Logfile of random's system information tool 1.16 (written by random/random)
Run by Jarda at 2017-06-06 16:26:28
Microsoft Windows 8
System drive C: has 526 GB (75%) free of 699 GB
Total RAM: 3911 MB (57% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:26:38, on 6.6.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17568)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files\trend micro\Jarda_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://acer13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GCDTRAY.EXE] C:\Program Files\gBurner Virtual Drive\GCDTRAY.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-21-2214875189-3760211905-2910999632-1008\..\RunOnce: [RegAutoPlay] C:\Program Files (x86)\Acer\clear.fi Media\RegAutoplay.exe /r (User 'UpdatusUser')
O8 - Extra context menu item: Stiahnuť s IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stiahnuť s IDM všetky prepojenia - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SMService - IObit - C:\Program Files (x86)\IObit\Classic Start\SMService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9263 bytes
====== Enumerating Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\dwm.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe "C:\Program Files\iDMult\iDMult.dll",DdaoyLuPcx
C:\Windows\system32\rundll32.exe "C:\Program Files\BDDFools 8 v1.02 2009\BDDFools 8 v1.02 2009.dll",yMqnwwnYC
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
C:\Windows\system32\dashost.exe
C:\Windows\system32\taskhostex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}" --enable-wmi-window --enable-setforeground-window --enable-kbhook-window
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
C:\Windows\RfBtnSvc64.exe
"C:\Program Files (x86)\IObit\Classic Start\SMService.exe"
"C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe" Service
"C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe"
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe" /HotCorners
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
"C:\Windows\System32\Taskmgr.exe" /3
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files\Windows Defender\MsMpEng.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
C:\Program Files\CCleaner\CCleaner64.exe
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\system32\msiexec.exe /V
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4236.0.408320939\659731986" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 4236 "\\.\pipe\gecko-crash-server-pipe.4236" gpu
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4236.2.802068542\1062484322" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 4236 "\\.\pipe\gecko-crash-server-pipe.4236" tab
"C:\Program Files (x86)\Internet Download Manager\IDMan.exe" -Embedding
"C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe"
"C:\Users\Jarda\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
====== Scheduled tasks folder ======
C:\Windows\system32\tasks\ALU - C:\Program Files (x86)\Acer\Live Updater\updater.exe -auto
C:\Windows\system32\tasks\ALUAgent - C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe
C:\Windows\system32\tasks\ALU_SelfUpgrade - C:\ProgramData\Acer\updater2\Download\52972008\D\UpgradeDownload.exe
C:\Windows\system32\tasks\BDDFools 8 v1-02 2009 - C:\Windows\system32\rundll32.exe "C:\Program Files\BDDFools 8 v1.02 2009\BDDFools 8 v1.02 2009.dll",yMqnwwnYC
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\DeviceDetector - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Windows\system32\tasks\DigiTert - C:\Windows\system32\rundll32.exe "C:\Program Files\DigiTert\DigiTert.dll",qcQsKF
C:\Windows\system32\tasks\iDMult - C:\Windows\system32\rundll32.exe "C:\Program Files\iDMult\iDMult.dll",DdaoyLuPcx
C:\Windows\system32\tasks\Power Management - "C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\Windows\system32\tasks\Synaptics TouchPad Enhancements - \Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-2214875189-3760211905-2910999632-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScheduleJob
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\Setup\EOSNotify - %windir%\system32\EOSNotify.exe
C:\Windows\system32\tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification - C:\Windows\system32\NotificationUI.exe /Applicability
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\kc9o04ej.default
prefs.js - "browser.startup.homepage" - "
https://www.google.com/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\kc9o04ej.default\addons.json
C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\kc9o04ej.default\extensions.json
Application Update Service Helper - extension -
aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\
aushelper@mozilla.org.xpi
Multi-process staged rollout - extension -
e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\
e10srollout@mozilla.org.xpi
Pocket - extension -
firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\
firefox@getpocket.com.xpi
Web Compat - extension -
webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\
webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
IDM Integration Module - webextension -
mozilla_cc3@internetdownloadmanager.com - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\kc9o04ej.default\pluginreg.dat
=========Google Chrome=========
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek]
"Path"=C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={42F02A82-1141-4AF7-8599-D7C2407F4066}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{42F02A82-1141-4AF7-8599-D7C2407F4066}]
"URL"=
http://www.bing.com/search?q={searchTer ... &pc=MAARJS
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={42F02A82-1141-4AF7-8599-D7C2407F4066}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{42F02A82-1141-4AF7-8599-D7C2407F4066}]
"URL"=
http://www.bing.com/search?q={searchTer ... &pc=MAARJS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-10 517176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-01-28 66688]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-10 447544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2012-06-28 650648]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-05-22 2890056]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-10-23 171040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-10-23 399392]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-10-23 441888]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"JAROSLAV"=C:\Windows\Temp\gE06.tmp.exe [2017-06-06 307200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-02-12 8641240]
"GCDTRAY.EXE"=C:\Program Files\gBurner Virtual Drive\GCDTRAY.EXE [2017-01-10 834696]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-04-26 3019552]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"= []
