:13 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-04-02 11:24 - 2017-03-04 08:12 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2017-04-02 11:24 - 2017-03-04 08:12 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2017-04-02 11:24 - 2017-03-04 08:12 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2017-04-02 11:24 - 2017-03-04 08:11 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2017-04-02 11:24 - 2017-03-04 08:11 - 01320448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2017-04-02 11:24 - 2017-03-04 08:11 - 01137152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2017-04-02 11:24 - 2017-03-04 08:11 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2017-04-02 11:24 - 2017-03-04 08:10 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-04-02 11:24 - 2017-03-04 08:10 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2017-04-02 11:24 - 2017-03-04 08:09 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2017-04-02 11:24 - 2017-03-04 08:09 - 00570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2017-04-02 11:24 - 2017-03-04 08:08 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-04-02 11:24 - 2017-03-04 08:07 - 02748928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-04-02 11:24 - 2017-03-04 08:07 - 02643456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-04-02 11:24 - 2017-03-04 08:07 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2017-04-02 11:24 - 2017-03-04 08:06 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-04-02 11:24 - 2017-03-04 08:06 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-04-02 11:24 - 2017-03-04 08:06 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2017-04-02 11:24 - 2017-03-04 08:06 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-04-02 11:24 - 2017-03-04 08:05 - 07468544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-04-02 11:24 - 2017-03-04 08:05 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-04-02 11:24 - 2017-03-04 08:05 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2017-04-02 11:24 - 2017-03-04 08:05 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2017-04-02 11:24 - 2017-03-04 08:04 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-04-02 11:24 - 2017-03-04 08:03 - 02363904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-04-02 11:24 - 2017-03-04 08:03 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-04-02 11:24 - 2017-03-04 08:02 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-04-02 11:24 - 2017-03-04 08:02 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-04-02 11:24 - 2017-03-04 08:02 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2017-04-02 11:24 - 2017-03-04 08:02 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-04-02 11:24 - 2017-03-04 08:02 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01571840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01564160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-04-02 11:24 - 2017-03-04 08:01 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-04-02 11:24 - 2017-03-04 08:01 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 02996736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-04-02 11:24 - 2017-03-04 08:00 - 02483200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 02003968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-04-02 11:24 - 2017-03-04 08:00 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2017-04-02 11:24 - 2017-03-04 07:59 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2017-04-02 11:24 - 2017-03-04 07:57 - 00449024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-04-02 11:23 - 2017-03-04 09:19 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2017-04-02 11:23 - 2017-03-04 09:09 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-04-02 11:23 - 2017-03-04 09:09 - 00527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2017-04-02 11:23 - 2017-03-04 09:04 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-04-02 11:23 - 2017-03-04 09:04 - 01362512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
2017-04-02 11:23 - 2017-03-04 08:56 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-04-02 11:23 - 2017-03-04 08:47 - 00640976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2017-04-02 11:23 - 2017-03-04 08:47 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2017-04-02 11:23 - 2017-03-04 08:45 - 00112120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2017-04-02 11:23 - 2017-03-04 08:42 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2017-04-02 11:23 - 2017-03-04 08:34 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-04-02 11:23 - 2017-03-04 08:30 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-04-02 11:23 - 2017-03-04 08:30 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2017-04-02 11:23 - 2017-03-04 08:30 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2017-04-02 11:23 - 2017-03-04 08:30 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-04-02 11:23 - 2017-03-04 08:29 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-04-02 11:23 - 2017-03-04 08:29 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2017-04-02 11:23 - 2017-03-04 08:29 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfp.dll
2017-04-02 11:23 - 2017-03-04 08:29 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInputUap.dll
2017-04-02 11:23 - 2017-03-04 08:29 - 00019968 _____ C:\WINDOWS\SysWOW64\GamePanelExternalHook.dll
2017-04-02 11:23 - 2017-03-04 08:28 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-04-02 11:23 - 2017-03-04 08:28 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-04-02 11:23 - 2017-03-04 08:27 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-04-02 11:23 - 2017-03-04 08:27 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2017-04-02 11:23 - 2017-03-04 08:27 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accountaccessor.dll
2017-04-02 11:23 - 2017-03-04 08:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
2017-04-02 11:23 - 2017-03-04 08:27 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2017-04-02 11:23 - 2017-03-04 08:27 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddrawex.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.UI.GameBar.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2017-04-02 11:23 - 2017-03-04 08:26 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2017-04-02 11:23 - 2017-03-04 08:25 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-04-02 11:23 - 2017-03-04 08:25 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscandui.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCCSEngineShared.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.SystemManagement.dll
2017-04-02 11:23 - 2017-03-04 08:25 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfui.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-02 11:23 - 2017-03-04 08:24 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2017-04-02 11:23 - 2017-03-04 08:23 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00506368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-04-02 11:23 - 2017-03-04 08:23 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DavSyncProvider.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2017-04-02 11:23 - 2017-03-04 08:23 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 01299968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icm32.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2017-04-02 11:23 - 2017-03-04 08:22 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2017-04-02 11:23 - 2017-03-04 08:22 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\main.cpl
2017-04-02 11:23 - 2017-03-04 08:21 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi32.dll
2017-04-02 11:23 - 2017-03-04 08:21 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00271360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2017-04-02 11:23 - 2017-03-04 08:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-04-02 11:23 - 2017-03-04 08:19 - 00714752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2017-04-02 11:23 - 2017-03-04 08:19 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-04-02 11:23 - 2017-03-04 08:19 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2017-04-02 11:23 - 2017-03-04 08:19 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2017-04-02 11:23 - 2017-03-04 08:19 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00548352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2017-04-02 11:23 - 2017-03-04 08:18 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-04-02 11:23 - 2017-03-04 08:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2017-04-02 11:23 - 2017-03-04 08:17 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00968704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2017-04-02 11:23 - 2017-03-04 08:16 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#7 Příspěvek od Sergeii »