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-08-23 56128]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5F51FFFE-7463-4220-B711-E5B9ACB8EDFE}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\str]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1
"DisableCAD"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"midi4"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-06-06 16:26:29 ----D---- C:\Program Files\trend micro
2017-06-06 16:26:28 ----D---- C:\rsit
2017-06-06 12:08:43 ----HD---- C:\Windows\msdownld.tmp
2017-06-06 12:08:40 ----D---- C:\Windows\SYSWOW64\directx
2017-06-05 23:43:40 ----SHD---- C:\ProgramData\SecuROM
2017-06-05 21:59:12 ----A---- C:\Windows\system32\drivers\vcdrom.sys
2017-06-05 21:56:02 ----D---- C:\Users\Jarda\AppData\Roaming\NVIDIA
2017-06-02 20:42:28 ----D---- C:\steamapps
2017-06-02 20:42:23 ----D---- C:\ProgramData\Steam
2017-06-02 20:06:44 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2017-06-02 20:06:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2017-06-02 20:06:44 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2017-06-02 20:06:35 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2017-06-02 20:06:35 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2017-06-02 20:06:34 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2017-06-02 20:06:34 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2017-06-02 20:01:23 ----D---- C:\ProgramData\Package Cache
2017-06-01 13:17:48 ----D---- C:\ProgramData\Logs
2017-05-28 11:31:58 ----D---- C:\Users\Jarda\AppData\Roaming\Bloom! 2
2017-05-28 11:31:43 ----D---- C:\ProgramData\Licenses
2017-05-27 01:12:12 ----D---- C:\Program Files\Hasleo
2017-05-26 18:55:55 ----D---- C:\Program Files (x86)\Steam
2017-05-25 03:43:54 ----A---- C:\Windows\system32\drivers\cryptfd.sys
2017-05-20 14:33:47 ----D---- C:\Users\Jarda\AppData\Roaming\Ahead
2017-05-20 14:33:27 ----D---- C:\ProgramData\Ahead
2017-05-20 14:26:52 ----D---- C:\Program Files (x86)\MyCam
2017-05-20 14:25:52 ----D---- C:\Users\Jarda\AppData\Roaming\Macromedia
2017-05-20 14:23:15 ----D---- C:\Program Files (x86)\KMPlayer
2017-05-20 14:22:57 ----D---- C:\Program Files (x86)\FormatFactory
2017-05-20 13:27:48 ----A---- C:\Windows\system32\FNTCACHE.DAT
2017-05-20 13:25:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-05-20 13:13:33 ----SD---- C:\Windows\system32\CompatTel
2017-05-20 13:13:33 ----D---- C:\Windows\system32\appraiser
2017-05-20 13:13:33 ----D---- C:\Windows\Migration
2017-05-20 11:15:53 ----A---- C:\Windows\SYSWOW64\vsstrace.dll
2017-05-20 11:15:53 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2017-05-20 11:15:53 ----A---- C:\Windows\system32\VSSVC.exe
2017-05-20 11:15:53 ----A---- C:\Windows\system32\vsstrace.dll
2017-05-20 11:15:53 ----A---- C:\Windows\system32\vssapi.dll
2017-05-20 10:33:39 ----D---- C:\Windows\system32\MRT
2017-05-20 08:53:51 ----A---- C:\Windows\system32\YamahaAE2.dll
2017-05-20 08:53:51 ----A---- C:\Windows\system32\YamahaAE.dll
2017-05-20 08:53:50 ----A---- C:\Windows\system32\XAudio2_7.dll
2017-05-20 08:53:50 ----A---- C:\Windows\system32\XAudio2_6.dll
2017-05-20 08:53:50 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2017-05-20 08:53:50 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2017-05-20 08:53:50 ----A---- C:\Windows\system32\xactengine3_7.dll
2017-05-20 08:53:49 ----A---- C:\Windows\system32\xactengine3_6.dll
2017-05-20 08:53:49 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2017-05-20 08:53:49 ----A---- C:\Windows\system32\wpcap.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\WdfCoInstaller01011.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\wdfcoinstaller01005.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\WavesGUILib64.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vcruntime140.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vcomp140.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vcomp110.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vccorlib140.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vccorlib120.dll
2017-05-20 08:53:48 ----A---- C:\Windows\system32\vccorlib110.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\vcamp140.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\ucrtbase.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\tossaeapo64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\toseaeapo64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\tosasfapo64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\SynTPCo19.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\SRRPTR64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\SRCOM64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\SRCOM.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\SRAPO64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\sltech64.dll
2017-05-20 08:53:47 ----A---- C:\Windows\system32\slprp64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\slcnt64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\sl3apo64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\SEHDRA64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\SECOMN64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\SEAPO64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-05-20 08:53:46 ----A---- C:\Windows\system32\pdfmona64.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\pdf995mon64ui.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\pdf995mon64.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\Packet.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\NVUNINST.EXE
2017-05-20 08:53:45 ----A---- C:\Windows\system32\nvdispgenco6432702.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\nvdispco6432702.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2017-05-20 08:53:45 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\msvcr120.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\msvcr110.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\msvcp140.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\msvcp120.dll
2017-05-20 08:53:44 ----A---- C:\Windows\system32\msvcp110.dll
2017-05-20 08:53:35 ----AC---- C:\Windows\system32\MRT.exe
2017-05-20 08:53:35 ----A---- C:\Windows\system32\MISS_APO.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfcm140u.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfcm140.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140u.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140rus.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140kor.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140jpn.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140ita.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140cht.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140chs.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140fra.dll
2017-05-20 08:53:35 ----A---- C:\Windows\system32\mfc140esn.dll
2017-05-20 08:53:34 ----A---- C:\Windows\system32\mfc140enu.dll