2017-04-02 11:23 - 2017-03-04 08:16 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-04-02 11:23 - 2017-03-04 08:16 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2017-04-02 11:23 - 2017-03-04 08:15 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2017-04-02 11:23 - 2017-03-04 08:15 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-04-02 11:23 - 2017-03-04 08:14 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2017-04-02 11:23 - 2017-03-04 08:13 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-04-02 11:23 - 2017-03-04 08:13 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-04-02 11:23 - 2017-03-04 08:13 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2017-04-02 11:23 - 2017-03-04 08:13 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2017-04-02 11:23 - 2017-03-04 08:12 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2017-04-02 11:23 - 2017-03-04 08:12 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-04-02 11:23 - 2017-03-04 08:12 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2017-04-02 11:23 - 2017-03-04 08:12 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2017-04-02 11:23 - 2017-03-04 08:11 - 01357312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2017-04-02 11:23 - 2017-03-04 08:10 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-04-02 11:23 - 2017-03-04 08:10 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
2017-04-02 11:23 - 2017-03-04 08:10 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
2017-04-02 11:23 - 2017-03-04 08:09 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2017-04-02 11:23 - 2017-03-04 08:09 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2017-04-02 11:23 - 2017-03-04 08:08 - 03405312 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-04-02 11:23 - 2017-03-04 08:08 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-04-02 11:23 - 2017-03-04 08:08 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-04-02 11:23 - 2017-03-04 08:07 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-04-02 11:23 - 2017-03-04 08:07 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-04-02 11:23 - 2017-03-04 08:07 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2017-04-02 11:23 - 2017-03-04 08:06 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-04-02 11:23 - 2017-03-04 08:06 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-04-02 11:23 - 2017-03-04 08:06 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2017-04-02 11:23 - 2017-03-04 08:06 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-04-02 11:23 - 2017-03-04 08:05 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2017-04-02 11:23 - 2017-03-04 08:05 - 01133568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
2017-04-02 11:23 - 2017-03-04 08:05 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2017-04-02 11:23 - 2017-03-04 08:05 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
2017-04-02 11:23 - 2017-03-04 08:05 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
2017-04-02 11:23 - 2017-03-04 08:04 - 00753152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
2017-04-02 11:23 - 2017-03-04 08:04 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
2017-04-02 11:23 - 2017-03-04 08:03 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2017-04-02 11:23 - 2017-03-04 08:03 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSENCD.DLL
2017-04-02 11:23 - 2017-03-04 08:03 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-04-02 11:23 - 2017-03-04 08:03 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
2017-04-02 11:23 - 2017-03-04 08:02 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-04-02 11:23 - 2017-03-04 08:02 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-04-02 11:23 - 2017-03-04 08:02 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-04-02 11:23 - 2017-03-04 08:02 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2017-04-02 11:23 - 2017-03-04 08:01 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-04-02 11:23 - 2017-03-04 08:01 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2017-04-02 11:23 - 2017-03-04 08:01 - 01154560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Pimstore.dll
2017-04-02 11:23 - 2017-03-04 08:01 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-04-02 11:23 - 2017-03-04 08:01 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2017-04-02 11:23 - 2017-03-04 08:00 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2017-04-02 11:23 - 2017-03-04 08:00 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2017-04-02 11:23 - 2017-03-04 08:00 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2017-04-02 11:23 - 2017-03-04 08:00 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-04-02 11:23 - 2017-03-04 07:59 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2017-04-02 11:23 - 2017-03-04 07:57 - 03106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-04-02 11:23 - 2017-03-04 07:57 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2017-04-02 11:23 - 2017-03-04 07:57 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RADCUI.dll
2017-04-02 11:23 - 2017-03-04 07:36 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-04-02 11:22 - 2017-03-04 09:26 - 00794416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-04-02 11:22 - 2017-03-04 09:24 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2017-04-02 11:22 - 2017-03-04 09:24 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2017-04-02 11:22 - 2017-03-04 09:24 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2017-04-02 11:22 - 2017-03-04 09:23 - 02512304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2017-04-02 11:22 - 2017-03-04 09:22 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-04-02 11:22 - 2017-03-04 09:18 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-04-02 11:22 - 2017-03-04 09:18 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-04-02 11:22 - 2017-03-04 09:17 - 00409952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2017-04-02 11:22 - 2017-03-04 09:15 - 01000280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2017-04-02 11:22 - 2017-03-04 09:10 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-04-02 11:22 - 2017-03-04 09:09 - 07220696 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-04-02 11:22 - 2017-03-04 09:09 - 01860288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-04-02 11:22 - 2017-03-04 09:09 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-04-02 11:22 - 2017-03-04 09:09 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2017-04-02 11:22 - 2017-03-04 09:06 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-04-02 11:22 - 2017-03-04 09:04 - 08169536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-04-02 11:22 - 2017-03-04 09:04 - 01063472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 22223968 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 04260576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01989072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01723560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2017-04-02 11:22 - 2017-03-04 09:03 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01454512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01301112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 00596040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 00443232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-04-02 11:22 - 2017-03-04 09:03 - 00382272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2017-04-02 11:22 - 2017-03-04 09:01 - 00137936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2017-04-02 11:22 - 2017-03-04 08:57 - 02536288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-04-02 11:22 - 2017-03-04 08:57 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-04-02 11:22 - 2017-03-04 08:39 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-04-02 11:22 - 2017-03-04 08:36 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2017-04-02 11:22 - 2017-03-04 08:36 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-04-02 11:22 - 2017-03-04 08:36 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
2017-04-02 11:22 - 2017-03-04 08:36 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2017-04-02 11:22 - 2017-03-04 08:35 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-04-02 11:22 - 2017-03-04 08:35 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-04-02 11:22 - 2017-03-04 08:34 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-04-02 11:22 - 2017-03-04 08:34 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-04-02 11:22 - 2017-03-04 08:34 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-04-02 11:22 - 2017-03-04 08:34 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-04-02 11:22 - 2017-03-04 08:34 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2017-04-02 11:22 - 2017-03-04 08:33 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-04-02 11:22 - 2017-03-04 08:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-04-02 11:22 - 2017-03-04 08:33 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2017-04-02 11:22 - 2017-03-04 08:32 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2017-04-02 11:22 - 2017-03-04 08:32 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2017-04-02 11:22 - 2017-03-04 08:32 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCCSEngineShared.dll
2017-04-02 11:22 - 2017-03-04 08:32 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-02 11:22 - 2017-03-04 08:31 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-04-02 11:22 - 2017-03-04 08:31 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2017-04-02 11:22 - 2017-03-04 08:31 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2017-04-02 11:22 - 2017-03-04 08:31 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-04-02 11:22 - 2017-03-04 08:30 - 00535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-04-02 11:22 - 2017-03-04 08:30 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-04-02 11:22 - 2017-03-04 08:30 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2017-04-02 11:22 - 2017-03-04 08:30 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-04-02 11:22 - 2017-03-04 08:30 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2017-04-02 11:22 - 2017-03-04 08:30 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys
2017-04-02 11:22 - 2017-03-04 08:29 - 01291264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-04-02 11:22 - 2017-03-04 08:29 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2017-04-02 11:22 - 2017-03-04 08:29 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2017-04-02 11:22 - 2017-03-04 08:29 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi32.dll
2017-04-02 11:22 - 2017-03-04 08:29 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2017-04-02 11:22 - 2017-03-04 08:29 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-04-02 11:22 - 2017-03-04 08:28 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-04-02 11:22 - 2017-03-04 08:28 - 00741888 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2017-04-02 11:22 - 2017-03-04 08:28 - 00556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-04-02 11:22 - 2017-03-04 08:28 - 00462848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2017-04-02 11:22 - 2017-03-04 08:28 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-04-02 11:22 - 2017-03-04 08:27 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-04-02 11:22 - 2017-03-04 08:27 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DavSyncProvider.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2017-04-02 11:22 - 2017-03-04 08:26 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2017-04-02 11:22 - 2017-03-04 08:25 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShServiceObj.dll
2017-04-02 11:22 - 2017-03-04 08:24 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2017-04-02 11:22 - 2017-03-04 08:24 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 01184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 00945152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 00820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintRenderAPIHost.DLL
2017-04-02 11:22 - 2017-03-04 08:23 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2017-04-02 11:22 - 2017-03-04 08:23 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-04-02 11:22 - 2017-03-04 08:23 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-04-02 11:22 - 2017-03-04 08:22 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2017-04-02 11:22 - 2017-03-04 08:21 - 06285824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-04-02 11:22 - 2017-03-04 08:21 - 01937920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2017-04-02 11:22 - 2017-03-04 08:21 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-04-02 11:22 - 2017-03-04 08:20 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-04-02 11:22 - 2017-03-04 08:19 - 23676416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-04-02 11:22 - 2017-03-04 08:19 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-04-02 11:22 - 2017-03-04 08:19 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-04-02 11:22 - 2017-03-04 08:19 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2017-04-02 11:22 - 2017-03-04 08:19 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-04-02 11:22 - 2017-03-04 08:18 - 01762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2017-04-02 11:22 - 2017-03-04 08:18 - 01189376 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2017-04-02 11:22 - 2017-03-04 08:18 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2017-04-02 11:22 - 2017-03-04 08:17 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-04-02 11:22 - 2017-03-04 08:17 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 13441536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2017-04-02 11:22 - 2017-03-04 08:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-04-02 11:22 - 2017-03-04 08:15 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-04-02 11:22 - 2017-03-04 08:13 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-04-02 11:22 - 2017-03-04 08:13 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-04-02 11:22 - 2017-03-04 08:13 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2017-04-02 11:22 - 2017-03-04 08:13 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2017-04-02 11:22 - 2017-03-04 08:12 - 07654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-04-02 11:22 - 2017-03-04 08:12 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-04-02 11:22 - 2017-03-04 08:12 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2017-04-02 11:22 - 2017-03-04 08:11 - 03441664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-04-02 11:22 - 2017-03-04 08:11 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-04-02 11:22 - 2017-03-04 08:11 - 01891328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 01917440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2017-04-02 11:22 - 2017-03-04 08:10 - 01536000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 01399296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-04-02 11:22 - 2017-03-04 08:10 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-04-02 11:22 - 2017-03-04 08:09 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-04-02 11:22 - 2017-03-04 08:09 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-04-02 11:22 - 2017-03-04 08:09 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2017-04-02 11:22 - 2017-03-04 08:09 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 12349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 08076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 01981440 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-04-02 11:22 - 2017-03-04 08:08 - 00792576 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2017-04-02 11:22 - 2017-03-04 08:07 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2017-04-02 11:22 - 2017-03-04 08:07 - 01792512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2017-04-02 11:22 - 2017-03-04 08:07 - 01512448 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2017-04-02 11:22 - 2017-03-04 08:07 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-04-02 11:22 - 2017-03-04 08:06 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-04-02 11:22 - 2017-03-04 08:06 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-04-02 11:22 - 2017-03-04 08:06 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-04-02 11:22 - 2017-03-04 08:06 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2017-04-02 11:22 - 2017-03-04 08:06 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-04-02 11:22 - 2017-03-04 08:04 - 01826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2017-04-02 11:22 - 2017-03-04 08:04 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-04-02 11:22 - 2017-03-04 08:04 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-04-02 11:22 - 2017-03-04 08:04 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2017-04-02 11:22 - 2017-03-04 08:04 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2017-04-02 11:22 - 2017-03-04 08:01 - 01493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2017-04-02 11:22 - 2017-02-22 04:17 - 00448285 _____ C:\WINDOWS\system32\ApnDatabase.xml
2017-04-02 11:21 - 2017-03-04 09:27 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-04-02 11:21 - 2017-03-04 09:24 - 00646688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-04-02 11:21 - 2017-03-04 09:22 - 07786336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-04-02 11:21 - 2017-03-04 09:19 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-04-02 11:21 - 2017-03-04 09:18 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL
2017-04-02 11:21 - 2017-03-04 09:15 - 00063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-04-02 11:21 - 2017-03-04 09:11 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-04-02 11:21 - 2017-03-04 09:10 - 02828384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-04-02 11:21 - 2017-03-04 09:10 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-04-02 11:21 - 2017-03-04 09:09 - 02750384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-04-02 11:21 - 2017-03-04 09:09 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-04-02 11:21 - 2017-03-04 09:09 - 00681312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2017-04-02 11:21 - 2017-03-04 09:09 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-04-02 11:21 - 2017-03-04 09:09 - 00635864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-04-02 11:21 - 2017-03-04 09:09 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-04-02 11:21 - 2017-03-04 09:08 - 00450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2017-04-02 11:21 - 2017-03-04 09:08 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-04-02 11:21 - 2017-03-04 09:07 - 00432992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-04-02 11:21 - 2017-03-04 09:03 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-04-02 11:21 - 2017-03-04 09:03 - 00755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2017-04-02 11:21 - 2017-03-04 09:03 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2017-04-02 11:21 - 2017-03-04 09:03 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2017-04-02 11:21 - 2017-03-04 09:03 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-04-02 11:21 - 2017-03-04 09:03 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-04-02 11:21 - 2017-03-04 08:37 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-04-02 11:21 - 2017-03-04 08:36 - 22565376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-04-02 11:21 - 2017-03-04 08:36 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2017-04-02 11:21 - 2017-03-04 08:33 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-04-02 11:21 - 2017-03-04 08:33 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2017-04-02 11:21 - 2017-03-04 08:31 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2017-04-02 11:21 - 2017-03-04 08:31 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2017-04-02 11:21 - 2017-03-04 08:31 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\icm32.dll
2017-04-02 11:21 - 2017-03-04 08:30 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2017-04-02 11:21 - 2017-03-04 08:30 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2017-04-02 11:21 - 2017-03-04 08:30 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-04-02 11:21 - 2017-03-04 08:30 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2017-04-02 11:21 - 2017-03-04 08:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2017-04-02 11:21 - 2017-03-04 08:29 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-04-02 11:21 - 2017-03-04 08:29 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-04-02 11:21 - 2017-03-04 08:29 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-02 11:21 - 2017-03-04 08:29 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-04-02 11:21 - 2017-03-04 08:29 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