2017-05-20 08:53:34 ----A---- C:\Windows\system32\mfc140deu.dll
2017-05-20 08:53:34 ----A---- C:\Windows\system32\mfc140.dll
2017-05-20 08:53:34 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-05-20 08:53:34 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2017-05-20 08:53:33 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2017-05-20 08:53:32 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2017-05-20 08:53:32 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2017-05-20 08:53:32 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2017-05-20 08:53:32 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2017-05-20 08:53:31 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2017-05-20 08:53:31 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2017-05-20 08:53:31 ----A---- C:\Windows\system32\fsp_lmwl.dll
2017-05-20 08:53:30 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2017-05-20 08:53:30 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPP64AF3.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPP64A.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPO64AF3.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPO64A.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPD64AF3.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPD64A.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPA64F3.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\DDPA64.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\d3dx11_43.dll
2017-05-20 08:53:29 ----A---- C:\Windows\system32\d3dx10_43.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\D3DX9_43.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\d3dcsx_43.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CX64APO.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\concrt140.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CNMLMAA.DLL
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CNMIUAA.DLL
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CNHMCA6.dll
2017-05-20 08:53:28 ----A---- C:\Windows\system32\CNC280O.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\CNC280L.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\CNC280I.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\CNC280C.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\AutoUpdate.exe
2017-05-20 08:53:27 ----A---- C:\Windows\system32\audioLibVc.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-05-20 08:53:27 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-05-20 08:53:26 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2017-05-20 08:49:08 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2017-05-20 08:49:08 ----A---- C:\Windows\system32\drivers\portcls.sys
2017-05-20 08:49:08 ----A---- C:\Windows\system32\drivers\drmk.sys
2017-05-20 08:49:06 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2017-05-20 08:49:06 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2017-05-20 08:49:06 ----A---- C:\Windows\system32\drivers\UCX01000.SYS
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbprint.sys
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbport.sys
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbhub.sys
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbehci.sys
2017-05-20 08:49:05 ----A---- C:\Windows\system32\drivers\usbd.sys
2017-05-20 08:49:04 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2017-05-20 08:49:04 ----A---- C:\Windows\system32\drivers\usbcir.sys
2017-05-20 08:49:04 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2017-05-20 08:49:03 ----A---- C:\Windows\system32\drivers\tpm.sys
2017-05-20 08:49:03 ----A---- C:\Windows\system32\drivers\rfcomm.sys
2017-05-20 08:48:52 ----A---- C:\Windows\system32\drivers\spaceport.sys
2017-05-20 08:48:49 ----A---- C:\Windows\system32\drivers\sdbus.sys
2017-05-20 08:48:49 ----A---- C:\Windows\system32\drivers\dumpsd.sys
2017-05-20 08:47:46 ----A---- C:\Windows\system32\drivers\storahci.sys
2017-05-20 08:47:46 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2017-05-20 08:47:46 ----A---- C:\Windows\system32\drivers\mouhid.sys
2017-05-20 08:47:19 ----A---- C:\Windows\system32\drivers\monitor.sys
2017-05-20 08:47:16 ----A---- C:\Windows\system32\drivers\hidusb.sys
2017-05-20 08:47:16 ----A---- C:\Windows\system32\drivers\hidparse.sys
2017-05-20 08:47:15 ----A---- C:\Windows\system32\drivers\hidclass.sys
2017-05-20 08:47:14 ----A---- C:\Windows\system32\drivers\hidbth.sys
2017-05-20 08:46:55 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2017-05-20 08:46:54 ----A---- C:\Windows\system32\drivers\BthAvrcpTg.sys
2017-05-20 08:46:53 ----A---- C:\Windows\system32\fsquirt.exe
2017-05-20 08:46:53 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2017-05-20 08:46:53 ----A---- C:\Windows\system32\drivers\bthport.sys
2017-05-20 08:46:53 ----A---- C:\Windows\system32\drivers\bthenum.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\whfltr2k.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\vmx86.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\vmci.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\usbscan.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\usb8023x.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\usb80236.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\TeeDriverx64.sys
2017-05-20 08:43:27 ----A---- C:\Windows\system32\drivers\TeeDriverW8x64.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\rndismpx.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\rndismp6.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\nxusbs.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\nxusbh.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\nxusbf.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\nxaudio.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\nuidfltr.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\npf.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\NBVolUp.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\NBVol.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\lmpc4.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\ICCWDT.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\hcmon.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\acedrv11.sys
2017-05-20 08:43:26 ----A---- C:\Windows\system32\drivers\48230029.sys
2017-05-20 07:27:03 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2017-05-20 07:27:03 ----A---- C:\Windows\system32\TsWpfWrp.exe
2017-05-20 07:24:12 ----A---- C:\Windows\system32\sppsvc.exe
2017-05-20 07:24:11 ----A---- C:\Windows\system32\sppwinob.dll
2017-05-20 07:24:11 ----A---- C:\Windows\system32\sppobjs.dll
2017-05-19 20:54:39 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-05-19 20:52:09 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2017-05-19 20:52:09 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-19 20:52:09 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-05-19 20:52:09 ----A---- C:\Windows\system32\WSShared.dll