2017-04-02 11:21 - 2017-03-04 08:28 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-04-02 11:21 - 2017-03-04 08:28 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2017-04-02 11:21 - 2017-03-04 08:28 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-04-02 11:21 - 2017-03-04 08:28 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2017-04-02 11:21 - 2017-03-04 08:28 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-04-02 11:21 - 2017-03-04 08:27 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2017-04-02 11:21 - 2017-03-04 08:27 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-04-02 11:21 - 2017-03-04 08:27 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-04-02 11:21 - 2017-03-04 08:27 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2017-04-02 11:21 - 2017-03-04 08:26 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-04-02 11:21 - 2017-03-04 08:25 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-04-02 11:21 - 2017-03-04 08:25 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-04-02 11:21 - 2017-03-04 08:24 - 01025536 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-04-02 11:21 - 2017-03-04 08:24 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2017-04-02 11:21 - 2017-03-04 08:23 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2017-04-02 11:21 - 2017-03-04 08:23 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-04-02 11:21 - 2017-03-04 08:23 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2017-04-02 11:21 - 2017-03-04 08:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-04-02 11:21 - 2017-03-04 08:21 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-04-02 11:21 - 2017-03-04 08:21 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-04-02 11:21 - 2017-03-04 08:20 - 01280512 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-04-02 11:21 - 2017-03-04 08:20 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-04-02 11:21 - 2017-03-04 08:20 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-04-02 11:21 - 2017-03-04 08:19 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-04-02 11:21 - 2017-03-04 08:19 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-04-02 11:21 - 2017-03-04 08:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-04-02 11:21 - 2017-03-04 08:19 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Tabbtn.dll
2017-04-02 11:21 - 2017-03-04 08:18 - 17198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-04-02 11:21 - 2017-03-04 08:18 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2017-04-02 11:21 - 2017-03-04 08:17 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2017-04-02 11:21 - 2017-03-04 08:17 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-04-02 11:21 - 2017-03-04 08:17 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2017-04-02 11:21 - 2017-03-04 08:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2017-04-02 11:21 - 2017-03-04 08:16 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2017-04-02 11:21 - 2017-03-04 08:15 - 18362368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-04-02 11:21 - 2017-03-04 08:15 - 01837056 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-04-02 11:21 - 2017-03-04 08:14 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2017-04-02 11:21 - 2017-03-04 08:14 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 19411968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00937472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
2017-04-02 11:21 - 2017-03-04 08:13 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersGPExt.dll
2017-04-02 11:21 - 2017-03-04 08:12 - 13085184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-04-02 11:21 - 2017-03-04 08:12 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2017-04-02 11:21 - 2017-03-04 08:12 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2017-04-02 11:21 - 2017-03-04 08:11 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-04-02 11:21 - 2017-03-04 08:11 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-04-02 11:21 - 2017-03-04 08:11 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2017-04-02 11:21 - 2017-03-04 08:11 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2017-04-02 11:21 - 2017-03-04 08:11 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2017-04-02 11:21 - 2017-03-04 08:10 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-04-02 11:21 - 2017-03-04 08:10 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-04-02 11:21 - 2017-03-04 08:10 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-04-02 11:21 - 2017-03-04 08:10 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-04-02 11:21 - 2017-03-04 08:10 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2017-04-02 11:21 - 2017-03-04 08:10 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2017-04-02 11:21 - 2017-03-04 08:09 - 08125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-04-02 11:21 - 2017-03-04 08:09 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-04-02 11:21 - 2017-03-04 08:08 - 01780224 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-04-02 11:21 - 2017-03-04 08:08 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 12178944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 02895872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-04-02 11:21 - 2017-03-04 08:07 - 01348608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2017-04-02 11:21 - 2017-03-04 08:07 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-04-02 11:21 - 2017-03-04 08:06 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-04-02 11:21 - 2017-03-04 08:06 - 03202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-04-02 11:21 - 2017-03-04 08:06 - 02475008 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-04-02 11:21 - 2017-03-04 08:06 - 02287104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-04-02 11:21 - 2017-03-04 08:05 - 01328640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2017-04-02 11:21 - 2017-03-04 08:05 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-04-02 11:21 - 2017-03-04 08:05 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-04-02 11:21 - 2017-03-04 08:03 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-04-02 11:21 - 2017-03-04 08:03 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-04-02 11:21 - 2017-03-04 08:02 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2017-04-02 11:21 - 2017-03-04 08:00 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-04-02 11:20 - 2017-03-04 09:57 - 00192352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 01617760 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 01294688 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00655200 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00378720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00343904 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00315232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00242528 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-04-02 11:20 - 2017-03-04 09:35 - 00086368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-04-02 11:20 - 2017-03-04 09:35 - 00038240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-04-02 11:20 - 2017-03-04 09:25 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2017-04-02 11:20 - 2017-03-04 09:24 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-04-02 11:20 - 2017-03-04 09:24 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-04-02 11:20 - 2017-03-04 09:24 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2017-04-02 11:20 - 2017-03-04 09:22 - 01354312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-04-02 11:20 - 2017-03-04 09:22 - 01172984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-04-02 11:20 - 2017-03-04 09:21 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-04-02 11:20 - 2017-03-04 09:20 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2017-04-02 11:20 - 2017-03-04 09:20 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-04-02 11:20 - 2017-03-04 09:18 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-04-02 11:20 - 2017-03-04 09:15 - 00404320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2017-04-02 11:20 - 2017-03-04 09:13 - 00635456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-04-02 11:20 - 2017-03-04 09:11 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-04-02 11:20 - 2017-03-04 09:09 - 00578392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-04-02 11:20 - 2017-03-04 09:09 - 00178520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-04-02 11:20 - 2017-03-04 09:08 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-04-02 11:20 - 2017-03-04 09:08 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-04-02 11:20 - 2017-03-04 09:08 - 00342456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 02446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-04-02 11:20 - 2017-03-04 09:07 - 00989016 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-04-02 11:20 - 2017-03-04 09:07 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-04-02 11:20 - 2017-03-04 09:07 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-04-02 11:20 - 2017-03-04 09:07 - 00682808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2017-04-02 11:20 - 2017-03-04 09:07 - 00110944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2017-04-02 11:20 - 2017-03-04 09:07 - 00080224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2017-04-02 11:20 - 2017-03-04 09:03 - 04674360 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-04-02 11:20 - 2017-03-04 09:03 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-04-02 11:20 - 2017-03-04 09:03 - 00038768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2017-04-02 11:20 - 2017-03-04 09:01 - 00201568 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2017-04-02 11:20 - 2017-03-04 09:01 - 00128648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2017-04-02 11:20 - 2017-03-04 08:59 - 01570208 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-04-02 11:20 - 2017-03-04 08:58 - 01416224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-04-02 11:20 - 2017-03-04 08:58 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-04-02 11:20 - 2017-03-04 08:58 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2017-04-02 11:20 - 2017-03-04 08:57 - 00372432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-04-02 11:20 - 2017-03-04 08:42 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-04-02 11:20 - 2017-03-04 08:35 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddrawex.dll
2017-04-02 11:20 - 2017-03-04 08:34 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-04-02 11:20 - 2017-03-04 08:34 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2017-04-02 11:20 - 2017-03-04 08:33 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-04-02 11:20 - 2017-03-04 08:32 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2017-04-02 11:20 - 2017-03-04 08:32 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-04-02 11:20 - 2017-03-04 08:31 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-04-02 11:20 - 2017-03-04 08:30 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-04-02 11:20 - 2017-03-04 08:30 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-04-02 11:20 - 2017-03-04 08:30 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