2017-05-19 20:52:09 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-19 20:52:09 ----A---- C:\Windows\system32\NotificationUI.exe
2017-05-19 20:52:06 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2017-05-19 20:52:06 ----A---- C:\Windows\system32\apphelp.dll
2017-05-19 20:52:06 ----A---- C:\Windows\system32\aelupsvc.dll
2017-05-19 20:52:04 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2017-05-19 20:52:04 ----A---- C:\Windows\system32\sdbinst.exe
2017-05-19 20:51:59 ----A---- C:\Windows\system32\drivers\WdFilter.sys
2017-05-19 20:51:59 ----A---- C:\Windows\system32\drivers\WdBoot.sys
2017-05-19 20:51:48 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2017-05-19 20:51:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2017-05-19 20:51:48 ----A---- C:\Windows\system32\msxml6.dll
2017-05-19 20:51:48 ----A---- C:\Windows\system32\msxml3.dll
2017-05-19 20:51:46 ----A---- C:\Windows\system32\cryptcatsvc.dll
2017-05-19 20:51:23 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2017-05-19 20:51:23 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2017-05-19 20:51:23 ----A---- C:\Windows\system32\wpdshext.dll
2017-05-19 20:51:22 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2017-05-19 20:51:22 ----A---- C:\Windows\system32\msdrm.dll
2017-05-19 20:51:20 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2017-05-19 20:51:20 ----A---- C:\Windows\system32\d3d11.dll
2017-05-19 20:51:19 ----A---- C:\Windows\SYSWOW64\esent.dll
2017-05-19 20:51:19 ----A---- C:\Windows\system32\esent.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\invagent.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\generaltel.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\devinv.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-05-19 20:51:13 ----A---- C:\Windows\system32\centel.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\appraiser.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\aepic.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\aeinv.dll
2017-05-19 20:51:13 ----A---- C:\Windows\system32\acmigration.dll
2017-05-19 20:51:12 ----A---- C:\Windows\system32\pcasvc.dll
2017-05-19 20:51:06 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2017-05-19 20:51:06 ----A---- C:\Windows\system32\cryptdlg.dll
2017-05-19 20:50:58 ----A---- C:\Windows\SYSWOW64\msi.dll
2017-05-19 20:50:58 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2017-05-19 20:50:58 ----A---- C:\Windows\system32\msi.dll
2017-05-19 20:50:58 ----A---- C:\Windows\system32\actxprxy.dll
2017-05-19 20:50:56 ----A---- C:\Windows\system32\drivers\pdc.sys
2017-05-19 20:50:55 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2017-05-19 20:50:55 ----A---- C:\Windows\system32\msihnd.dll
2017-05-19 20:50:55 ----A---- C:\Windows\system32\consent.exe
2017-05-19 20:50:55 ----A---- C:\Windows\system32\appinfo.dll
2017-05-19 20:50:47 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2017-05-19 20:50:47 ----A---- C:\Windows\system32\VmHostAI.dll
2017-05-19 20:50:47 ----A---- C:\Windows\system32\tssdisai.dll
2017-05-19 20:50:47 ----A---- C:\Windows\system32\RDWebAI.dll
2017-05-19 20:50:47 ----A---- C:\Windows\system32\poqexec.exe
2017-05-19 20:50:47 ----A---- C:\Windows\system32\appserverai.dll
2017-05-19 20:50:27 ----A---- C:\Windows\system32\profsvc.dll
2017-05-19 20:50:23 ----A---- C:\Windows\SYSWOW64\PhotoMetadataHandler.dll
2017-05-19 20:50:23 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2017-05-19 20:50:19 ----A---- C:\Windows\system32\msieftp.dll
2017-05-19 20:50:18 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2017-05-19 20:50:15 ----A---- C:\Windows\system32\crypt32.dll
2017-05-19 20:50:14 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2017-05-19 20:43:31 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2017-05-19 20:43:31 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2017-05-19 20:42:59 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-05-19 20:42:59 ----A---- C:\Windows\system32\DWrite.dll
2017-05-19 20:42:47 ----A---- C:\Windows\system32\win32spl.dll
2017-05-19 20:42:47 ----A---- C:\Windows\system32\localspl.dll
2017-05-19 20:42:45 ----A---- C:\Windows\system32\wuaext.dll
2017-05-19 20:42:20 ----A---- C:\Windows\system32\wuaueng.dll
2017-05-19 20:42:19 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2017-05-19 20:42:19 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2017-05-19 20:42:19 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wuwebv.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wudriver.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wucltux.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wuauclt.exe
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wuapp.exe
2017-05-19 20:42:19 ----A---- C:\Windows\system32\wuapi.dll
2017-05-19 20:42:19 ----A---- C:\Windows\system32\storewuauth.dll
2017-05-19 20:42:18 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2017-05-19 20:42:04 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2017-05-19 20:42:04 ----A---- C:\Windows\system32\scesrv.dll
2017-05-19 20:41:48 ----A---- C:\Windows\system32\wmp.dll
2017-05-19 20:41:48 ----A---- C:\Windows\system32\tquery.dll
2017-05-19 20:41:45 ----A---- C:\Windows\SYSWOW64\wmp.dll
2017-05-19 20:41:45 ----A---- C:\Windows\system32\mssrch.dll
2017-05-19 20:41:43 ----A---- C:\Windows\SYSWOW64\tquery.dll
2017-05-19 20:41:41 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2017-05-19 20:41:38 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2017-05-19 20:41:38 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-05-19 20:41:37 ----A---- C:\Windows\SYSWOW64\MSAudDecMFT.dll
2017-05-19 20:41:37 ----A---- C:\Windows\system32\kd_02_10ec.dll
2017-05-19 20:41:35 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-05-19 20:41:34 ----A---- C:\Windows\SYSWOW64\mssph.dll
2017-05-19 20:41:34 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-19 20:41:33 ----A---- C:\Windows\system32\rsaenh.dll
2017-05-19 20:41:33 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2017-05-19 20:41:32 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2017-05-19 20:41:32 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2017-05-19 20:41:32 ----A---- C:\Windows\system32\Windows.Networking.dll
2017-05-19 20:41:32 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-05-19 20:41:32 ----A---- C:\Windows\system32\mssph.dll
2017-05-19 20:41:32 ----A---- C:\Windows\system32\dwmredir.dll
2017-05-19 20:41:32 ----A---- C:\Windows\system32\conhost.exe
2017-05-19 20:41:32 ----A---- C:\Windows\system32\AudioEng.dll
2017-05-19 20:41:31 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2017-05-19 20:41:31 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2017-05-19 20:41:31 ----A---- C:\Windows\system32\wpncore.dll
2017-05-19 20:41:31 ----A---- C:\Windows\system32\RecoveryDrive.exe
2017-05-19 20:41:31 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-19 20:41:29 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-05-19 20:41:29 ----A---- C:\Windows\system32\MFMediaEngine.dll
2017-05-19 20:41:28 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2017-05-19 20:41:26 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll
2017-05-19 20:41:26 ----A---- C:\Windows\system32\fhengine.dll
2017-05-19 20:41:26 ----A---- C:\Windows\system32\dmvdsitf.dll
2017-05-19 20:41:26 ----A---- C:\Windows\system32\ci.dll
2017-05-19 20:41:25 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2017-05-19 20:41:25 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2017-05-19 20:41:25 ----A---- C:\Windows\system32\XpsRasterService.dll
2017-05-19 20:41:25 ----A---- C:\Windows\system32\mfreadwrite.dll
2017-05-19 20:41:24 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2017-05-19 20:41:24 ----A---- C:\Windows\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-05-19 20:41:24 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2017-05-19 20:41:24 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-05-19 20:41:24 ----A---- C:\Windows\system32\Robocopy.exe
2017-05-19 20:41:24 ----A---- C:\Windows\system32\kdvm.dll
2017-05-19 20:41:23 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2017-05-19 20:41:23 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2017-05-19 20:41:22 ----A---- C:\Windows\SYSWOW64\dmvdsitf.dll
2017-05-19 20:41:22 ----A---- C:\Windows\system32\kdnet.dll
2017-05-19 20:41:22 ----A---- C:\Windows\system32\iuilp.dll
2017-05-19 20:41:21 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2017-05-19 20:41:21 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2017-05-19 20:41:21 ----A---- C:\Windows\system32\wscsvc.dll
2017-05-19 20:41:21 ----A---- C:\Windows\system32\drivers\wanarp.sys
2017-05-19 20:41:21 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-05-19 20:41:20 ----A---- C:\Windows\system32\mssvp.dll
2017-05-19 20:41:20 ----A---- C:\Windows\system32\GenuineCenter.dll
2017-05-19 20:41:20 ----A---- C:\Windows\system32\drivers\ndproxy.sys
2017-05-19 20:41:19 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2017-05-19 20:41:19 ----A---- C:\Windows\SYSWOW64\msshooks.dll
2017-05-19 20:41:19 ----A---- C:\Windows\SYSWOW64\fmifs.dll
2017-05-19 20:41:19 ----A---- C:\Windows\system32\mssprxy.dll
2017-05-19 20:41:19 ----A---- C:\Windows\system32\msshooks.dll
2017-05-19 20:41:19 ----A---- C:\Windows\system32\fmifs.dll
2017-05-19 20:41:18 ----A---- C:\Windows\SYSWOW64\mssprxy.dll
2017-05-19 20:41:18 ----A---- C:\Windows\system32\msscntrs.dll
2017-05-19 20:41:17 ----A---- C:\Windows\SYSWOW64\tzres.dll
2017-05-19 20:41:17 ----A---- C:\Windows\system32\tzres.dll
2017-05-19 20:40:45 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2017-05-19 20:40:45 ----A---- C:\Windows\system32\msvcr120_clr0400.dll
2017-05-19 20:39:39 ----A---- C:\Windows\system32\dnsapi.dll
2017-05-19 20:39:38 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2017-05-19 20:39:38 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2017-05-19 20:39:36 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2017-05-19 20:39:35 ----A---- C:\Windows\system32\dnsrslvr.dll
2017-05-19 20:39:03 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2017-05-19 20:39:03 ----A---- C:\Windows\system32\mstscax.dll
2017-05-19 20:39:02 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2017-05-19 20:39:02 ----A---- C:\Windows\system32\aaclient.dll
2017-05-19 20:38:51 ----A---- C:\Windows\system32\basesrv.dll
2017-05-19 20:38:50 ----A---- C:\Windows\system32\csrsrv.dll
2017-05-19 20:37:42 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2017-05-19 20:37:42 ----A---- C:\Windows\system32\imagehlp.dll
2017-05-19 20:37:26 ----A---- C:\Windows\SYSWOW64\msvcp120_clr0400.dll
2017-05-19 20:37:26 ----A---- C:\Windows\system32\msvcp120_clr0400.dll
2017-05-19 20:36:51 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-05-19 20:36:47 ----A---- C:\Windows\system32\WsmSvc.dll
2017-05-19 20:36:46 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2017-05-19 20:36:46 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2017-05-19 20:36:44 ----A---- C:\Windows\system32\WsmWmiPl.dll
2017-05-19 20:36:43 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2017-05-19 20:36:43 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-05-19 20:36:43 ----A---- C:\Windows\system32\rpchttp.dll
2017-05-19 20:36:42 ----A---- C:\Windows\SYSWOW64\FXSCOMEX.dll
2017-05-19 20:36:42 ----A---- C:\Windows\system32\FXSCOMEX.dll
2017-05-19 20:36:41 ----A---- C:\Windows\SYSWOW64\FXSAPI.dll
2017-05-19 20:36:40 ----A---- C:\Windows\system32\FXST30.dll
2017-05-19 20:36:39 ----A---- C:\Windows\system32\FXSTIFF.dll
2017-05-19 20:36:39 ----A---- C:\Windows\system32\FXSAPI.dll
2017-05-19 20:35:21 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2017-05-19 20:35:18 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2017-05-19 20:35:14 ----A---- C:\Windows\system32\drivers\rdbss.sys
2017-05-19 20:35:14 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2017-05-19 20:35:13 ----A---- C:\Windows\system32\BCP47Langs.dll
2017-05-19 20:35:12 ----A---- C:\Windows\system32\netprofmsvc.dll
2017-05-19 20:35:11 ----A---- C:\Windows\SYSWOW64\BCP47Langs.dll
2017-05-19 20:35:11 ----A---- C:\Windows\system32\netprofm.dll
2017-05-19 20:35:09 ----A---- C:\Windows\system32\stobject.dll
2017-05-19 20:35:09 ----A---- C:\Windows\system32\netplwiz.dll
2017-05-19 20:35:09 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2017-05-19 20:35:08 ----A---- C:\Windows\system32\psmsrv.dll
2017-05-19 20:35:08 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2017-05-19 20:35:08 ----A---- C:\Windows\system32\Magnify.exe
2017-05-19 20:35:07 ----A---- C:\Windows\SYSWOW64\stobject.dll
2017-05-19 20:35:07 ----A---- C:\Windows\SYSWOW64\netplwiz.dll
2017-05-19 20:35:07 ----A---- C:\Windows\system32\taskhost.exe
2017-05-19 20:35:07 ----A---- C:\Windows\system32\DevicePairing.dll
2017-05-19 20:35:06 ----A---- C:\Windows\SYSWOW64\Magnify.exe
2017-05-19 20:35:06 ----A---- C:\Windows\system32\AuthHost.exe
2017-05-19 20:35:05 ----A---- C:\Windows\SYSWOW64\netprofm.dll
2017-05-19 20:35:05 ----A---- C:\Windows\SYSWOW64\DevicePairing.dll
2017-05-19 20:35:05 ----A---- C:\Windows\system32\biwinrt.dll
2017-05-19 20:35:04 ----A---- C:\Windows\SYSWOW64\biwinrt.dll
2017-05-19 20:35:03 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2017-05-19 20:35:03 ----A---- C:\Windows\system32\taskhostex.exe
2017-05-19 20:35:03 ----A---- C:\Windows\system32\bisrv.dll
2017-05-19 20:35:02 ----A---- C:\Windows\SYSWOW64\npmproxy.dll
2017-05-19 20:35:02 ----A---- C:\Windows\SYSWOW64\muifontsetup.dll
2017-05-19 20:35:02 ----A---- C:\Windows\system32\muifontsetup.dll
2017-05-19 20:35:01 ----A---- C:\Windows\SYSWOW64\nlmsprep.dll