2017-04-02 11:20 - 2017-03-04 08:30 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-04-02 11:20 - 2017-03-04 08:29 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2017-04-02 11:20 - 2017-03-04 08:28 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-04-02 11:20 - 2017-03-04 08:27 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-04-02 11:20 - 2017-03-04 08:27 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-04-02 11:20 - 2017-03-04 08:26 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
2017-04-02 11:20 - 2017-03-04 08:26 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-04-02 11:20 - 2017-03-04 08:25 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2017-04-02 11:20 - 2017-03-04 08:25 - 01016320 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2017-04-02 11:20 - 2017-03-04 08:25 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-04-02 11:20 - 2017-03-04 08:24 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-04-02 11:20 - 2017-03-04 08:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2017-04-02 11:20 - 2017-03-04 08:24 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-04-02 11:20 - 2017-03-04 08:24 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-04-02 11:20 - 2017-03-04 08:24 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2017-04-02 11:20 - 2017-03-04 08:23 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2017-04-02 11:20 - 2017-03-04 08:23 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-04-02 11:20 - 2017-03-04 08:23 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-04-02 11:20 - 2017-03-04 08:23 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-04-02 11:20 - 2017-03-04 08:23 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-04-02 11:20 - 2017-03-04 08:22 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-04-02 11:20 - 2017-03-04 08:21 - 00776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabletPC.cpl
2017-04-02 11:20 - 2017-03-04 08:20 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-04-02 11:20 - 2017-03-04 08:20 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-04-02 11:20 - 2017-03-04 08:20 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2017-04-02 11:20 - 2017-03-04 08:20 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-04-02 11:20 - 2017-03-04 08:19 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-04-02 11:20 - 2017-03-04 08:19 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-04-02 11:20 - 2017-03-04 08:17 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-04-02 11:20 - 2017-03-04 08:17 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2017-04-02 11:20 - 2017-03-04 08:16 - 03289088 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-04-02 11:20 - 2017-03-04 08:16 - 00583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2017-04-02 11:20 - 2017-03-04 08:15 - 09130496 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-04-02 11:20 - 2017-03-04 08:15 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-04-02 11:20 - 2017-03-04 08:15 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-04-02 11:20 - 2017-03-04 08:14 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-04-02 11:20 - 2017-03-04 08:14 - 01562112 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2017-04-02 11:20 - 2017-03-04 08:14 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-04-02 11:20 - 2017-03-04 08:14 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-04-02 11:20 - 2017-03-04 08:14 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2017-04-02 11:20 - 2017-03-04 08:13 - 00961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2017-04-02 11:20 - 2017-03-04 08:13 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2017-04-02 11:20 - 2017-03-04 08:13 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2017-04-02 11:20 - 2017-03-04 08:12 - 01692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-04-02 11:20 - 2017-03-04 08:12 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-04-02 11:20 - 2017-03-04 08:11 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-04-02 11:20 - 2017-03-04 08:11 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-04-02 11:20 - 2017-03-04 08:11 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-04-02 11:20 - 2017-03-04 08:11 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-04-02 11:20 - 2017-03-04 08:11 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2017-04-02 11:20 - 2017-03-04 08:11 - 00818176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-04-02 11:20 - 2017-03-04 08:10 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-04-02 11:20 - 2017-03-04 08:10 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-04-02 11:20 - 2017-03-04 08:10 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-04-02 11:20 - 2017-03-04 08:09 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-04-02 11:20 - 2017-03-04 08:08 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 02914816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-04-02 11:20 - 2017-03-04 08:07 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 04060672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 03614720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-04-02 11:20 - 2017-03-04 08:06 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-04-02 11:20 - 2017-03-04 08:06 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2017-04-02 11:20 - 2017-03-04 08:05 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-04-02 11:20 - 2017-03-04 08:04 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2017-04-02 11:20 - 2017-03-04 08:03 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-04-02 11:20 - 2017-03-04 08:01 - 03478528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2017-04-02 11:20 - 2016-07-16 04:29 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CspCellularSettings.dll
2017-04-02 11:20 - 2016-07-16 04:28 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-04-02 11:20 - 2016-07-16 04:26 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CfgSPCellular.dll
2017-04-02 11:19 - 2017-03-04 08:37 - 00025088 _____ C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-04-02 11:19 - 2017-03-04 08:36 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2017-04-02 11:19 - 2017-03-04 08:36 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-04-02 11:19 - 2017-03-04 08:36 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-04-02 11:19 - 2017-03-04 08:35 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-04-02 11:19 - 2017-03-04 08:34 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfui.dll
2017-04-02 11:19 - 2017-03-04 08:33 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2017-04-02 11:19 - 2017-03-04 08:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2017-04-02 11:19 - 2017-03-04 08:33 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
2017-04-02 11:19 - 2017-03-04 08:33 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInputUap.dll
2017-04-02 11:19 - 2017-03-04 08:32 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-04-02 11:19 - 2017-03-04 08:32 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-04-02 11:19 - 2017-03-04 08:32 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-04-02 11:19 - 2017-03-04 08:31 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-04-02 11:19 - 2017-03-04 08:30 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscandui.dll
2017-04-02 11:19 - 2017-03-04 08:30 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-04-02 11:19 - 2017-03-04 08:30 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-04-02 11:19 - 2017-03-04 08:29 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-02 11:19 - 2017-03-04 08:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2017-04-02 11:19 - 2017-03-04 08:28 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-04-02 11:19 - 2017-03-04 08:28 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-04-02 11:19 - 2017-03-04 08:27 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-04-02 11:19 - 2017-03-04 08:27 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-04-02 11:19 - 2017-03-04 08:27 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-04-02 11:19 - 2017-03-04 08:27 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-04-02 11:19 - 2017-03-04 08:26 - 00643072 _____ (Microsoft Corporation) C:\WINDOWS\system32\main.cpl
2017-04-02 11:19 - 2017-03-04 08:26 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-04-02 11:19 - 2017-03-04 08:26 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
2017-04-02 11:19 - 2017-03-04 08:26 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-04-02 11:19 - 2017-03-04 08:26 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-04-02 11:19 - 2017-03-04 08:26 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-04-02 11:19 - 2017-03-04 08:24 - 01092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2017-04-02 11:19 - 2017-03-04 08:24 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2017-04-02 11:19 - 2017-03-04 08:22 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-04-02 11:19 - 2017-03-04 08:21 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-04-02 11:19 - 2017-03-04 08:20 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-04-02 11:19 - 2017-03-04 08:19 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabcal.exe
2017-04-02 11:19 - 2017-03-04 08:18 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2017-04-02 11:19 - 2017-03-04 08:18 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2017-04-02 11:19 - 2017-03-04 08:16 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-04-02 11:19 - 2017-03-04 08:14 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2017-04-02 11:19 - 2017-03-04 08:13 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-04-02 11:19 - 2017-03-04 08:13 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MultiDigiMon.exe
2017-04-02 11:19 - 2017-03-04 08:10 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-04-02 11:19 - 2017-03-04 08:10 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-04-02 11:19 - 2017-03-04 08:08 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2017-04-02 11:19 - 2017-03-04 08:05 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2017-04-02 11:18 - 2016-05-29 20:38 - 08886976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSetup.exe
2017-03-29 19:07 - 2017-03-29 19:48 - 1311777038 _____ C:\Users\Aneta\Downloads\Gold.2016.DVDr.CZ.titulky.avi
2017-03-29 18:35 - 2017-03-29 19:03 - 921267886 _____ C:\Users\Aneta\Downloads\Hacksaw Ridge-Zrození hrdiny 2016 CZ-titulky.avi
2017-03-21 13:33 - 2017-03-21 13:33 - 00096215 _____ C:\Users\Aneta\Desktop\CV Michal Zíma.pdf
2017-03-21 13:31 - 2017-03-21 13:34 - 00327951 _____ C:\Users\Aneta\Desktop\životopis Michal Zíma.odt
2017-03-21 13:31 - 2017-03-21 13:31 - 00096211 _____ C:\Users\Aneta\Desktop\životopis Michal Zíma.pdf
2017-03-21 12:59 - 2017-03-21 12:59 - 00112489 _____ C:\Users\Aneta\Downloads\Zivotopis - Zíma Michal.pdf