2017-05-19 20:35:01 ----A---- C:\Windows\SYSWOW64\nlmproxy.dll
2017-05-19 20:34:20 ----A---- C:\Windows\SYSWOW64\certutil.exe
2017-05-19 20:34:20 ----A---- C:\Windows\system32\certutil.exe
2017-05-19 20:34:19 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2017-05-19 20:34:19 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-19 20:34:14 ----A---- C:\Windows\SYSWOW64\untfs.dll
2017-05-19 20:34:14 ----A---- C:\Windows\system32\untfs.dll
2017-05-19 20:34:14 ----A---- C:\Windows\system32\autochk.exe
2017-05-19 20:34:13 ----A---- C:\Windows\SYSWOW64\autochk.exe
2017-05-19 20:34:12 ----A---- C:\Windows\system32\WindowsCodecs.dll
2017-05-19 20:34:11 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2017-05-19 20:34:04 ----A---- C:\Windows\system32\mshtml.dll
2017-05-19 20:33:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-05-19 20:33:27 ----A---- C:\Windows\system32\ieframe.dll
2017-05-19 20:33:23 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-05-19 20:33:21 ----A---- C:\Windows\system32\jscript9.dll
2017-05-19 20:33:20 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-05-19 20:33:19 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-05-19 20:33:18 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-05-19 20:33:18 ----A---- C:\Windows\system32\wininet.dll
2017-05-19 20:33:18 ----A---- C:\Windows\system32\iertutil.dll
2017-05-19 20:33:17 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-05-19 20:33:17 ----A---- C:\Windows\system32\uxtheme.dll
2017-05-19 20:33:17 ----A---- C:\Windows\system32\urlmon.dll
2017-05-19 20:33:16 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-05-19 20:33:16 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-05-19 20:33:15 ----A---- C:\Windows\system32\vbscript.dll
2017-05-19 20:33:15 ----A---- C:\Windows\system32\jscript.dll
2017-05-19 20:33:15 ----A---- C:\Windows\system32\dxtmsft.dll
2017-05-19 20:33:03 ----A---- C:\Windows\SYSWOW64\uxtheme.dll
2017-05-19 20:33:03 ----A---- C:\Windows\system32\inetcomm.dll
2017-05-19 20:33:02 ----A---- C:\Windows\system32\msfeeds.dll
2017-05-19 20:33:01 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-05-19 20:33:01 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2017-05-19 20:33:00 ----A---- C:\Windows\system32\ie4uinit.exe
2017-05-19 20:32:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-05-19 20:32:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-05-19 20:32:59 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2017-05-19 20:32:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-05-19 20:32:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-05-19 20:32:59 ----A---- C:\Windows\system32\jsproxy.dll
2017-05-19 20:32:59 ----A---- C:\Windows\system32\dxtrans.dll
2017-05-19 20:32:58 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-05-19 20:32:58 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-05-19 20:32:58 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-05-19 20:32:58 ----A---- C:\Windows\system32\msrating.dll
2017-05-19 20:32:58 ----A---- C:\Windows\system32\mshtmled.dll
2017-05-19 20:32:58 ----A---- C:\Windows\system32\iesysprep.dll
2017-05-19 20:32:58 ----A---- C:\Windows\system32\iedkcs32.dll
2017-05-19 20:32:57 ----A---- C:\Windows\SYSWOW64\UXInit.dll
2017-05-19 20:32:57 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-05-19 20:32:57 ----A---- C:\Windows\system32\UXInit.dll
2017-05-19 20:32:57 ----A---- C:\Windows\system32\iernonce.dll
2017-05-19 20:32:56 ----A---- C:\Windows\system32\iesetup.dll
2017-05-19 20:32:55 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2017-05-19 20:32:55 ----A---- C:\Windows\system32\INETRES.dll
2017-05-19 20:32:27 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2017-05-19 20:32:26 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2017-05-19 20:32:23 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2017-05-19 20:32:23 ----A---- C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-05-19 20:32:23 ----A---- C:\Windows\system32\Windows.Globalization.dll
2017-05-19 20:32:23 ----A---- C:\Windows\system32\SystemEventsBrokerServer.dll
2017-05-19 20:32:22 ----A---- C:\Windows\system32\TimeBrokerServer.dll
2017-05-19 20:32:22 ----A---- C:\Windows\system32\drivers\storport.sys
2017-05-19 20:32:21 ----A---- C:\Windows\SYSWOW64\Windows.Globalization.dll
2017-05-19 20:32:21 ----A---- C:\Windows\system32\wpdbusenum.dll
2017-05-19 20:32:21 ----A---- C:\Windows\system32\netcfgx.dll
2017-05-19 20:32:20 ----A---- C:\Windows\SYSWOW64\Windows.Security.Authentication.OnlineId.dll
2017-05-19 20:32:20 ----A---- C:\Windows\SYSWOW64\drvstore.dll
2017-05-19 20:32:20 ----A---- C:\Windows\system32\usbmon.dll
2017-05-19 20:32:19 ----A---- C:\Windows\system32\drvstore.dll
2017-05-19 20:32:18 ----A---- C:\Windows\system32\discan.dll
2017-05-19 20:32:15 ----A---- C:\Windows\system32\NdisImPlatform.dll
2017-05-19 20:32:12 ----A---- C:\Windows\system32\WSDPrintProxy.DLL
2017-05-19 20:32:12 ----A---- C:\Windows\system32\DevDispItemProvider.dll
2017-05-19 20:32:09 ----A---- C:\Windows\SYSWOW64\DevDispItemProvider.dll
2017-05-19 20:31:30 ----A---- C:\Windows\system32\rdpcorets.dll
2017-05-19 20:31:29 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2017-05-19 20:31:29 ----A---- C:\Windows\system32\termsrv.dll
2017-05-19 20:31:29 ----A---- C:\Windows\system32\mstsc.exe
2017-05-19 20:31:28 ----A---- C:\Windows\SYSWOW64\winsta.dll
2017-05-19 20:31:28 ----A---- C:\Windows\system32\winsta.dll
2017-05-19 20:31:26 ----A---- C:\Windows\system32\rdpudd.dll
2017-05-19 20:31:06 ----A---- C:\Windows\system32\WSService.dll
2017-05-19 20:31:04 ----A---- C:\Windows\system32\WinSetupUI.dll
2017-05-19 20:31:03 ----A---- C:\Windows\SYSWOW64\sppc.dll
2017-05-19 20:31:03 ----A---- C:\Windows\system32\sppc.dll
2017-05-19 20:31:02 ----A---- C:\Windows\SYSWOW64\WSSync.dll
2017-05-19 20:31:02 ----A---- C:\Windows\system32\WSSync.dll
2017-05-19 20:31:01 ----A---- C:\Windows\system32\WSClient.dll
2017-05-19 20:31:01 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2017-05-19 20:31:01 ----A---- C:\Windows\system32\drivers\dam.sys
2017-05-19 20:31:00 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2017-05-19 20:31:00 ----A---- C:\Windows\system32\setupcln.dll
2017-05-19 20:30:56 ----A---- C:\Windows\SYSWOW64\setupcln.dll
2017-05-19 20:30:56 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2017-05-19 20:30:04 ----A---- C:\Windows\SYSWOW64\wlroamextension.dll
2017-05-19 20:30:03 ----A---- C:\Windows\SYSWOW64\WWanAPI.dll
2017-05-19 20:30:03 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2017-05-19 20:30:03 ----A---- C:\Windows\SYSWOW64\tasklist.exe
2017-05-19 20:30:03 ----A---- C:\Windows\SYSWOW64\taskkill.exe
2017-05-19 20:30:03 ----A---- C:\Windows\SYSWOW64\duser.dll
2017-05-19 20:30:02 ----A---- C:\Windows\SYSWOW64\mbsmsapi.dll
2017-05-19 20:29:57 ----A---- C:\Windows\system32\wlroamextension.dll
2017-05-19 20:29:56 ----A---- C:\Windows\system32\WWanAPI.dll
2017-05-19 20:29:56 ----A---- C:\Windows\system32\wpd_ci.dll
2017-05-19 20:29:56 ----A---- C:\Windows\system32\tasklist.exe
2017-05-19 20:29:56 ----A---- C:\Windows\system32\taskkill.exe
2017-05-19 20:29:54 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-05-19 20:29:54 ----A---- C:\Windows\system32\mbsmsapi.dll
2017-05-19 20:29:54 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-05-19 20:29:54 ----A---- C:\Windows\system32\drivers\ndis.sys
2017-05-19 20:29:53 ----A---- C:\Windows\system32\wersvc.dll
2017-05-19 20:29:53 ----A---- C:\Windows\system32\hotspotauth.dll
2017-05-19 20:29:53 ----A---- C:\Windows\system32\drivers\ks.sys
2017-05-19 20:29:52 ----A---- C:\Windows\system32\duser.dll
2017-05-19 20:29:50 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2017-05-19 20:29:15 ----A---- C:\Windows\SYSWOW64\SettingSyncInfo.dll
2017-05-19 20:29:15 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2017-05-19 20:29:15 ----A---- C:\Windows\SYSWOW64\authui.dll
2017-05-19 20:29:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2017-05-19 20:29:13 ----A---- C:\Windows\SYSWOW64\twinui.dll
2017-05-19 20:29:10 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2017-05-19 20:29:08 ----A---- C:\Windows\system32\twinui.dll
2017-05-19 20:29:08 ----A---- C:\Windows\system32\SettingSyncInfo.dll
2017-05-19 20:29:08 ----A---- C:\Windows\system32\SettingSync.dll
2017-05-19 20:29:08 ----A---- C:\Windows\system32\authui.dll
2017-05-19 20:29:00 ----A---- C:\Windows\SYSWOW64\osk.exe
2017-05-19 20:29:00 ----A---- C:\Windows\system32\osk.exe
2017-05-19 20:28:57 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-05-19 20:28:56 ----A---- C:\Windows\system32\gdi32.dll
2017-05-19 20:27:56 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2017-05-19 20:27:55 ----A---- C:\Windows\system32\drivers\clfs.sys
2017-05-19 20:27:55 ----A---- C:\Windows\system32\clfsw32.dll
2017-05-19 20:27:53 ----A---- C:\Windows\system32\services.exe
2017-05-19 20:27:47 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2017-05-19 20:27:46 ----A---- C:\Windows\system32\GdiPlus.dll
2017-05-19 20:27:41 ----A---- C:\Windows\system32\schedsvc.dll
2017-05-19 20:21:45 ----A---- C:\Windows\system32\mmc.exe
2017-05-19 20:21:44 ----A---- C:\Windows\SYSWOW64\mmc.exe
2017-05-19 20:21:44 ----A---- C:\Windows\system32\wlidsvc.dll
2017-05-19 20:21:42 ----A---- C:\Windows\system32\msctf.dll
2017-05-19 20:21:41 ----A---- C:\Windows\system32\setupapi.dll
2017-05-19 20:21:40 ----A---- C:\Windows\SYSWOW64\setupapi.dll
2017-05-19 20:21:39 ----A---- C:\Windows\system32\drivers\partmgr.sys
2017-05-19 20:21:38 ----A---- C:\Windows\system32\iphlpsvc.dll
2017-05-19 20:21:36 ----A---- C:\Windows\system32\inetpp.dll
2017-05-19 20:21:35 ----A---- C:\Windows\SYSWOW64\msctf.dll
2017-05-19 20:21:34 ----A---- C:\Windows\SYSWOW64\wiaacmgr.exe
2017-05-19 20:21:34 ----A---- C:\Windows\system32\WSDMon.dll
2017-05-19 20:21:34 ----A---- C:\Windows\system32\wiaacmgr.exe
2017-05-19 20:21:34 ----A---- C:\Windows\system32\samsrv.dll
2017-05-19 20:21:34 ----A---- C:\Windows\system32\ncbservice.dll
2017-05-19 20:21:33 ----A---- C:\Windows\SYSWOW64\samlib.dll
2017-05-19 20:21:33 ----A---- C:\Windows\system32\keepaliveprovider.dll
2017-05-19 20:21:33 ----A---- C:\Windows\system32\httpprxp.dll
2017-05-19 20:21:33 ----A---- C:\Windows\system32\httpprxm.dll
2017-05-19 20:21:33 ----A---- C:\Windows\system32\adhsvc.dll
2017-05-19 20:21:33 ----A---- C:\Windows\system32\adhapi.dll
2017-05-19 20:20:20 ----A---- C:\Windows\system32\TSWbPrxy.exe
2017-05-19 20:17:36 ----A---- C:\Windows\SYSWOW64\objsel.dll
2017-05-19 20:17:35 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-05-19 20:17:35 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2017-05-19 20:15:53 ----A---- C:\Windows\system32\objsel.dll
2017-05-19 20:15:46 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-19 20:15:46 ----A---- C:\Windows\system32\dpapisrv.dll
2017-05-19 20:15:45 ----A---- C:\Windows\system32\dimsroam.dll
2017-05-19 20:15:26 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-05-19 20:15:24 ----A---- C:\Windows\system32\appidsvc.dll
2017-05-19 20:15:24 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-05-19 20:15:24 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-05-19 20:15:24 ----A---- C:\Windows\system32\appidapi.dll
2017-05-19 20:15:20 ----A---- C:\Windows\SYSWOW64\rastls.dll
2017-05-19 20:15:19 ----A---- C:\Windows\system32\rastls.dll
2017-05-19 20:14:33 ----A---- C:\Windows\system32\EOSNotify.exe
2017-05-19 20:14:26 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-05-19 20:14:17 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-05-19 20:12:50 ----D---- C:\Windows\SYSWOW64\NV
2017-05-19 20:12:50 ----D---- C:\Windows\system32\NV
2017-05-18 23:59:54 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2017-05-18 23:59:54 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2017-05-18 23:59:54 ----A---- C:\Windows\system32\nshwfp.dll
2017-05-18 23:59:54 ----A---- C:\Windows\system32\IKEEXT.DLL
2017-05-18 23:59:54 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2017-05-18 23:59:54 ----A---- C:\Windows\system32\drivers\wfplwfs.sys
2017-05-18 23:59:54 ----A---- C:\Windows\system32\BFE.DLL
2017-05-18 23:59:44 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2017-05-18 23:59:44 ----A---- C:\Windows\system32\schannel.dll
2017-05-18 23:59:44 ----A---- C:\Windows\system32\SHCore.dll
2017-05-18 23:59:44 ----A---- C:\Windows\system32\kerberos.dll
2017-05-18 23:59:43 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2017-05-18 23:59:43 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-05-18 23:59:43 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-05-18 23:59:43 ----A---- C:\Windows\system32\drivers\cng.sys
2017-05-18 23:59:42 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2017-05-18 23:59:42 ----A---- C:\Windows\system32\usercpl.dll
2017-05-18 23:59:42 ----A---- C:\Windows\system32\ncrypt.dll
2017-05-18 23:59:42 ----A---- C:\Windows\system32\bcryptprimitives.dll
2017-05-18 23:59:41 ----A---- C:\Windows\SYSWOW64\ncryptsslp.dll
2017-05-18 23:59:41 ----A---- C:\Windows\system32\ncryptsslp.dll
2017-05-18 23:59:41 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-05-18 23:59:40 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-05-18 23:58:48 ----A---- C:\Windows\system32\wer.dll
2017-05-18 23:58:47 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2017-05-18 23:58:47 ----A---- C:\Windows\SYSWOW64\wer.dll
2017-05-18 23:58:47 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2017-05-18 23:58:47 ----A---- C:\Windows\system32\WerFault.exe
2017-05-18 23:58:47 ----A---- C:\Windows\system32\Faultrep.dll
2017-05-18 23:58:46 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2017-05-18 23:58:46 ----A---- C:\Windows\system32\WerFaultSecure.exe