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-15 19:41 - 2016-05-31 17:09 - 00000000 ____D C:\Users\Aneta\Documents\Youcam
2017-04-15 19:40 - 2016-09-22 04:25 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-04-15 17:18 - 2014-12-29 17:24 - 00000000 __RDO C:\Users\Aneta\OneDrive
2017-04-15 17:17 - 2016-05-20 18:13 - 00000000 __SHD C:\Users\Aneta\IntelGraphicsProfiles
2017-04-15 17:16 - 2016-09-22 05:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-04-15 17:15 - 2016-07-16 08:04 - 01048576 _____ C:\WINDOWS\system32\config\BBI
2017-04-15 17:10 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-04-14 14:53 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-04-14 14:34 - 2016-09-22 04:33 - 01978932 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-14 14:34 - 2016-07-17 00:25 - 00687682 _____ C:\WINDOWS\system32\perfh005.dat
2017-04-14 14:34 - 2016-07-17 00:25 - 00168472 _____ C:\WINDOWS\system32\perfc005.dat
2017-04-14 14:25 - 2016-09-22 04:34 - 00000000 ____D C:\Users\Aneta
2017-04-13 15:40 - 2017-02-12 13:52 - 00004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-04-12 00:45 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-04-11 23:49 - 2017-02-12 15:06 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-11 23:49 - 2017-02-12 15:06 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-11 02:02 - 2014-12-30 11:35 - 00000000 ____D C:\KMPlayer
2017-04-11 00:42 - 2016-01-17 16:52 - 00000000 ____D C:\ProgramData\Package Cache
2017-04-09 23:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2017-04-09 22:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-04-09 21:45 - 2016-12-08 02:32 - 00003270 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-04-09 21:45 - 2016-05-20 18:35 - 00002430 _____ C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-04-06 23:18 - 2016-10-04 05:17 - 00001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-04-04 23:45 - 2017-02-12 15:06 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-04 23:45 - 2017-02-12 15:06 - 00002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-04 23:23 - 2016-02-13 15:12 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-04-04 23:18 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-04-04 23:15 - 2016-09-22 04:25 - 00257592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-04-04 23:09 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-04-04 23:09 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\setup
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-04-04 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-04-03 23:06 - 2015-01-03 17:20 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-04-03 23:01 - 2015-01-03 17:20 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-04-02 13:37 - 2015-03-18 15:04 - 00548928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2017-03-26 09:54 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-21 13:37 - 2015-03-18 15:04 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2017-03-21 03:20 - 2016-12-29 19:45 - 00000817 _____ C:\Users\Aneta\Desktop\World of Tanks.lnk