2017-05-18 23:58:31 ----A---- C:\Windows\system32\drivers\usb8023.sys
2017-05-18 23:58:29 ----A---- C:\Windows\system32\drivers\rmcast.sys
2017-05-18 23:54:13 ----A---- C:\Windows\system32\drivers\http.sys
2017-05-18 23:44:46 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-05-18 23:44:42 ----A---- C:\Windows\system32\winload.exe
2017-05-18 23:44:41 ----A---- C:\Windows\system32\winresume.exe
2017-05-18 23:40:07 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2017-05-18 23:40:07 ----A---- C:\Windows\system32\nlasvc.dll
2017-05-18 23:40:07 ----A---- C:\Windows\system32\nlaapi.dll
2017-05-18 23:40:07 ----A---- C:\Windows\system32\ncsi.dll
2017-05-18 23:39:58 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2017-05-18 23:39:58 ----A---- C:\Windows\system32\ubpm.dll
2017-05-18 23:39:00 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-05-18 23:24:49 ----A---- C:\Windows\system32\win32k.sys
2017-05-18 23:24:46 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2017-05-18 23:24:46 ----A---- C:\Windows\system32\comctl32.dll
2017-05-18 23:22:00 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2017-05-18 23:22:00 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2017-05-18 23:22:00 ----A---- C:\Windows\system32\vulkaninfo.exe
2017-05-18 23:22:00 ----A---- C:\Windows\system32\vulkan-1.dll
2017-05-18 23:21:56 ----D---- C:\Program Files (x86)\VulkanRT
2017-05-18 23:20:16 ----A---- C:\Windows\NvContainerRecovery.bat
2017-05-18 23:17:55 ----A---- C:\Windows\system32\scrrun.dll
2017-05-18 23:17:55 ----A---- C:\Windows\system32\scrobj.dll
2017-05-18 23:17:54 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2017-05-18 23:17:54 ----A---- C:\Windows\system32\cscript.exe
2017-05-18 23:17:53 ----A---- C:\Windows\SYSWOW64\scrobj.dll
2017-05-18 23:17:53 ----A---- C:\Windows\SYSWOW64\cscript.exe
2017-05-18 23:17:02 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2017-05-18 23:17:02 ----A---- C:\Windows\system32\shdocvw.dll
2017-05-18 21:19:21 ----A---- C:\Windows\system32\kernel32.dll
2017-05-18 21:19:20 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-05-18 21:16:38 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2017-05-18 21:16:38 ----A---- C:\Windows\system32\WMVDECOD.DLL
2017-05-18 21:16:38 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2017-05-18 21:16:37 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2017-05-18 21:16:37 ----A---- C:\Windows\system32\WMADMOD.DLL
2017-05-18 21:16:36 ----A---- C:\Windows\SYSWOW64\msmpeg2adec.dll
2017-05-18 21:16:36 ----A---- C:\Windows\SYSWOW64\mfnetsrc.dll
2017-05-18 21:16:36 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2017-05-18 21:16:36 ----A---- C:\Windows\system32\msmpeg2adec.dll
2017-05-18 21:16:36 ----A---- C:\Windows\system32\mfnetsrc.dll
2017-05-18 21:16:36 ----A---- C:\Windows\system32\mfnetcore.dll
2017-05-18 21:16:35 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2017-05-18 21:16:35 ----A---- C:\Windows\system32\WMVSDECD.DLL
2017-05-18 21:16:35 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2017-05-18 21:16:35 ----A---- C:\Windows\system32\mfcore.dll
2017-05-18 21:16:35 ----A---- C:\Windows\system32\mf.dll
2017-05-18 21:16:35 ----A---- C:\Windows\system32\audiosrv.dll
2017-05-18 21:16:35 ----A---- C:\Windows\system32\AUDIOKSE.dll
2017-05-18 21:16:34 ----A---- C:\Windows\SYSWOW64\mfnetcore.dll
2017-05-18 21:16:34 ----A---- C:\Windows\SYSWOW64\mf.dll
2017-05-18 21:16:34 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2017-05-18 21:16:34 ----A---- C:\Windows\system32\wmpmde.dll
2017-05-18 21:16:34 ----A---- C:\Windows\system32\evr.dll
2017-05-18 21:16:33 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2017-05-18 21:16:33 ----A---- C:\Windows\SYSWOW64\WMSPDMOD.DLL
2017-05-18 21:16:33 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-05-18 21:16:33 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2017-05-18 21:16:33 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2017-05-18 21:16:33 ----A---- C:\Windows\system32\winmde.dll
2017-05-18 21:16:33 ----A---- C:\Windows\system32\AudioSes.dll
2017-05-18 21:16:32 ----A---- C:\Windows\SYSWOW64\evr.dll
2017-05-18 21:16:32 ----A---- C:\Windows\system32\mfplat.dll
2017-05-18 21:16:32 ----A---- C:\Windows\system32\audiodg.exe
2017-05-18 21:16:31 ----A---- C:\Windows\SYSWOW64\WMADMOE.DLL
2017-05-18 21:16:31 ----A---- C:\Windows\SYSWOW64\winmde.dll
2017-05-18 21:16:31 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2017-05-18 21:16:31 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2017-05-18 21:16:31 ----A---- C:\Windows\system32\quartz.dll
2017-05-18 21:16:30 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2017-05-18 21:16:30 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2017-05-18 21:16:30 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\WMVXENCD.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\WMVSENCD.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\WMVENCOD.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\WMADMOE.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\Windows.Media.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\qdvd.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2017-05-18 21:16:30 ----A---- C:\Windows\system32\mfsvr.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\mfps.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\EncDump.dll
2017-05-18 21:16:30 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\WMVXENCD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\WMVSENCD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\WMVENCOD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\WMSPDMOE.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\VIDRESZR.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\RESAMPLEDMO.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\qasf.dll
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\MPG4DECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\MP4SDECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\MP43DECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\MP3DMOD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\MFWMAAEC.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\mfvdsp.dll
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\mfps.dll
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\devenum.dll
2017-05-18 21:16:29 ----A---- C:\Windows\SYSWOW64\COLORCNV.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\VIDRESZR.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\qasf.dll
2017-05-18 21:16:29 ----A---- C:\Windows\system32\MPG4DECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\MP4SDECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\MP43DECD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\MP3DMOD.DLL
2017-05-18 21:16:29 ----A---- C:\Windows\system32\mfvdsp.dll