==================== Files in the root of some directories =======

2015-06-09 22:10 - 2015-06-09 22:10 - 0003584 _____ () C:\Users\Aneta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
2016-11-28 21:36 - 2016-11-28 21:36 - 5523968 _____ () C:\Users\Aneta\AppData\Local\Temp\3427980.exe
2016-11-28 21:59 - 2016-11-28 21:59 - 37794928 _____ (PandoraTV) C:\Users\Aneta\AppData\Local\Temp\KMP_4.1.4.7.exe
2017-04-04 23:30 - 2017-04-13 16:14 - 0534528 _____ () C:\Users\Aneta\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Aneta\Desktop" je 624 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x1
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
C:\WINDOWS\system32\ApnDatabase.xml
C:\Users\Aneta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Aneta\AppData\Local\Temp
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> DefaultScope {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL =
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#9 Příspěvek od Sergeii »

zatim me to stale po zadani url do chromu presmerovava na cizi adresy, log:
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Aneta (15-04-2017 21:11:08) Run:2
Running from C:\Users\Aneta\Desktop
Loaded Profiles: Aneta (Available Profiles: Aneta)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
C:\WINDOWS\system32\ApnDatabase.xml
C:\Users\Aneta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Aneta\AppData\Local\Temp
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> DefaultScope {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL =
SearchScopes: HKU\S-1-5-21-2808533366-2824297521-463841363-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

EmptyTemp:
End
*****************

"C:\WINDOWS\system32\ApnDatabase.xml" => not found.
"C:\Users\Aneta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" => not found.
"C:\Users\Aneta\AppData\Local\Temp" => not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-21-2808533366-2824297521-463841363-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => key not found.

=========== EmptyTemp: ==========

BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5403422 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 8646827 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 818 B
NetworkService => 0 B
Aneta => 106384 B

RecycleBin => 3557 B
EmptyTemp: => 13.5 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:11:14 ====
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#10 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#11 Příspěvek od Sergeii »

bohužel jen malá, ještě tak při každém druhém pokusu zadat url do chromu proběhne presmerování
například: http://imgur.com/Oz0twJy
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#12 Příspěvek od Rudy »

Udělejte ještě tyto skeny:

1. Stahnete Zoek.exe http://download.bleepingcomputer.com/smeenk/zoek.exe a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;





Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#13 Příspěvek od Sergeii »

Zoek:

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by Aneta on ne 16. 04. 2017 at 12:45:38,86.
Microsoft Windows 10 Home 10.0.14393 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Aneta\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16. 4. 2017 12:49:54 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Apowersoft deleted successfully
C:\Program Files\McAfee deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\Lavasoft deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\Users\Aneta\AppData\Local\ActiveSync deleted successfully
C:\Users\Aneta\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Aneta\AppData\Local\EmieSiteList deleted successfully
C:\Users\Aneta\AppData\Local\EmieUserList deleted successfully
C:\Users\Aneta\AppData\Local\NetworkTiles deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Apowersoft not found
C:\Users\Aneta\.android deleted
C:\PROGRA~2\Lavasoft\Web Companion deleted
C:\PROGRA~3\{3A83B8C4-5F70-453E-A723-B5672F107885} deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Aneta\AppData\Local\Lavasoft\WebCompanion.exe_Url_siq0lwf3tzgxp2khfkllybk3idtbehng deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Lavasoft\WebCompanion.exe_Url_siq0lwf3tzgxp2khfkllybk3idtbehng deleted
C:\WINDOWS\Syswow64\InstallUtil.InstallLog deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04. 10. 2016 00:07]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [04. 10. 2016 00:07]

==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Default\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]

Chrome Media Router - Aneta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://www.google.com/"
"First Home Page"="http://www.bing.com?pc=HPNTDFJS"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"First Home Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Aneta\AppData\Local\AliExpress\User Data\Default\Preferences was reset successfully
C:\Users\Aneta\AppData\Local\AliExpress\User Data\Default\Secure Preferences was reset successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Aneta\AppData\Local\AliExpress\User Data\Default\Web Data was reset successfully
C:\Users\Aneta\AppData\Local\AliExpress\User Data\Default\Web Data-journal was reset successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Web Data copy was reset successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\Aneta\Desktop\KMPlayer.lnk - C:\KMPlayer\KMPlayer.exe
C:\Users\Aneta\Desktop\SUPERAntiSpyware Free Edition.lnk - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Aneta\Desktop\World of Tanks.lnk - C:\Games\World_of_Tanks\WoTLauncher.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Avast Free Antivirus.lnk - C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\Public\Desktop\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\HP Connected Music.lnk - C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Public\Desktop\LibreOffice 4.4.lnk - C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
C:\Users\Public\Desktop\PDF Architect 5.lnk - C:\Program Files\PDF Architect 5\architect.exe
C:\Users\Public\Desktop\PDFCreator.lnk - C:\Program Files\PDFCreator\PDFCreator.exe
C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk - C:\Users\Aneta\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Alternate Start.lnk - C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE
C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Free Edition.lnk - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Registration-Activation.lnk - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe /register

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Fotografie na iCloudu.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\ShellStreamsShortcut.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Hledat iPhone.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe find
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\iCloud.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Kalendář.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Keynote.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe keynote
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Kontakty.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe contacts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Numbers.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe numbers
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Pages.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe pages
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Poznámky.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Pošta.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Připomínky.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Co jsou iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.Resources\cs.lproj\About iTunes.rtf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 5\PDF Architect 5.lnk - C:\Program Files\PDF Architect 5\architect.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 5\Uninstall or Modify PDF Architect 5.lnk - C:\ProgramData\PDF Architect 5\Installation\PDFArchitect5Installer.exe /uninstall
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 5\Uninstall PDF Architect 5.lnk - C:\ProgramData\PDF Architect 5\Installation\PDFArchitect5Installer.exe /uninstall
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Aplikace PDFCreator na internetu.lnk - C:\Program Files\PDFCreator\PDFCreator.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\PDFCreator Nápověda.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\PDFCreator.lnk - C:\Program Files\PDFCreator\PDFCreator.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Sponzoruj PDFCreator.lnk - C:\Program Files\PDFCreator\Sponzoruj PDFCreator.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\AFPL License.lnk - C:\Program Files\PDFCreator\AFPL License.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\FairPlay License.lnk - C:\Program Files\PDFCreator\FairPlay License.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator\Licenses\GPL License.lnk - C:\Program Files\PDFCreator\GNU License.txt

==== shortcuts in Quick Launch ======================

C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e94d381f9de17bf\AliExpress.lnk - C:\Program Files (x86)\AliExpress\AliExpress.exe --user-data-dir="C:\Users\Aneta\AppData\Local\AliExpress\User Data" --profile-directory=Default --app-id=cmegngdghknoiclpbcjlajfkphoelcia
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CyberLink YouCam 5.lnk - C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HP Utility Center.lnk - C:\Program Files\Hewlett-Packard\HP Utility Center\HPPU.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\KMPlayer.exe.lnk - C:\KMPlayer\KMPlayer.exe
C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

==== shortcuts After Repair ======================

C:\Users\Aneta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e94d381f9de17bf\AliExpress.lnk - C:\Program Files (x86)\AliExpress\AliExpress.exe

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{b323ceb3-5846-4aab-b26f-dd008f581b02} deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Aneta\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Aneta\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Aneta\AppData\Local\AliExpress\User Data\Default\Cache emptied successfully
C:\Users\Aneta\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=100 folders=48 31487959 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Aneta\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on ne 16. 04. 2017 at 13:17:19,30 ======================
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Sergeii
3. Stupeň Varování
Příspěvky: 135
Registrován: 03 bře 2007 15:49
Kontaktovat uživatele:

Re: malware v prohlížeči

#14 Příspěvek od Sergeii »

JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Home x64
Ran by Aneta (Administrator) on ne 16. 04. 2017 at 13:20:38,30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 4

Failed to delete: C:\ProgramData\pdfforge (Folder)
Successfully deleted: C:\Users\Aneta\AppData\Local\aliexpress (Folder)
Successfully deleted: C:\Users\Aneta\AppData\Roaming\aliexpress_helper (Folder)
Successfully deleted: C:\Users\Aneta\Downloads\fix-my-pc-setup.exe (File)



Registry: 4

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{765B91BB-63FC-4B65-831A-B229EA3C8E56} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{84F23192-A475-4038-B5C0-8584777F2DF4} (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 16. 04. 2017 at 13:28:24,82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Asus X99 Deluxe | Intel i7 5960X | Nvidia Gtx1080Ti | 64gb Crucial | http://89vision.cz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: malware v prohlížeči

#15 Příspěvek od Rudy »

Změnilo se něco nyní?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět