Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with an UNKNOWN Cryptolocker


  • This topic is locked This topic is locked
15 replies to this topic

#1 alir32a

alir32a

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 05 February 2015 - 02:30 AM

Recently (about 60 hours ago) my home pc (Win7 x64) infected with a type of CTB-Locker, i guess.
 
My video and image files has been encrypted with this ext. ".id-9086528147_fud@india.com"
 
And my big disaster is videos and images of my decedent mother.
Unfortunately, it seems main encryptor is gone from TEMP or somewhere else. Now system is clean but before, Malwarebyte and ESET didn't detect any issue!
I attended to attack from full pagefile, svchost high load memory (with Netsvcs related service) and one unknown temp file. so i turned off the pc immediately, disconnected logical HDDs and start pc by second OS. Unfortunately i don't know when infection had started but many video (mkv and avi but no mp4) almost all images and some rar files have been encrypted and all from logical drives. At the end i clean the system with Stinger and AVAST and SUPERAntispyware from second operating sytem (XP). My portable Chrome was infected.

Stinger detect some Artemis! trojan
AVAST detect a generic trojan
SUPERAntispyware detect PUP and Adware Somoto

 

After a boot scan by AVAST my XP didn't start and locked on a black screen before logon screen. After that i'm using Win7 Safe Mod.

Unfamiliar things are another Pagefile.sys in logical drive and a file called "Lockdir6.lg" in Public user folder.
 

Biggest problem is that now even i don't know how to pay for unlocking!!! 
I checked hex of some locked files but my knowlege is not enough to find the correct algorithm.

Here is a JPEG file both clean and encrypted: http://www.datafilehost.com/d/3b73f465

 FRST Log

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2015 01
Ran by Administrator at 2015-02-05 10:22:07
Running from C:\Users\Administrator\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 4.2 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET Smart Security 4.2 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall (Enabled) {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\uTorrent) (Version: 3.4.2.33870 - BitTorrent Inc.)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.125 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ASRock eXtreme Tuner v0.1.94 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version:  - )
BitTorrent (HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\BitTorrent) (Version: 7.9.2.33876 - BitTorrent Inc.)
Canon MP Navigator EX 2.1 (HKLM-x32\...\MP Navigator EX 2.1) (Version:  - )
CanoScan LiDE 700F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ9601) (Version:  - )
CopyFilenames 3.1 (HKLM\...\CopyFilenames_is1) (Version: 3.1 - ExtraBit Software)
CyberGhost 5 (HKLM\...\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
Data Recovery Pro (HKLM-x32\...\{B1C2398C-6FAB-46D1-806C-5942F0829994}) (Version: 2.1.0.0 - ParetoLogic, Inc.)
Earth Alerts (HKLM-x32\...\{4C892B5B-3F19-4FF4-B3CC-B746DB646C1F}) (Version: 14.1.130 - South Wind Technologies)
ESET Smart Security (HKLM\...\{C0D93E4E-0866-43C8-A104-BF41A803EA84}) (Version: 4.2.71.2 - ESET, spol. s r.o.)
FlashGet(JetCar) (HKLM-x32\...\FlashGet(JetCar)) (Version:  - )
Folder Marker Free (HKLM\...\Folder Marker Free_is1) (Version: 4.2 - ArcticLine Software)
FUJIFILM MyFinePix Studio 4.2a (HKLM-x32\...\MyFinePix Studio_is1) (Version:  - )
HashCheck Shell Extension (x86-32) (HKLM-x32\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
HashCheck Shell Extension (x86-64) (HKLM\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
iSpy (HKLM-x32\...\{E05C738C-1CA9-4E80-B44F-B31E2F44CEA3}) (Version: 5.6.5 - iSpy)
Java 8 Update 5 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418005FF}) (Version: 8.0.50 - Oracle Corporation)
Java 8 Update 5 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218005FF}) (Version: 8.0.50 - Oracle Corporation)
Microsoft .NET Framework 4.5.2 Hotfix Rollup (KB3011114) (HKLM\...\{8AB1C38E-8622-3F81-B3D8-C5DD2D70830E}) (Version: 4.5.52279 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (HKLM\...\{3C28BFD4-90C7-3138-87EF-418DC16E9598}) (Version: 11.0.51106 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (HKLM\...\{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}) (Version: 11.0.51106 - Microsoft Corporation)
NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software s.r.o.)
NetSpeedMonitor 2.5.4.0 x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: 2.5.4.0 - Florian Gilles)
novaPDF Professional Desktop 7.7 printer (HKLM\...\novaPDF Professional Desktop 7 printer_is1) (Version: 7.7.394 - Softland)
Platform (x32 Version: 1.36 - VIA Technologies, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.14.9529 - SoftEther VPN Project)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TaskmgrPro V1.4.5 (HKLM\...\TaskmgrPro_is1) (Version:  - GoldGingko Software)
Theme Resource Changer X64 v1.0 (HKLM\...\Theme Resource Changer X64 v1.0) (Version:  - Bad Ass Apps)
THX TruStudio (HKLM-x32\...\{AFB907F5-C0E6-4753-8284-DE955EF86AC2}) (Version: 1.00.01 - Creative Technology Limited)
Types (HKLM\...\Types) (Version: 2.1.1 - E. Strunnikov)
VBA (2627.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.)
Weather Watcher Live (HKLM-x32\...\{98FDC595-92B3-48D5-80D6-FE7AABD9191B}_is1) (Version: Weather Watcher Live (Build: 3/17/14) - Singer's Creations)
WinArchiver (HKLM-x32\...\WinArchiver) (Version: 3.7 - Power Software Ltd)
Windows Deployment Tools (HKLM-x32\...\{FEA31583-30A7-0951-718C-AF75DCB003B1}) (Version: 8.100.25984 - Microsoft)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
Zan Image Printer (HKLM\...\zvprt50) (Version:  - )
Zling HCF V.90 Speakerphone PCI Modem (HKLM\...\CXT1056) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3192508786-2493758777-3291605813-500_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> D:\Portable\MediaInfo\MediaInfo_InfoTip.dll (http://MediaArea.net/MediaInfo)

==================== Restore Points  =========================

ATTENTION: System Restore is disabled.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-09-14 19:20 - 2015-02-04 05:35 - 00000080 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 martau.com total-uninstall.com
127.0.0.1 license.superantispyware.com

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01767C1E-4E42-409B-AC98-88F8375E840B} - System32\Tasks\{F1B17328-CEC2-4A19-850D-1D02900D4E83} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2010 x64 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: {714C9CD0-A6D2-4B61-91F3-27F2F487E017} - System32\Tasks\{804625CF-BAEC-4D45-B0DD-C0E5787E0CD5} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2008 x86 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: {99C9036A-7593-4A20-B687-5ADDE8B7A32A} - System32\Tasks\{B5EBED75-55ED-4E33-B407-96709489D3DC} => pcalua.exe -a C:\Users\Administrator\Desktop\FlashGetPortable\FlashGetPortable.exe -d C:\Users\Administrator\Desktop\FlashGetPortable
Task: {9E326901-3285-4CD1-8B8D-154CF2F87F77} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {AACDE4E9-D0D5-4D03-9D77-B4FEAB00D7B0} - System32\Tasks\{85986AA8-1E97-477A-9EE2-057D572761F7} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2010 x86 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: C:\Windows\Tasks\ParetoLogic Registration3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\UUS3.dll

==================== Loaded Modules (whitelisted) ==============

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows\win.ini:s1
AlternateDataStreams: C:\Users\Administrator\Cookies:KHXvOrekXH5qyOhfDoGTGALe98
AlternateDataStreams: C:\Users\Administrator\Local Settings:init
AlternateDataStreams: C:\Users\Administrator\Local Settings:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\ProgramData\Microsoft:olXsEwmMswjyX3V1RWskBwY0SZ
AlternateDataStreams: C:\ProgramData\Microsoft:xRlz20fmPhmNWamwAD8w
AlternateDataStreams: C:\ProgramData\Temp:0888F409
AlternateDataStreams: C:\ProgramData\Temp:1677AB3F
AlternateDataStreams: C:\ProgramData\Temp:3440EB47
AlternateDataStreams: C:\ProgramData\Temp:58A5270D
AlternateDataStreams: C:\ProgramData\Temp:66633281
AlternateDataStreams: C:\ProgramData\Temp:6DAA43DB
AlternateDataStreams: C:\ProgramData\Temp:8FAE08A5
AlternateDataStreams: C:\ProgramData\Temp:93433455
AlternateDataStreams: C:\ProgramData\Temp:9E00596C
AlternateDataStreams: C:\ProgramData\Temp:BF3D62E7
AlternateDataStreams: C:\ProgramData\Temp:C7D0F96D
AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9
AlternateDataStreams: C:\ProgramData\Temp:CF54F1CA
AlternateDataStreams: C:\ProgramData\Temp:D8999815
AlternateDataStreams: C:\ProgramData\Temp:E36A723B
AlternateDataStreams: C:\ProgramData\Temp:EC2E1DEC

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== Other Registry Areas =====================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3192508786-2493758777-3291605813-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== Accounts: =============================

Administrator (S-1-5-21-3192508786-2493758777-3291605813-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-3192508786-2493758777-3291605813-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: ehdrv
Description: ehdrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ehdrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (02/05/2015 09:31:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 09:52:07 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {0b5a2c52-3eb9-470a-96e2-6c6d4570e40f} and name VssSnapshotMgmt cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]

Error: (02/04/2015 09:44:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 05:34:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 02:17:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 03:43:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 06:08:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:24:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:48:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:41:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

System errors:
=============
Error: (02/05/2015 09:30:52 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (02/05/2015 09:30:52 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Microsoft Office Sessions:
=========================
Error: (02/05/2015 09:31:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 09:52:07 PM) (Source: VSS) (EventID: 18) (User: )
Description: {0b5a2c52-3eb9-470a-96e2-6c6d4570e40f}VssSnapshotMgmt0x8007043c, This service cannot be started in Safe Mode

Error: (02/04/2015 09:44:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 05:34:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 02:17:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 03:43:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 06:08:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:24:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:48:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:41:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

CodeIntegrity Errors:
===================================
  Date: 2014-06-11 10:14:07.328
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-06-11 10:14:07.280
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-06-11 10:14:06.795
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-06-11 10:14:06.747
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-06-11 10:14:06.182
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-06-11 10:14:06.134
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-12-22 03:34:27.103
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Crack\Quick Unpack\Engine.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-12-22 03:34:27.058
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Crack\Quick Unpack\Engine.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: AMD A8-3870 APU with Radeon™ HD Graphics
Percentage of memory in use: 20%
Total physical RAM: 3553.42 MB
Available physical RAM: 2816.4 MB
Total Pagefile: 7105.02 MB
Available Pagefile: 6403.41 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Disk) (Fixed) (Total:50.01 GB) (Free:17.03 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Disk) (Fixed) (Total:400.03 GB) (Free:46.45 GB) NTFS
Drive e: (Disk) (Fixed) (Total:15.72 GB) (Free:5.8 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 11012125)
Partition 1: (Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=15.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=400 GB) - (Type=OF Extended)

==================== End Of Log ============================

 



BC AdBot (Login to Remove)

 


m

#2 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 05 February 2015 - 11:48 PM

Please! no one can help?

 

I perused my infection story and submit an encrypted JPEG with original one.

 

I checked hex of some encrypted files and compared to originals, cryptor has changed bits just till 7520 offset and added 4 extra hex at the end of files. It seems simple :unsure:

 

Also i found these files and folders at %USER%APPDATA%LOCAL% :

 

EmieBrowserModeList/container.dat

EmieSiteList/container.dat

EmieUserList/container.dat

 

and see some folder state has been changed to SHARED.

 

And also remembered i cleaned registry one one day ago, before using FRST. 

 

After infection till now i'm using safe mode and checked my system with RogueKiller and JRT, no critical issue!

 

Thanks in advance



#3 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 06 February 2015 - 11:51 PM

Any idea?

 

I want to restore quarantine and registry keys and start Windows and Chrome to let trojan start infection again.

Maybe by this way can this time find crypter. Has it any profit? or this time crypter use a different key?

 

I checked modification date of encrypted files, this crypter has encrypted more than 120gb at only 5min!



#4 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,549 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:44 AM

Posted 10 February 2015 - 02:35 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/565757 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#5 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 10 February 2015 - 06:50 AM

As i discribed my problem was a cryptor attack that encrypt all kind of files, it encrypt firt 30kb of files and add 4 extra random bit to the end of files. this infection seems a new kind of decode@india that after locking all files on all logical drive with a commad prompt window tell to victim for getting unlocker and code email to fud@india.com

After infection there is a pagefile.sys in each logical drive. I hope unlocking code can be recover from that.

Unfortunately or luckily i killed encryption process before lost all files as i discribed. So main cryptor is missing. I emailed them, they said "send us an encrypted file, we unlock it and send back to you, then pay 2 Bitcoins to get Unlocker and Code"
I sent sample file but till now they have not answered. Also their pay method is unknown.

After this story i'm using safe mode and has not changed OS. My problem is restoring files, now FRST log is clear and my first FRST log is Here:

========
FRST LOG
========
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2015 01
Ran by Administrator (administrator) on PC on 06-02-2015 22:11:46
Running from C:\Users\Administrator\Desktop\New folder
Loaded Profiles: Administrator (Available profiles: Administrator)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(PortableXapps®) C:\Users\Administrator\Desktop\SUPERAntiSpywarePortable\SUPERAntiSpywarePortable.exe
(SUPERAntiSpyware.com) C:\Users\Administrator\Desktop\SUPERAntiSpywarePortable\App\SUPERAntiSpyware\PROGRAM64.COM


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [SoftEther VPN Client UI Helper] => C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [4408888 2015-02-03] (SoftEther VPN Project at University of Tsukuba, Japan.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [2918656 2015-02-03] (ESET)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [224128 2014-03-18] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM\...\RunOnce: [GrpConv] => grpconv -o
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Run: [xwidget] => D:\Portable\XWidget\xwidget.exe [1858048 2014-09-03] (xwidget.com)
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Run: [NetLimiter] => C:\Program Files\NetLimiter 3\NLClientApp.exe [2910208 2011-03-21] (Locktime Software)
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3886672 2014-12-16] (Tonec Inc.)
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[S1].txt
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Policies\Explorer: [NoSecurityTab] 0
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Policies\Explorer: [NoControlPanel] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDSentinel.lnk
ShortcutTarget: HDSentinel.lnk -> D:\Portable\HDD BOOT\Hard Disk Sentinel\HDSentinel.exe (H.D.S. Hungary)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\JalaliCalendar.lnk
ShortcutTarget: JalaliCalendar.lnk -> D:\Portable\JalaliCalendar\JalaliCalendar46.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RocketDock.lnk
ShortcutTarget: RocketDock.lnk -> D:\Portable\RocketDock\RocketDock.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SoftEther VPN Client Manager Startup.lnk
ShortcutTarget: SoftEther VPN Client Manager Startup.lnk -> C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Speedfan.lnk
ShortcutTarget: Speedfan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3192508786-2493758777-3291605813-500\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3192508786-2493758777-3291605813-500 -> {56064A0F-55FB-4C37-8108-6CF543751103} URL = http://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
BHO: No Name -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> No File
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre8\bin\ssv.dll (Oracle Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\d5qxbs0x.default
FF Plugin: @java.com/DTPlugin,version=11.5.2 -> C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.5.2 -> C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2015-02-03]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Administrator\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Administrator\AppData\Roaming\IDM\idmmzcc5 [2015-01-09]
FF HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Administrator\AppData\Roaming\IDM\idmmzcc5

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-12-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-11-20] (Advanced Micro Devices, Inc.) [File not signed]
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42360 2011-01-12] (ESET)
S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810144 2011-01-12] (ESET)
S2 MBAMService; D:\Portable\Malwarebytes\App\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 MPlayerWWService; D:\Portable\MEDIA PLAYER\MPlayer\tools\MPlayerWWService.exe [11776 2014-07-09] () [File not signed]
S2 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1845248 2011-03-21] (Locktime Software) [File not signed]
S2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [4408888 2015-02-03] (SoftEther VPN Project at University of Tsukuba, Japan.)
S2 Themes; C:\Windows\system32\themeservice.dll [44544 2013-07-28] (Microsoft Corporation) [File not signed]
S2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.)
S2 WinArchiver Service; C:\Program Files\WinArchiver\WAService.exe [257336 2014-12-19] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 MBAMScheduler; "\mbamscheduler.exe" [X]
S2 nlsX86cc; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AODDriver4.2.0; No ImagePath
S2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 DCamUSBEMPIA; C:\Windows\System32\DRIVERS\emDevice64.sys [215808 2007-06-21] (eMPIA Technology, Inc.) [File not signed]
S3 DIRECTIO; D:\Portable\Benchmark\Passmark PerformanceTest\DirectIo64.sys [31160 2014-04-24] ()
S2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
S3 emAudio; C:\Windows\System32\drivers\emAudio64.sys [79872 2007-08-31] (eMPIA Technology, Inc.) [File not signed]
S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [170640 2010-12-21] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
S2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2010-12-21] (ESET)
S3 FiltUSBEMPIA; C:\Windows\System32\DRIVERS\emFilter64.sys [6400 2007-06-21] (eMPIA Technology, Inc.) [File not signed]
S3 GPU-Z; No ImagePath
S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus64.sys [261120 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-03] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
S3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-14] (Microsoft Corporation)
S3 Neo_GAT; C:\Windows\System32\DRIVERS\Neo_0035.sys [28768 2013-09-19] (SoftEther Project at University of Tsukuba, Japan.)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0027.sys [28768 2013-09-20] (SoftEther Project at University of Tsukuba, Japan.)
R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [88200 2011-03-21] (Locktime Software)
S3 SANDRA; No ImagePath
S1 SASDIFSV; C:\Users\Administrator\Desktop\SUPERAntiSpywarePortable\App\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Users\Administrator\Desktop\SUPERAntiSpywarePortable\App\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ScanUSBEMPIA; C:\Windows\System32\DRIVERS\emScan64.sys [6144 2007-06-21] (eMPIA Technology, Inc.) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2013-11-18] (Duplex Secure Ltd.)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-07-08] (Spotflux, Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [37624 2015-02-05] ()
S3 VMfilt; C:\Windows\System32\drivers\VMfilt64.sys [25600 2009-07-31] (Creative Technology Ltd.)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [142096 2014-12-19] (Power Software Ltd)
S3 Winachcf; C:\Windows\System32\DRIVERS\winaxhcf.sys [1254912 2006-07-27] (Conexant)
S3 AxtuDrv; \??\C:\Windows\SysWOW64\Drivers\AxtuDrv.sys [X]
S3 Ndisrd; system32\DRIVERS\ndisrd.sys [X]
S3 NdisrdMP; system32\DRIVERS\ndisrd.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-06 21:55 - 2015-02-06 22:01 - 209715200 ____H () C:\Users\Administrator\Desktop\6605.part1.rar
2015-02-06 21:43 - 2015-02-06 21:55 - 85524055 _____ () C:\Users\Administrator\Desktop\6606.part3.rar
2015-02-06 21:42 - 2015-02-06 21:43 - 06365048 _____ (Tonec Inc.) C:\Users\Administrator\Desktop\idman622f.exe
2015-02-06 21:09 - 2015-02-06 21:42 - 209715200 _____ () C:\Users\Administrator\Desktop\6606.part2.rar
2015-02-06 07:18 - 2015-02-06 07:18 - 00000000 ____D () C:\Users\Administrator\Desktop\EmergencyKitPortable
2015-02-06 06:34 - 2015-02-06 06:35 - 00000000 ____D () C:\Users\Administrator\Desktop\SpyHunter
2015-02-05 20:47 - 2015-02-06 22:12 - 00000000 ____D () C:\Users\Administrator\Desktop\New folder
2015-02-05 20:17 - 2015-02-05 21:11 - 00037624 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2015-02-05 20:17 - 2015-02-05 20:17 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-02-05 16:22 - 2015-02-05 16:22 - 00000000 ____D () C:\Users\Administrator\Desktop\R-StudioPortable
2015-02-05 13:52 - 2015-02-05 13:52 - 00001123 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-05 13:52 - 2015-02-05 13:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-05 10:20 - 2015-02-06 22:11 - 00000000 ____D () C:\FRST
2015-02-05 09:50 - 2015-02-05 20:50 - 00000000 ____D () C:\ProgramData\ParetoLogic
2015-02-05 09:50 - 2015-02-05 20:50 - 00000000 ____D () C:\Program Files (x86)\ParetoLogic
2015-02-05 09:50 - 2015-02-05 16:15 - 00000000 _____ () C:\FileRecovery.log
2015-02-04 09:27 - 2015-02-06 22:11 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
2015-02-04 09:27 - 2015-02-06 22:11 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-02-04 08:50 - 2015-02-05 20:16 - 00000000 ____D () C:\Program Files\stinger
2015-02-04 08:17 - 2015-02-04 08:17 - 00000000 ____D () C:\Users\Administrator\Desktop\Enigma Software Group
2015-02-04 07:20 - 2015-02-04 07:20 - 00000000 ____D () C:\Users\Administrator\Desktop\Tor Browser
2015-02-03 18:28 - 2015-02-06 19:10 - 00000000 ____D () C:\Users\Administrator\Desktop\1
2015-02-03 17:50 - 2015-02-03 17:50 - 00000000 ____D () C:\Users\Administrator\Desktop\SUPERAntiSpywarePortable
2015-02-03 16:55 - 2015-02-04 05:51 - 00000000 ____D () C:\Users\Administrator\Desktop\ClamWinPortable
2015-02-03 16:50 - 2015-02-03 16:50 - 00000000 ____D () C:\Users\Administrator\Desktop\TDSSKillerPortable
2015-02-03 12:43 - 2015-02-03 12:43 - 00000000 ____D () C:\Users\Administrator\Desktop\AdwCleanerPortable
2015-02-03 12:11 - 2015-02-03 12:11 - 00000000 ____D () C:\Users\Administrator\Desktop\Stinger64Portable
2015-02-03 10:38 - 2015-02-03 10:38 - 00000000 ____D () C:\Quarantine
2015-02-03 07:33 - 2015-02-03 16:41 - 00000000 ____D () C:\Users\Administrator\Desktop\StingerPortable
2015-02-03 07:33 - 2015-02-03 13:46 - 00000000 ____D () C:\Stinger_Quarantine
2015-02-03 05:25 - 2015-02-03 05:25 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-03 05:25 - 2015-02-03 05:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-03 05:25 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-03 05:25 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-03 03:51 - 2015-02-03 03:51 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ESET
2015-02-03 03:51 - 2015-02-03 03:51 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ESET
2015-02-03 03:50 - 2015-02-03 03:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-02-03 03:50 - 2015-02-03 03:50 - 00000000 ____D () C:\ProgramData\ESET
2015-02-03 03:50 - 2015-02-03 03:50 - 00000000 ____D () C:\Program Files\ESET
2015-02-03 01:42 - 2014-12-19 06:36 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-02-03 01:42 - 2014-12-19 05:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-02-03 01:42 - 2014-12-12 09:05 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-03 01:42 - 2014-12-12 09:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-03 01:42 - 2014-12-12 09:01 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-03 01:42 - 2014-12-12 09:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-03 01:42 - 2014-12-12 08:41 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-03 01:42 - 2014-12-12 08:41 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-03 01:42 - 2014-12-12 08:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-03 01:42 - 2014-12-11 21:17 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-02-03 01:42 - 2014-12-06 07:47 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-02-03 01:42 - 2014-12-06 07:20 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-02-03 01:42 - 2014-12-06 07:20 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-02-03 01:23 - 2015-02-03 01:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client
2015-01-30 10:48 - 2015-01-30 10:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Obsidium
2015-01-30 10:48 - 2015-01-30 10:48 - 00000000 ____D () C:\ProgramData\BolideSoftware
2015-01-29 01:19 - 2015-01-29 01:19 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\2416
2015-01-28 21:08 - 2012-02-11 01:46 - 00017920 ___SH () C:\Users\Administrator\Desktop\Thumbs.db
2015-01-27 06:36 - 2015-01-27 06:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\24677
2015-01-22 11:00 - 2015-01-24 07:10 - 00000000 ____D () C:\ProgramData\Licenses
2015-01-22 11:00 - 2015-01-22 11:00 - 00000000 ____D () C:\Users\Administrator\Documents\VideoReDo
2015-01-20 18:03 - 2015-01-20 18:03 - 00000000 ____D () C:\ProgramData\Yahoo!
2015-01-16 15:02 - 2015-01-16 15:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SubtitleCreator
2015-01-16 00:35 - 2015-01-16 20:10 - 00000000 ____D () C:\Users\Administrator\Documents\ConvertXtoDVD
2015-01-15 16:07 - 2015-01-15 16:08 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\JPEGminiPro
2015-01-09 15:55 - 2015-01-09 16:21 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\IDM
2015-01-09 15:55 - 2015-01-09 15:56 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
2015-01-09 15:55 - 2015-01-09 15:55 - 00000000 ____D () C:\Users\Administrator\Downloads\Video
2015-01-09 15:55 - 2015-01-09 15:55 - 00000000 ____D () C:\Users\Administrator\Downloads\Compressed
2015-01-09 15:55 - 2015-01-09 15:55 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-01-09 15:55 - 2015-01-09 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-06 22:12 - 2013-07-28 10:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NetSpeedMonitor
2015-02-06 17:30 - 2013-08-01 04:38 - 00000000 ____D () C:\ProgramData\Temp
2015-02-06 08:13 - 2013-10-03 00:33 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ChemTable Software
2015-02-05 13:53 - 2014-03-01 15:22 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2015-02-03 18:06 - 2014-05-05 19:28 - 00062920 _____ () C:\Windows\PFRO.log
2015-02-03 14:10 - 2009-07-14 08:43 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-03 04:25 - 2013-07-28 08:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DMCache
2015-02-03 04:25 - 2013-07-28 06:47 - 01312667 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 04:25 - 2009-07-14 08:15 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 04:25 - 2009-07-14 08:15 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 04:23 - 2014-05-05 19:28 - 00029296 _____ () C:\Windows\setupact.log
2015-02-03 04:22 - 2013-09-20 01:51 - 00000000 ____D () C:\Program Files\SoftEther VPN Client
2015-02-03 04:21 - 2014-02-28 15:03 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2015-02-03 04:21 - 2009-07-14 08:38 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 01:44 - 2013-07-28 05:53 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-03 01:42 - 2013-07-28 01:01 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-03 01:23 - 2013-09-20 01:51 - 00135736 _____ (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Windows\system32\vpncmd.exe
2015-02-03 01:23 - 2013-09-20 01:51 - 00001943 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk
2015-02-03 01:10 - 2013-07-27 19:55 - 00767492 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-02-02 04:49 - 2014-11-26 00:07 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\HandBrake
2015-01-31 23:52 - 2013-08-09 12:14 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2015-01-30 10:48 - 2009-07-14 06:04 - 00000624 _____ () C:\Windows\win.ini
2015-01-19 19:10 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-19 00:27 - 2013-08-10 01:46 - 00000000 ____D () C:\Program Files (x86)\FlashGet
2015-01-16 19:14 - 2014-08-18 03:22 - 00000000 ____D () C:\ProgramData\VSO
2015-01-10 18:04 - 2013-07-27 19:25 - 00000000 ____D () C:\Users\Administrator

==================== Files in the root of some directories =======

2013-10-14 06:14 - 2013-10-14 06:14 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2014-01-24 20:12 - 2014-01-24 21:28 - 0000132 _____ () C:\Users\Administrator\AppData\Roaming\Adobe BMP Format CS5 Prefs
2013-07-29 00:12 - 2014-06-26 19:23 - 0000132 _____ () C:\Users\Administrator\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-07-12 09:25 - 2014-07-12 09:25 - 0000113 ___SH () C:\Users\Administrator\AppData\Local\00000114
2014-09-23 23:06 - 2014-09-23 23:06 - 0000600 _____ () C:\Users\Administrator\AppData\Local\PUTTY.RND
2013-10-23 03:56 - 2013-11-18 01:50 - 0000083 ___SH () C:\ProgramData\.zreglib
2014-08-04 23:06 - 2014-08-04 23:06 - 0000008 __RSH () C:\ProgramData\sysqcl1131236454.dat

Files to move or delete:
====================
C:\ProgramData\sysqcl1131236454.dat


Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\dllnt_dump.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

========
Addition
========
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2015 01
Ran by Administrator at 2015-02-05 10:22:07
Running from C:\Users\Administrator\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 4.2 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET Smart Security 4.2 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall (Enabled) {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\uTorrent) (Version: 3.4.2.33870 - BitTorrent Inc.)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.125 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ASRock eXtreme Tuner v0.1.94 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version: - )
BitTorrent (HKU\S-1-5-21-3192508786-2493758777-3291605813-500\...\BitTorrent) (Version: 7.9.2.33876 - BitTorrent Inc.)
Canon MP Navigator EX 2.1 (HKLM-x32\...\MP Navigator EX 2.1) (Version: - )
CanoScan LiDE 700F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ9601) (Version: - )
CopyFilenames 3.1 (HKLM\...\CopyFilenames_is1) (Version: 3.1 - ExtraBit Software)
CyberGhost 5 (HKLM\...\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.)
Data Recovery Pro (HKLM-x32\...\{B1C2398C-6FAB-46D1-806C-5942F0829994}) (Version: 2.1.0.0 - ParetoLogic, Inc.)
Earth Alerts (HKLM-x32\...\{4C892B5B-3F19-4FF4-B3CC-B746DB646C1F}) (Version: 14.1.130 - South Wind Technologies)
ESET Smart Security (HKLM\...\{C0D93E4E-0866-43C8-A104-BF41A803EA84}) (Version: 4.2.71.2 - ESET, spol. s r.o.)
FlashGet(JetCar) (HKLM-x32\...\FlashGet(JetCar)) (Version: - )
Folder Marker Free (HKLM\...\Folder Marker Free_is1) (Version: 4.2 - ArcticLine Software)
FUJIFILM MyFinePix Studio 4.2a (HKLM-x32\...\MyFinePix Studio_is1) (Version: - )
HashCheck Shell Extension (x86-32) (HKLM-x32\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
HashCheck Shell Extension (x86-64) (HKLM\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.)
iSpy (HKLM-x32\...\{E05C738C-1CA9-4E80-B44F-B31E2F44CEA3}) (Version: 5.6.5 - iSpy)
Java 8 Update 5 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418005FF}) (Version: 8.0.50 - Oracle Corporation)
Java 8 Update 5 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218005FF}) (Version: 8.0.50 - Oracle Corporation)
Microsoft .NET Framework 4.5.2 Hotfix Rollup (KB3011114) (HKLM\...\{8AB1C38E-8622-3F81-B3D8-C5DD2D70830E}) (Version: 4.5.52279 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (HKLM\...\{3C28BFD4-90C7-3138-87EF-418DC16E9598}) (Version: 11.0.51106 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (HKLM\...\{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}) (Version: 11.0.51106 - Microsoft Corporation)
NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software s.r.o.)
NetSpeedMonitor 2.5.4.0 x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: 2.5.4.0 - Florian Gilles)
novaPDF Professional Desktop 7.7 printer (HKLM\...\novaPDF Professional Desktop 7 printer_is1) (Version: 7.7.394 - Softland)
Platform (x32 Version: 1.36 - VIA Technologies, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.14.9529 - SoftEther VPN Project)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TaskmgrPro V1.4.5 (HKLM\...\TaskmgrPro_is1) (Version: - GoldGingko Software)
Theme Resource Changer X64 v1.0 (HKLM\...\Theme Resource Changer X64 v1.0) (Version: - Bad Ass Apps)
THX TruStudio (HKLM-x32\...\{AFB907F5-C0E6-4753-8284-DE955EF86AC2}) (Version: 1.00.01 - Creative Technology Limited)
Types (HKLM\...\Types) (Version: 2.1.1 - E. Strunnikov)
VBA (2627.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.)
Weather Watcher Live (HKLM-x32\...\{98FDC595-92B3-48D5-80D6-FE7AABD9191B}_is1) (Version: Weather Watcher Live (Build: 3/17/14) - Singer's Creations)
WinArchiver (HKLM-x32\...\WinArchiver) (Version: 3.7 - Power Software Ltd)
Windows Deployment Tools (HKLM-x32\...\{FEA31583-30A7-0951-718C-AF75DCB003B1}) (Version: 8.100.25984 - Microsoft)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
Zan Image Printer (HKLM\...\zvprt50) (Version: - )
Zling HCF V.90 Speakerphone PCI Modem (HKLM\...\CXT1056) (Version: - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3192508786-2493758777-3291605813-500_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> D:\Portable\MediaInfo\MediaInfo_InfoTip.dll (http://MediaArea.net/MediaInfo)

==================== Restore Points =========================

ATTENTION: System Restore is disabled.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-09-14 19:20 - 2015-02-04 05:35 - 00000080 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 martau.com total-uninstall.com
127.0.0.1 license.superantispyware.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01767C1E-4E42-409B-AC98-88F8375E840B} - System32\Tasks\{F1B17328-CEC2-4A19-850D-1D02900D4E83} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2010 x64 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: {714C9CD0-A6D2-4B61-91F3-27F2F487E017} - System32\Tasks\{804625CF-BAEC-4D45-B0DD-C0E5787E0CD5} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2008 x86 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: {99C9036A-7593-4A20-B687-5ADDE8B7A32A} - System32\Tasks\{B5EBED75-55ED-4E33-B407-96709489D3DC} => pcalua.exe -a C:\Users\Administrator\Desktop\FlashGetPortable\FlashGetPortable.exe -d C:\Users\Administrator\Desktop\FlashGetPortable
Task: {9E326901-3285-4CD1-8B8D-154CF2F87F77} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {AACDE4E9-D0D5-4D03-9D77-B4FEAB00D7B0} - System32\Tasks\{85986AA8-1E97-477A-9EE2-057D572761F7} => pcalua.exe -a "D:\Software\Microsoft\Visual C++ Redistributable\VCRedist 2010 x86 SP1.exe" -d "D:\Software\Microsoft\Visual C++ Redistributable"
Task: C:\Windows\Tasks\ParetoLogic Registration3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\UUS3.dll

==================== Loaded Modules (whitelisted) ==============


==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows\win.ini:s1
AlternateDataStreams: C:\Users\Administrator\Cookies:KHXvOrekXH5qyOhfDoGTGALe98
AlternateDataStreams: C:\Users\Administrator\Local Settings:init
AlternateDataStreams: C:\Users\Administrator\Local Settings:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\ProgramData\Microsoft:olXsEwmMswjyX3V1RWskBwY0SZ
AlternateDataStreams: C:\ProgramData\Microsoft:xRlz20fmPhmNWamwAD8w
AlternateDataStreams: C:\ProgramData\Temp:0888F409
AlternateDataStreams: C:\ProgramData\Temp:1677AB3F
AlternateDataStreams: C:\ProgramData\Temp:3440EB47
AlternateDataStreams: C:\ProgramData\Temp:58A5270D
AlternateDataStreams: C:\ProgramData\Temp:66633281
AlternateDataStreams: C:\ProgramData\Temp:6DAA43DB
AlternateDataStreams: C:\ProgramData\Temp:8FAE08A5
AlternateDataStreams: C:\ProgramData\Temp:93433455
AlternateDataStreams: C:\ProgramData\Temp:9E00596C
AlternateDataStreams: C:\ProgramData\Temp:BF3D62E7
AlternateDataStreams: C:\ProgramData\Temp:C7D0F96D
AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9
AlternateDataStreams: C:\ProgramData\Temp:CF54F1CA
AlternateDataStreams: C:\ProgramData\Temp:D8999815
AlternateDataStreams: C:\ProgramData\Temp:E36A723B
AlternateDataStreams: C:\ProgramData\Temp:EC2E1DEC

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Registry Areas =====================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3192508786-2493758777-3291605813-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3192508786-2493758777-3291605813-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-3192508786-2493758777-3291605813-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: ehdrv
Description: ehdrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ehdrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/05/2015 09:31:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 09:52:07 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {0b5a2c52-3eb9-470a-96e2-6c6d4570e40f} and name VssSnapshotMgmt cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]

Error: (02/04/2015 09:44:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 05:34:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 02:17:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 03:43:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 06:08:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:24:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:48:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:41:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/05/2015 09:30:52 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (02/05/2015 09:30:52 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (02/05/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (02/05/2015 09:31:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 09:52:07 PM) (Source: VSS) (EventID: 18) (User: )
Description: {0b5a2c52-3eb9-470a-96e2-6c6d4570e40f}VssSnapshotMgmt0x8007043c, This service cannot be started in Safe Mode

Error: (02/04/2015 09:44:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 05:34:52 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 02:17:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 03:43:04 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 06:08:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:24:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:48:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 04:41:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
Date: 2014-06-11 10:14:07.328
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2014-06-11 10:14:07.280
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2014-06-11 10:14:06.795
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2014-06-11 10:14:06.747
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2014-06-11 10:14:06.182
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2014-06-11 10:14:06.134
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Driver\Hardware\Overclock\WCPUID v3.3\nrkctl32.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-12-22 03:34:27.103
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Crack\Quick Unpack\Engine.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-12-22 03:34:27.058
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Software\Crack\Quick Unpack\Engine.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD A8-3870 APU with Radeon™ HD Graphics
Percentage of memory in use: 20%
Total physical RAM: 3553.42 MB
Available physical RAM: 2816.4 MB
Total Pagefile: 7105.02 MB
Available Pagefile: 6403.41 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Disk) (Fixed) (Total:50.01 GB) (Free:17.03 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Disk) (Fixed) (Total:400.03 GB) (Free:46.45 GB) NTFS
Drive e: (Disk) (Fixed) (Total:15.72 GB) (Free:5.8 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 11012125)
Partition 1: (Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=15.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=400 GB) - (Type=OF Extended)

==================== End Of Log ============================

Edited by alir32a, 10 February 2015 - 06:56 AM.


#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,532 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:44 AM

Posted 12 February 2015 - 10:28 AM

Greetings alir32a and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that. :thumbup2:

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Unfortunately there is no way for us to decrypt your files.

If you would like to continue to clean your computer please consider and run the below for me.

===================================================

P2P Warning

--------------------

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .

If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> No File
S2 MBAMScheduler; "\mbamscheduler.exe" [X]
S2 nlsX86cc; No ImagePath
S2 AODDriver4.2.0; No ImagePath
S3 GPU-Z; No ImagePath
S3 SANDRA; No ImagePath
S3 AxtuDrv; \??\C:\Windows\SysWOW64\Drivers\AxtuDrv.sys [X]
S3 Ndisrd; system32\DRIVERS\ndisrd.sys [X]
S3 NdisrdMP; system32\DRIVERS\ndisrd.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2014-07-12 09:25 - 2014-07-12 09:25 - 0000113 ___SH () C:\Users\Administrator\AppData\Local\00000114
2014-09-23 23:06 - 2014-09-23 23:06 - 0000600 _____ () C:\Users\Administrator\AppData\Local\PUTTY.RND
2013-10-23 03:56 - 2013-11-18 01:50 - 0000083 ___SH () C:\ProgramData\.zreglib
2014-08-04 23:06 - 2014-08-04 23:06 - 0000008 __RSH () C:\ProgramData\sysqcl1131236454.dat
C:\Users\Administrator\AppData\Local\Temp\dllnt_dump.dll
AlternateDataStreams: C:\Windows\win.ini:s1
AlternateDataStreams: C:\Users\Administrator\Cookies:KHXvOrekXH5qyOhfDoGTGALe98
AlternateDataStreams: C:\Users\Administrator\Local Settings:init
AlternateDataStreams: C:\Users\Administrator\Local Settings:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:init
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:r8x0wTYDTA60cmWC73H3yi18Z
AlternateDataStreams: C:\ProgramData\Microsoft:olXsEwmMswjyX3V1RWskBwY0SZ
AlternateDataStreams: C:\ProgramData\Microsoft:xRlz20fmPhmNWamwAD8w
AlternateDataStreams: C:\ProgramData\Temp:0888F409
AlternateDataStreams: C:\ProgramData\Temp:1677AB3F
AlternateDataStreams: C:\ProgramData\Temp:3440EB47
AlternateDataStreams: C:\ProgramData\Temp:58A5270D
AlternateDataStreams: C:\ProgramData\Temp:66633281
AlternateDataStreams: C:\ProgramData\Temp:6DAA43DB
AlternateDataStreams: C:\ProgramData\Temp:8FAE08A5
AlternateDataStreams: C:\ProgramData\Temp:93433455
AlternateDataStreams: C:\ProgramData\Temp:9E00596C
AlternateDataStreams: C:\ProgramData\Temp:BF3D62E7
AlternateDataStreams: C:\ProgramData\Temp:C7D0F96D
AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9
AlternateDataStreams: C:\ProgramData\Temp:CF54F1CA
AlternateDataStreams: C:\ProgramData\Temp:D8999815
AlternateDataStreams: C:\ProgramData\Temp:E36A723B
AlternateDataStreams: C:\ProgramData\Temp:EC2E1DEC
Hosts:
cmd: dir C:\Users\Administrator\AppData\Roaming\2416 /s
cmd: dir C:\Users\Administrator\AppData\Roaming\24677 /s
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply. If it is too large attach it to your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • System Summary Information
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 14 February 2015 - 04:56 PM

Hi Oh My!

Thank you for response!

I couldn't wait any more after my last post, so i installed a new fresh OS! :blush:

 

Before that to find origin of attack, i let infection activate again, as i said my chrome contained some unknown PUP and the attack happened again, My ip changed and system remoted and the story again ... and finally couldn't find any treat or issue ... in this case Antivirus or Internet Security softwares are bootless!

 

About P2P, naturally you're right!

 

Thank you and thank bleepingcomputer



#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,532 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:44 AM

Posted 14 February 2015 - 05:10 PM

Sorry it took a few days to respond, we are a bit busy. It is always the best course of action to reformat and reinstall the operating system after an infection like that.

Let me at least leave you with some information to consider as you try to keep your computer clean.

===================================================

Keeping Your Computer Safe

----------

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read: Simple and easy ways to keep your computer safe and secure on the Internet.

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:In addition, here are some more links you might find of interest:Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. OhMy_done.gif
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 15 February 2015 - 03:58 AM

I'm really confured :angry:

Just 3~5 hours after a fresh installation OS, without any P2P, again infection :angry:

It seems a hacker trace my PC or ...



#10 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 15 February 2015 - 04:03 AM

New FRST LOG

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-02-2015 02
Ran by Administrator (administrator) on PC on 15-02-2015 11:24:12
Running from D:\Software\Anti Virus & Spy\Farbar
Loaded Profiles: Administrator (Available profiles: Administrator)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5199984 2011-06-20] (VIA)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5199984 2011-06-20] (VIA)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-07-30] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM\...\RunOnce: [RemoveSRS] => Msiexec /x {E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049} /quiet
HKU\S-1-5-21-3665659012-2591172732-1161553720-500\...\Run: [xwidget] => D:\Portable\XWidget\xwidget.exe [1858048 2014-09-03] (xwidget.com)
HKU\S-1-5-21-3665659012-2591172732-1161553720-500\...\Run: [TaskmgrPro] => C:\Program Files\TaskmgrPro\TaskmpStart.exe [92504 2013-09-05] ()
HKU\S-1-5-21-3665659012-2591172732-1161553720-500\...\Run: [NetLimiter] => C:\Program Files\NetLimiter 3\NLClientApp.exe [2910208 2011-03-21] (Locktime Software)
HKU\S-1-5-21-3665659012-2591172732-1161553720-500\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-02-06] (Tonec Inc.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDSentinel.lnk
ShortcutTarget: HDSentinel.lnk -> D:\Portable\HDD BOOT\Hard Disk Sentinel\HDSentinel.exe (H.D.S. Hungary)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JalaliCalendar.lnk
ShortcutTarget: JalaliCalendar.lnk -> D:\Portable\JalaliCalendar\JalaliCalendar46.exe ()
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RocketDock.lnk
ShortcutTarget: RocketDock.lnk -> D:\Portable\RocketDock\RocketDock.exe ()
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpeedFan.lnk
ShortcutTarget: SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com))
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3665659012-2591172732-1161553720-500\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3665659012-2591172732-1161553720-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-3665659012-2591172732-1161553720-500 -> {16B3ABFA-60E2-4857-92EC-CD158F221036} URL = https://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF HKU\S-1-5-21-3665659012-2591172732-1161553720-500\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Administrator\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Administrator\AppData\Roaming\IDM\idmmzcc5 [2015-02-14]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-02-06]
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-02-06]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
S2 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1845248 2011-03-21] (Locktime Software) [File not signed]
S2 Themes; C:\Windows\system32\themeservice.dll [44544 2015-02-14] (Microsoft Corporation) [File not signed]
S2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.)
S2 WinArchiver Service; C:\Program Files\WinArchiver\WAService.exe [257336 2014-12-19] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-02-12] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [88200 2011-03-21] (Locktime Software)
S3 VMfilt; C:\Windows\System32\drivers\VMfilt64.sys [25600 2009-07-31] (Creative Technology Ltd.)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [142096 2014-12-19] (Power Software Ltd)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-15 11:24 - 2015-02-15 11:24 - 00000000 ____D () C:\FRST
2015-02-15 11:13 - 2015-02-15 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA
2015-02-15 11:12 - 2015-02-15 11:12 - 00000000 ____D () C:\Windows\system32\SRSLabs
2015-02-15 11:12 - 2015-02-15 11:12 - 00000000 ____D () C:\Program Files\VIA
2015-02-15 11:12 - 2012-10-22 12:14 - 02994808 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIAPropPageExt.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 01161336 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaKaraokeApo.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 01119352 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaMicArrayAPO.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 00683640 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIASysFx.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 00123512 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaKaraokePropPageExt.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 00095352 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaMicArrayPropPageExt.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 00070776 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\VtSrdAPO.dll
2015-02-15 11:12 - 2012-10-22 12:14 - 00027768 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViakaraokeSrv.exe
2015-02-15 11:12 - 2012-10-22 12:13 - 00248952 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\Dts2APO.dll
2015-02-15 11:12 - 2012-10-22 12:13 - 00092280 _____ (VIA Technologies, Inc.) C:\Windows\system32\Dts2PropPageExt.dll
2015-02-15 11:12 - 2012-10-22 12:13 - 00055416 _____ (TODO: <Company name>) C:\Windows\system32\PropPageExt.dll
2015-02-15 11:12 - 2012-09-24 12:03 - 03141496 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVIA64.dll
2015-02-15 11:12 - 2012-09-24 12:02 - 02080120 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2015-02-15 11:12 - 2012-09-05 12:42 - 00860024 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-02-15 11:12 - 2012-07-15 08:46 - 00394104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-02-15 11:12 - 2012-06-28 12:24 - 00086016 _____ (QSound Labs, Inc.) C:\Windows\system32\nQPropPageExt.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 07163744 _____ (Dolby Laboratories) C:\Windows\system32\EEP64H.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\EED64H.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\EED64A.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00137056 _____ (Dolby Laboratories) C:\Windows\system32\EEL64H.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00137056 _____ (Dolby Laboratories) C:\Windows\system32\EEL64A.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00120160 _____ (Dolby Laboratories) C:\Windows\system32\EEA64H.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00120160 _____ (Dolby Laboratories) C:\Windows\system32\EEA64A.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00075104 _____ (Dolby Laboratories) C:\Windows\system32\EEG64H.dll
2015-02-15 11:12 - 2011-12-15 08:46 - 00075104 _____ (Dolby Laboratories) C:\Windows\system32\EEG64A.dll
2015-02-15 11:12 - 2011-09-27 13:43 - 00879616 _____ (Creative Technology Ltd.) C:\Windows\system32\VMAPO64.DLL
2015-02-15 11:12 - 2011-09-27 13:43 - 00739328 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMAPO32.DLL
2015-02-15 11:12 - 2011-09-27 13:43 - 00619520 _____ (Creative Technology Ltd.) C:\Windows\system32\VMTHX64.DLL
2015-02-15 11:12 - 2011-09-27 13:43 - 00554496 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMTHX32.DLL
2015-02-15 11:12 - 2011-09-27 13:43 - 00057856 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPLD64.DLL
2015-02-15 11:12 - 2011-06-08 13:49 - 00083968 _____ (QSound Labs, Inc.) C:\Windows\system32\nQAPO.dll
2015-02-15 11:08 - 2011-12-15 08:46 - 07163744 _____ (Dolby Laboratories) C:\Windows\system32\EEP64A.dll
2015-02-15 05:02 - 2015-02-15 05:03 - 02452205 _____ () C:\Users\Administrator\Desktop\ipfilter1712.7z
2015-02-15 00:47 - 2015-02-15 02:04 - 00000760 _____ () C:\Users\Administrator\Desktop\New Text Document.txt
2015-02-14 21:03 - 2015-02-14 22:01 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\HandBrake
2015-02-14 16:04 - 2015-02-14 16:04 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Foxit Software
2015-02-14 15:52 - 2015-02-14 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinArchiver
2015-02-14 15:52 - 2015-02-14 15:52 - 00000000 ____D () C:\Program Files\WinArchiver
2015-02-14 15:52 - 2014-12-19 05:41 - 00142096 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2015-02-14 15:51 - 2015-02-14 15:51 - 00000000 ____D () C:\Windows\SysWOW64\ShellExt
2015-02-14 15:51 - 2015-02-14 15:51 - 00000000 ____D () C:\Windows\system32\ShellExt
2015-02-14 15:50 - 2015-02-14 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CopyFilenames
2015-02-14 15:50 - 2015-02-14 15:50 - 00000000 ____D () C:\Program Files\CopyFilenames
2015-02-14 15:48 - 2011-01-15 17:41 - 00000291 _____ () C:\Windows\system32\Show_Hide_Checkbox_On_Off.vbs
2015-02-14 15:48 - 2010-05-30 14:48 - 00000446 _____ () C:\Windows\system32\Show_Hide_Hidden_Files_On_Off.vbs
2015-02-14 15:48 - 2010-05-30 14:47 - 00000287 _____ () C:\Windows\system32\Show_Hide_File_Extension_On_Off.vbs
2015-02-14 15:44 - 2014-06-13 16:58 - 00000396 _____ () C:\Windows\system32\Eject-Close_CD-DVD.bat
2015-02-14 15:44 - 2013-08-11 14:41 - 00115712 _____ (NirSoft) C:\Windows\system32\nircmd.exe
2015-02-14 15:03 - 2015-02-15 11:13 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DMCache
2015-02-14 15:03 - 2015-02-15 00:26 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager
2015-02-14 15:03 - 2015-02-14 15:24 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\IDM
2015-02-14 15:03 - 2015-02-14 15:03 - 00000000 ____D () C:\Users\Administrator\Downloads\Video
2015-02-14 15:03 - 2015-02-14 15:03 - 00000000 ____D () C:\Users\Administrator\Downloads\Compressed
2015-02-14 15:03 - 2015-02-14 15:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-02-14 15:03 - 2015-02-14 15:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2015-02-14 15:03 - 2015-02-14 15:03 - 00000000 ____D () C:\ProgramData\IDM
2015-02-14 14:30 - 2015-02-14 14:30 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieUserList
2015-02-14 14:30 - 2015-02-14 14:30 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieSiteList
2015-02-14 14:30 - 2015-02-14 14:30 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieBrowserModeList
2015-02-14 14:10 - 2014-12-11 21:17 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-02-14 13:53 - 2014-09-05 05:41 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-14 13:53 - 2014-09-05 05:22 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-02-14 13:53 - 2014-08-29 05:37 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-02-14 13:53 - 2014-05-08 13:02 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-02-14 13:51 - 2015-02-14 13:51 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-02-14 13:50 - 2015-02-14 13:50 - 00001355 _____ () C:\Windows\TSSysprep.log
2015-02-14 13:50 - 2015-02-14 13:50 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-02-14 13:49 - 2015-02-15 11:18 - 00737226 _____ () C:\Windows\WindowsUpdate.log
2015-02-14 13:49 - 2015-02-14 13:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-02-14 13:46 - 2015-02-14 13:46 - 00008192 __RSH () C:\BOOTSECT.BAK
2015-02-14 13:46 - 2015-02-14 02:32 - 00000000 ____D () C:\Windows\Panther
2015-02-14 13:45 - 2010-11-21 06:53 - 00383786 __RSH () C:\bootmgr
2015-02-14 13:01 - 2015-02-14 13:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Locktime
2015-02-14 13:00 - 2015-02-14 13:00 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NetLimiter 3
2015-02-14 13:00 - 2015-02-14 13:00 - 00000000 ____D () C:\ProgramData\Locktime
2015-02-14 13:00 - 2015-02-14 13:00 - 00000000 ____D () C:\Program Files\NetLimiter 3
2015-02-14 12:56 - 2015-02-14 12:56 - 00000000 ____D () C:\Program Files\NetSpeedMonitor
2015-02-14 12:52 - 2015-02-14 12:52 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia
2015-02-14 05:48 - 2015-02-14 05:48 - 00044544 _____ () C:\Windows\SysWOW64\Gif89.dll
2015-02-14 05:48 - 2015-02-14 05:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Theme Resource Changer X64 v1.0
2015-02-14 05:48 - 2015-02-14 05:48 - 00000000 ____D () C:\Program Files\Theme Resource Changer
2015-02-14 05:45 - 2015-02-12 19:59 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll.backup
2015-02-14 05:45 - 2015-02-12 19:44 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll.backup
2015-02-14 05:45 - 2009-07-14 05:11 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\themeservice.dll.backup
2015-02-14 05:39 - 2013-10-02 05:52 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-02-14 05:39 - 2013-10-02 05:41 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-02-14 05:39 - 2013-10-02 05:38 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-02-14 05:39 - 2013-10-02 05:18 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-02-14 05:39 - 2013-10-02 05:18 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-02-14 05:39 - 2013-10-02 04:59 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-02-14 05:39 - 2013-10-02 04:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-02-14 05:39 - 2013-10-02 03:45 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-02-14 05:39 - 2013-10-02 03:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-02-14 05:39 - 2013-10-02 03:44 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-02-14 05:39 - 2013-10-02 03:31 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-02-14 05:39 - 2013-10-02 03:28 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-02-14 05:39 - 2013-10-02 03:01 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-02-14 05:39 - 2013-10-02 02:38 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-02-14 05:39 - 2013-10-02 02:04 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-02-14 05:39 - 2012-08-23 17:43 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-02-14 05:39 - 2012-08-23 17:42 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\terminpt.sys
2015-02-14 05:39 - 2012-08-23 17:40 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-02-14 05:39 - 2012-08-23 17:38 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2015-02-14 05:39 - 2012-08-23 14:42 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2015-02-14 05:39 - 2012-08-23 14:21 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2015-02-14 05:36 - 2015-02-15 11:15 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2015-02-14 05:36 - 2015-02-14 05:36 - 00000045 _____ () C:\Windows\SysWOW64\initdebug.nfo
2015-02-14 05:35 - 2015-01-23 08:12 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-14 05:35 - 2015-01-23 08:11 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-14 05:35 - 2015-01-23 07:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-14 05:35 - 2015-01-23 06:47 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-14 05:29 - 2015-02-14 05:29 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-02-14 05:28 - 2015-02-14 05:28 - 00000000 ____D () C:\ProgramData\ATI
2015-02-14 05:26 - 2015-02-14 05:26 - 00061880 _____ () C:\Windows\SysWOW64\CCCInstall_201502140526091463.log
2015-02-14 05:26 - 2015-02-14 05:26 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2015-02-14 05:26 - 2015-02-14 05:26 - 00000000 ____D () C:\Program Files (x86)\AMD
2015-02-14 05:25 - 2015-02-14 05:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-02-14 05:24 - 2015-02-14 05:26 - 00000000 ____D () C:\Program Files\AMD
2015-02-14 05:23 - 2015-02-14 05:23 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-14 05:23 - 2015-02-14 05:23 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-02-14 05:09 - 2015-02-14 05:11 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-14 05:09 - 2015-01-29 17:49 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-14 05:05 - 2015-01-14 08:39 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-14 05:05 - 2015-01-12 06:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-14 05:05 - 2015-01-12 06:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-14 05:05 - 2015-01-12 06:09 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-14 05:05 - 2015-01-12 06:04 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-14 05:05 - 2015-01-12 05:55 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-14 05:05 - 2015-01-12 05:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-14 05:05 - 2015-01-12 05:43 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-14 05:05 - 2015-01-12 05:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-02-14 05:05 - 2015-01-12 05:35 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-14 05:05 - 2015-01-12 05:29 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-02-14 05:05 - 2015-01-12 05:18 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-14 05:05 - 2015-01-12 05:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-14 05:05 - 2015-01-12 05:05 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-14 05:05 - 2015-01-12 05:03 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-14 05:05 - 2015-01-12 04:53 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-14 05:05 - 2015-01-12 04:26 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-14 05:04 - 2015-01-14 09:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-14 05:04 - 2015-01-12 06:39 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-14 05:04 - 2015-01-12 06:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-14 05:04 - 2015-01-12 06:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-14 05:04 - 2015-01-12 06:18 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-14 05:04 - 2015-01-12 06:18 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-14 05:04 - 2015-01-12 06:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-14 05:04 - 2015-01-12 06:10 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-14 05:04 - 2015-01-12 06:06 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-14 05:04 - 2015-01-12 06:04 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-14 05:04 - 2015-01-12 05:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-14 05:04 - 2015-01-12 05:51 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-14 05:04 - 2015-01-12 05:38 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-14 05:04 - 2015-01-12 05:38 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-14 05:04 - 2015-01-12 05:37 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-14 05:04 - 2015-01-12 05:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-02-14 05:04 - 2015-01-12 05:34 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-14 05:04 - 2015-01-12 05:32 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-14 05:04 - 2015-01-12 05:30 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-14 05:04 - 2015-01-12 05:27 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-14 05:04 - 2015-01-12 05:25 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-14 05:04 - 2015-01-12 05:18 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-14 05:04 - 2015-01-12 05:16 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-14 05:04 - 2015-01-12 05:16 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-14 05:04 - 2015-01-12 05:15 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-14 05:04 - 2015-01-12 05:13 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-14 05:04 - 2015-01-12 05:06 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-02-14 05:04 - 2015-01-12 04:57 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-14 05:04 - 2015-01-12 04:53 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-14 05:04 - 2015-01-12 04:52 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-02-14 05:04 - 2015-01-12 04:44 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-14 05:04 - 2015-01-12 04:44 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-14 05:04 - 2015-01-12 04:32 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-14 05:04 - 2015-01-12 04:30 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-14 05:04 - 2015-01-12 04:25 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-14 04:54 - 2014-08-01 15:23 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-02-14 04:54 - 2014-08-01 15:05 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2015-02-14 04:53 - 2011-04-09 10:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-02-14 04:53 - 2011-04-09 09:26 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-02-14 04:48 - 2015-02-14 04:50 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\TaskmgrPro
2015-02-14 04:48 - 2015-02-14 04:48 - 00000000 ____D () C:\Users\Administrator\Documents\TaskmgrPro
2015-02-14 04:48 - 2015-02-14 04:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TaskmgrPro
2015-02-14 04:48 - 2015-02-14 04:48 - 00000000 ____D () C:\Program Files\TaskmgrPro
2015-02-14 04:37 - 2015-02-14 04:37 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Hard Disk Sentinel
2015-02-14 04:35 - 2015-02-14 04:35 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-14 04:35 - 2015-02-14 04:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-14 04:35 - 2015-02-14 04:35 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2015-02-14 04:35 - 2015-02-14 04:35 - 00000000 ____D () C:\Windows\system32\Macromed
2015-02-14 04:34 - 2015-02-14 04:34 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-02-14 04:34 - 2015-02-14 04:34 - 00000000 ____D () C:\ProgramData\Sun
2015-02-14 04:34 - 2015-02-14 04:34 - 00000000 ____D () C:\ProgramData\Oracle
2015-02-14 04:34 - 2015-02-14 04:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-02-14 04:34 - 2015-02-14 04:34 - 00000000 ____D () C:\Program Files\Java
2015-02-14 04:32 - 2015-02-14 04:32 - 00757660 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-02-14 04:31 - 2015-02-14 04:31 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinRAR
2015-02-14 04:31 - 2014-09-10 10:14 - 00163480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00660120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00617896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00444328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshflxgd.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00416408 _____ (Microsoft Corporation ) C:\Windows\SysWOW64\comct332.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00279192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatgrd.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00259736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00253080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatlst.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00222360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tabctl32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00219288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00218776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00212112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00179352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmask32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00170920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00131728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00130712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstdfmt.dll
2015-02-14 04:31 - 2013-11-25 07:27 - 00127640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00119960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomm32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00108696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstkprp.dll
2015-02-14 04:31 - 2013-11-25 07:27 - 00104088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\picclp32.ocx
2015-02-14 04:31 - 2013-11-25 07:27 - 00084624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysinfo.ocx
2015-02-14 04:31 - 2011-01-12 13:36 - 01054208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71u.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71deu.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ita.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71fra.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71esp.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71enu.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71kor.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71jpn.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71cht.dll
2015-02-14 04:31 - 2011-01-12 13:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71chs.dll
2015-02-14 04:31 - 2011-01-12 13:19 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2015-02-14 04:31 - 2011-01-12 12:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll
2015-02-14 04:31 - 2007-02-01 22:13 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2015-02-14 04:31 - 2007-02-01 19:11 - 00344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2015-02-14 04:31 - 2007-01-30 22:04 - 00339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2015-02-14 04:31 - 2006-08-26 00:28 - 01017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ita.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70fra.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70esp.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70deu.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70enu.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70kor.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70jpn.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70cht.dll
2015-02-14 04:31 - 2006-08-26 00:15 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70chs.dll
2015-02-14 04:31 - 2006-08-26 00:07 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll
2015-02-14 04:31 - 2006-08-25 23:17 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll
2015-02-14 04:31 - 2005-01-20 19:25 - 00054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll
2015-02-14 04:31 - 2002-01-05 05:40 - 00487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp70.dll
2015-02-14 04:31 - 2001-08-23 00:00 - 01355776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvbvm50.dll
2015-02-14 04:31 - 1996-01-12 03:00 - 00722192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vb40032.dll
2015-02-14 04:31 - 1993-07-23 19:31 - 00210944 _____ () C:\Windows\SysWOW64\msvcrt10.dll
2015-02-14 04:30 - 2015-02-14 04:30 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-02-14 04:30 - 2015-02-14 04:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-02-14 04:29 - 2015-02-14 04:30 - 00000000 ____D () C:\Program Files\WinRAR
2015-02-14 02:58 - 2015-02-14 02:58 - 00000159 ___RH () C:\Windows\ctfile.rfc
2015-02-14 02:58 - 2011-05-19 15:39 - 00007195 ____N () C:\Windows\system32\THXCfgUninstall64.ini
2015-02-14 02:58 - 2011-05-19 15:39 - 00006925 ____N () C:\Windows\system32\THXCfg64.ini
2015-02-14 02:58 - 2011-05-19 15:39 - 00001424 ____N () C:\Windows\THXCfg_SP_APOIM.ini
2015-02-14 02:58 - 2011-05-19 15:39 - 00001323 ____N () C:\Windows\THXCfg_HP_APOIM.ini
2015-02-14 02:58 - 2011-05-19 15:39 - 00001323 ____N () C:\Windows\THXCfg_APOIM.ini
2015-02-14 02:58 - 2011-05-19 09:58 - 00246784 _____ () C:\Windows\system32\APOMgr64.DLL
2015-02-14 02:58 - 2011-05-19 09:56 - 00190464 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2015-02-14 02:58 - 2011-05-13 12:30 - 00026624 ____N (Creative Technology Ltd.) C:\Windows\system32\THXCfg64.dll
2015-02-14 02:58 - 2010-07-21 16:51 - 00011264 ____N (Creative Technology Ltd.) C:\Windows\SysWOW64\ResDefA.exe
2015-02-14 02:58 - 2009-12-29 16:53 - 00089088 _____ () C:\Windows\system32\CmdRtr64.DLL
2015-02-14 02:58 - 2009-12-29 16:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2015-02-14 02:58 - 2009-10-01 16:42 - 00141312 ____N (Creative Technology Ltd.) C:\Windows\system32\THXCfg64.exe
2015-02-14 02:58 - 2000-05-11 01:00 - 00090112 ____N (Creative Technology Ltd.) C:\Windows\Updreg.EXE
2015-02-14 02:57 - 2015-02-14 02:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2015-02-14 02:57 - 2015-02-14 02:57 - 00000000 ____D () C:\Program Files (x86)\Creative
2015-02-14 02:54 - 2015-02-14 02:54 - 00058128 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-14 02:54 - 2015-02-14 02:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ATI
2015-02-14 02:54 - 2015-02-14 02:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ATI
2015-02-14 02:54 - 2015-02-14 02:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AMD
2015-02-14 02:53 - 2015-02-14 02:53 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-02-14 02:52 - 2015-02-14 02:52 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2015-02-14 02:51 - 2015-02-14 05:26 - 00000000 ____D () C:\ProgramData\AMD
2015-02-14 02:51 - 2015-02-14 02:51 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-02-14 02:51 - 2011-07-29 01:06 - 00462848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll
2015-02-14 02:51 - 2011-07-29 00:31 - 00058880 _____ (AMD) C:\Windows\system32\coinst.dll
2015-02-14 02:51 - 2011-07-26 06:11 - 00034823 _____ () C:\Windows\atiogl.xml
2015-02-14 02:51 - 2010-02-18 09:18 - 00046136 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdiox64.sys
2015-02-14 02:48 - 2015-02-14 02:58 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-02-14 02:48 - 2015-02-14 02:48 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-02-14 02:48 - 2011-04-21 21:47 - 00471144 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2015-02-14 02:48 - 2011-04-21 21:47 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2015-02-14 02:48 - 2011-04-21 21:47 - 00074272 _____ () C:\Windows\system32\RtNicProp64.dll
2015-02-14 02:47 - 2012-10-22 13:39 - 02206864 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\viahduaa.sys
2015-02-14 02:47 - 2010-10-26 14:25 - 00074240 _____ (Creative Technology Ltd.) C:\Windows\system32\VMWRP64.DLL
2015-02-14 02:47 - 2010-10-26 14:24 - 00053760 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPCN64.DLL
2015-02-14 02:47 - 2009-07-31 07:10 - 00025600 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\VMfilt64.sys
2015-02-14 02:46 - 2015-02-14 02:47 - 00000000 ____D () C:\Program Files (x86)\VIA
2015-02-14 02:46 - 2007-04-11 11:05 - 00414632 ____N (Microsoft Corporation) C:\Windows\difxapi.dll
2015-02-14 02:43 - 2015-02-14 05:25 - 00000000 ____D () C:\Program Files\ATI Technologies
2015-02-14 02:43 - 2015-02-14 02:43 - 00000000 ____D () C:\Program Files\ATI
2015-02-14 02:43 - 2011-03-18 03:34 - 00188544 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdxhc.sys
2015-02-14 02:43 - 2011-03-18 03:34 - 00087168 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdhub30.sys
2015-02-14 02:39 - 2015-02-14 02:39 - 00001413 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-14 02:39 - 2015-02-14 02:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2015-02-14 02:38 - 2015-02-14 02:39 - 00000000 ____D () C:\Users\Administrator
2015-02-14 02:38 - 2015-02-14 02:38 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2015-02-14 02:38 - 2009-07-14 08:24 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-14 02:38 - 2009-07-14 08:19 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-02-14 02:32 - 2015-02-14 02:32 - 00002802 _____ () C:\Windows\system32\WinToolkit_RunOnce_Log.log
2015-02-14 02:32 - 2015-02-14 02:32 - 00000000 __SHD () C:\Recovery
2015-02-14 01:51 - 2015-02-15 11:24 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NetSpeedMonitor
2015-02-12 21:42 - 2015-02-12 21:42 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2015-02-12 21:42 - 2015-02-12 21:42 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-02-12 21:42 - 2015-02-12 21:42 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-02-12 21:42 - 2015-02-12 21:42 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-02-12 21:42 - 2015-02-12 21:42 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-02-12 21:42 - 2015-02-12 21:42 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2015-02-12 21:42 - 2015-02-12 21:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2015-02-12 21:42 - 2015-02-12 21:42 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-02-12 21:42 - 2015-02-12 21:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-02-12 21:41 - 2015-02-12 21:41 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-12 21:41 - 2015-02-12 21:41 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00458832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-12 21:39 - 2015-02-12 21:39 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-02-12 21:39 - 2015-02-12 21:39 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-02-12 21:38 - 2015-02-12 21:38 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2015-02-12 21:37 - 2015-02-12 21:37 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-02-12 21:37 - 2015-02-12 21:37 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-02-12 21:37 - 2015-02-12 21:37 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-02-12 21:37 - 2015-02-12 21:37 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-02-12 21:37 - 2015-02-12 21:37 - 00087552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-02-12 21:36 - 2015-02-12 21:36 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-12 21:36 - 2015-02-12 21:36 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll
2015-02-12 21:36 - 2015-02-12 21:36 - 00193024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassam.dll
2015-02-12 21:35 - 2015-02-12 21:35 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-12 21:35 - 2015-02-12 21:35 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-12 21:35 - 2015-02-12 21:35 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-02-12 21:35 - 2015-02-12 21:35 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2015-02-12 21:34 - 2015-02-12 21:34 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2015-02-12 21:34 - 2015-02-12 21:34 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 05553080 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-12 21:33 - 2015-02-12 21:33 - 03977656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-12 21:33 - 2015-02-12 21:33 - 03921848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-12 21:33 - 2015-02-12 21:33 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-02-12 21:33 - 2015-02-12 21:33 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00617384 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-02-12 21:33 - 2015-02-12 21:33 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-02-12 21:33 - 2015-02-12 21:33 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-02-12 21:32 - 2015-02-12 21:32 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-12 21:32 - 2015-02-12 21:32 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-12 21:31 - 2015-02-12 21:31 - 00686592 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2015-02-12 21:31 - 2015-02-12 21:31 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-12 21:31 - 2015-02-12 21:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-12 21:31 - 2015-02-12 21:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00104896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys
2015-02-12 21:30 - 2015-02-12 21:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-02-12 21:30 - 2015-02-12 21:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-02-12 21:29 - 2015-02-12 21:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-02-12 21:29 - 2015-02-12 21:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-02-12 21:28 - 2015-02-12 21:28 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2015-02-12 21:28 - 2015-02-12 21:28 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2015-02-12 21:27 - 2015-02-12 21:27 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-02-12 21:27 - 2015-02-12 21:27 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-02-12 21:27 - 2015-02-12 21:27 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-02-12 21:27 - 2015-02-12 21:27 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2015-02-12 21:25 - 2015-02-12 21:25 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-02-12 21:25 - 2015-02-12 21:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2015-02-12 21:25 - 2015-02-12 21:25 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2015-02-12 21:25 - 2015-02-12 21:25 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-02-12 21:24 - 2015-02-12 21:24 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2015-02-12 21:24 - 2015-02-12 21:24 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2015-02-12 21:22 - 2015-02-12 21:22 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2015-02-12 21:22 - 2015-02-12 21:22 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2015-02-12 21:21 - 2015-02-12 21:21 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-02-12 21:20 - 2015-02-12 21:20 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-02-12 21:20 - 2015-02-12 21:20 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-02-12 21:20 - 2015-02-12 21:20 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-02-12 21:20 - 2015-02-12 21:20 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-02-12 21:20 - 2015-02-12 21:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-02-12 21:20 - 2015-02-12 21:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-02-12 21:18 - 2015-02-12 21:18 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-02-12 21:18 - 2015-02-12 21:18 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2015-02-12 21:18 - 2015-02-12 21:18 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-02-12 21:18 - 2015-02-12 21:18 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2015-02-12 21:18 - 2015-02-12 21:18 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2015-02-12 21:18 - 2015-02-12 21:18 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-02-12 21:18 - 2015-02-12 21:18 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2015-02-12 21:18 - 2015-02-12 21:18 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-02-12 21:11 - 2015-02-12 21:11 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-02-12 21:11 - 2015-02-12 21:11 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2015-02-12 21:11 - 2015-02-12 21:11 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2015-02-12 21:11 - 2015-02-12 21:11 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2015-02-12 21:09 - 2015-02-12 21:09 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2015-02-12 21:09 - 2015-02-12 21:09 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2015-02-12 21:09 - 2015-02-12 21:09 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2015-02-12 21:09 - 2015-02-12 21:09 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2015-02-12 21:09 - 2015-02-12 21:09 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2015-02-12 21:09 - 2015-02-12 21:09 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2015-02-12 21:09 - 2015-02-12 21:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2015-02-12 21:09 - 2015-02-12 21:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00315904 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00260096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2015-02-12 21:08 - 2015-02-12 21:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2015-02-12 21:08 - 2015-02-12 21:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-12 21:08 - 2015-02-12 21:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-12 21:08 - 2015-02-12 21:08 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-02-12 21:08 - 2015-02-12 21:08 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-12 21:08 - 2015-02-12 21:08 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-12 21:08 - 2015-02-12 21:08 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-12 21:07 - 2015-02-12 21:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2015-02-12 21:06 - 2015-02-12 21:06 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-02-12 21:06 - 2015-02-12 21:06 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-02-12 21:06 - 2015-02-12 21:06 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-02-12 21:04 - 2015-02-12 21:04 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-02-12 21:04 - 2015-02-12 21:04 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-02-12 21:03 - 2015-02-12 21:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-02-12 21:02 - 2015-02-12 21:02 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2015-02-12 21:02 - 2015-02-12 21:02 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2015-02-12 21:02 - 2015-02-12 21:02 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2015-02-12 21:02 - 2015-02-12 21:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2015-02-12 21:02 - 2015-02-12 21:02 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2015-02-12 21:01 - 2015-02-12 21:01 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-02-12 21:01 - 2015-02-12 21:01 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2015-02-12 21:01 - 2015-02-12 21:01 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2015-02-12 21:01 - 2015-02-12 21:01 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2015-02-12 21:00 - 2015-02-12 21:00 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2015-02-12 21:00 - 2015-02-12 21:00 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2015-02-12 20:59 - 2015-02-12 20:59 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2015-02-12 20:59 - 2015-02-12 20:59 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2015-02-12 20:59 - 2015-02-12 20:59 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2015-02-12 20:59 - 2015-02-12 20:59 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2015-02-12 20:59 - 2015-02-12 20:59 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2015-02-12 20:58 - 2015-02-12 20:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2015-02-12 20:58 - 2015-02-12 20:58 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2015-02-12 20:58 - 2015-02-12 20:58 - 00625152 _____ (Microsoft Corporation) C:\Windows\system32\colorui.dll
2015-02-12 20:58 - 2015-02-12 20:58 - 00606208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\colorui.dll
2015-02-12 20:58 - 2015-02-12 20:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2015-02-12 20:57 - 2015-02-12 20:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-02-12 20:55 - 2015-02-12 20:55 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2015-02-12 20:55 - 2015-02-12 20:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2015-02-12 20:54 - 2015-02-12 20:54 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2015-02-12 20:54 - 2015-02-12 20:54 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2015-02-12 20:54 - 2015-02-12 20:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2015-02-12 20:54 - 2015-02-12 20:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2015-02-12 20:54 - 2015-02-12 20:54 - 00200576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2015-02-12 20:54 - 2015-02-12 20:54 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2015-02-12 20:53 - 2015-02-12 20:53 - 00288704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2015-02-12 20:52 - 2015-02-12 20:52 - 01895872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-02-12 20:52 - 2015-02-12 20:52 - 00377792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2015-02-12 20:52 - 2015-02-12 20:52 - 00296896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2015-02-12 20:52 - 2015-02-12 20:52 - 00143288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2015-02-12 20:51 - 2015-02-12 20:51 - 01032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-02-12 20:51 - 2015-02-12 20:51 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-02-12 20:51 - 2015-02-12 20:51 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2015-02-12 20:51 - 2015-02-12 20:51 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-02-12 20:50 - 2015-02-12 20:50 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2015-02-12 20:50 - 2015-02-12 20:50 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2015-02-12 20:50 - 2015-02-12 20:50 - 00299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2015-02-12 20:50 - 2015-02-12 20:50 - 00257536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2015-02-12 20:50 - 2015-02-12 20:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2015-02-12 20:50 - 2015-02-12 20:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2015-02-12 20:49 - 2015-02-12 20:49 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-02-12 20:49 - 2015-02-12 20:49 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll
2015-02-12 20:49 - 2015-02-12 20:49 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\csc.sys
2015-02-12 20:49 - 2015-02-12 20:49 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2015-02-12 20:49 - 2015-02-12 20:49 - 00153088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00582656 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00328704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsvcs.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll
2015-02-12 20:48 - 2015-02-12 20:48 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 14181376 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 12878336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 01499136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 00967168 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-02-12 20:47 - 2015-02-12 20:47 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 01215488 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00263096 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-02-12 20:46 - 2015-02-12 20:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-02-12 20:45 - 2015-02-12 20:45 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2015-02-12 20:45 - 2015-02-12 20:45 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2015-02-12 20:45 - 2015-02-12 20:45 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sisbkup.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 01511936 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 01008128 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00748032 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00581120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcprx.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00419648 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-12 20:44 - 2015-02-12 20:44 - 00419648 _____ () C:\Windows\system32\locale.nls
2015-02-12 20:44 - 2015-02-12 20:44 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\xolehlp.dll
2015-02-12 20:44 - 2015-02-12 20:44 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xolehlp.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2015-02-12 20:43 - 2015-02-12 20:43 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2015-02-12 20:42 - 2015-02-12 20:42 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2015-02-12 20:42 - 2015-02-12 20:42 - 00762368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroles.dll
2015-02-12 20:42 - 2015-02-12 20:42 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2015-02-12 20:42 - 2015-02-12 20:42 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2015-02-12 20:41 - 2015-02-12 20:41 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2015-02-12 20:40 - 2015-02-12 20:40 - 01506304 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2015-02-12 20:39 - 2015-02-12 20:39 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2015-02-12 20:39 - 2015-02-12 20:39 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2015-02-12 20:38 - 2015-02-12 20:38 - 01753600 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2015-02-12 20:38 - 2015-02-12 20:38 - 01602560 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2015-02-12 20:38 - 2015-02-12 20:38 - 01128448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll
2015-02-12 20:38 - 2015-02-12 20:38 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\vsstrace.dll
2015-02-12 20:38 - 2015-02-12 20:38 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vsstrace.dll
2015-02-12 20:37 - 2015-02-12 20:37 - 00164792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2015-02-12 20:36 - 2015-02-12 20:36 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-02-12 20:36 - 2015-02-12 20:36 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\tscfgwmi.dll
2015-02-12 20:36 - 2015-02-12 20:36 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2015-02-12 20:36 - 2015-02-12 20:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2015-02-12 20:36 - 2015-02-12 20:36 - 00072192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\regapi.dll
2015-02-12 20:36 - 2015-02-12 20:36 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\dimsjob.dll
2015-02-12 20:36 - 2015-02-12 20:36 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsjob.dll
2015-02-12 20:36 - 2015-02-12 20:36 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2015-02-12 20:35 - 2015-02-12 20:35 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efscore.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2015-02-12 20:35 - 2015-02-12 20:35 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2015-02-12 20:35 - 2015-02-12 20:35 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\efslsaext.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2015-02-12 20:35 - 2015-02-12 20:35 - 00038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2015-02-12 20:35 - 2015-02-12 20:35 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\efssvc.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2015-02-12 20:35 - 2015-02-12 20:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2015-02-12 20:34 - 2015-02-12 20:34 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-02-12 20:34 - 2015-02-12 20:34 - 00443320 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 03650560 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 01339904 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00613376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kstvtune.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00068608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSTPager.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cca.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksxbar.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\tvratings.dll
2015-02-12 20:33 - 2015-02-12 20:33 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbisurf.ax
2015-02-12 20:33 - 2015-02-12 20:33 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tvratings.dll
2015-02-12 20:32 - 2015-02-12 20:32 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\linkinfo.dll
2015-02-12 20:32 - 2015-02-12 20:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\linkinfo.dll
2015-02-12 20:31 - 2015-02-12 20:31 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2015-02-12 20:31 - 2015-02-12 20:31 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2015-02-12 20:31 - 2015-02-12 20:31 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe
2015-02-12 20:31 - 2015-02-12 20:31 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\uxsms.dll
2015-02-12 20:30 - 2015-02-12 20:30 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2015-02-12 20:30 - 2015-02-12 20:30 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2015-02-12 20:30 - 2015-02-12 20:30 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2015-02-12 20:30 - 2015-02-12 20:30 - 00350720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shlwapi.dll
2015-02-12 20:30 - 2015-02-12 20:30 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2015-02-12 20:30 - 2015-02-12 20:30 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2015-02-12 20:29 - 2015-02-12 20:29 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00275392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2015-02-12 20:29 - 2015-02-12 20:29 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00242176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00222208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00183296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasnap.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2015-02-12 20:29 - 2015-02-12 20:29 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00591360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2015-02-12 20:28 - 2015-02-12 20:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2015-02-12 20:28 - 2015-02-12 20:28 - 00031168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2015-02-12 20:27 - 2015-02-12 20:27 - 01002496 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2015-02-12 20:27 - 2015-02-12 20:27 - 00953856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2015-02-12 20:27 - 2015-02-12 20:27 - 00653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2015-02-12 20:27 - 2015-02-12 20:27 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2015-02-12 20:27 - 2015-02-12 20:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2015-02-12 20:27 - 2015-02-12 20:27 - 00108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2015-02-12 20:27 - 2015-02-12 20:27 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2015-02-12 20:27 - 2015-02-12 20:27 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2015-02-12 20:26 - 2015-02-12 20:26 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2015-02-12 20:25 - 2015-02-12 20:25 - 00577536 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2015-02-12 20:25 - 2015-02-12 20:25 - 00458752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2015-02-12 20:25 - 2015-02-12 20:25 - 00154624 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2015-02-12 20:25 - 2015-02-12 20:25 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2015-02-12 20:25 - 2015-02-12 20:25 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2015-02-12 20:25 - 2015-02-12 20:25 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nci.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00862208 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-02-12 20:24 - 2015-02-12 20:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00832000 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00706560 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2015-02-12 20:24 - 2015-02-12 20:24 - 00657920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-02-12 20:24 - 2015-02-12 20:24 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2015-02-12 20:24 - 2015-02-12 20:24 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-02-12 20:24 - 2015-02-12 20:24 - 00320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2015-02-12 20:24 - 2015-02-12 20:24 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2015-02-12 20:23 - 2015-02-12 20:23 - 01363968 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 01227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2015-02-12 20:23 - 2015-02-12 20:23 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2015-02-12 20:23 - 2015-02-12 20:23 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2015-02-12 20:23 - 2015-02-12 20:23 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2015-02-12 20:22 - 2015-02-12 20:22 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2015-02-12 20:22 - 2015-02-12 20:22 - 00365568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2015-02-12 20:22 - 2015-02-12 20:22 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2015-02-12 20:22 - 2015-02-12 20:22 - 00180736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 01901056 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 01668096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 00474112 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlangpui.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2015-02-12 20:21 - 2015-02-12 20:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\l2gpstore.dll
2015-02-12 20:21 - 2015-02-12 20:21 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\TpmInit.exe
2015-02-12 20:20 - 2015-02-12 20:20 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmInit.exe
2015-02-12 20:20 - 2015-02-12 20:20 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\tpmcompc.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tpmcompc.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2015-02-12 20:20 - 2015-02-12 20:20 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\AdmTmpl.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\scrptadm.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00464896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrptadm.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00438272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AdmTmpl.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00119808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imm32.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2015-02-12 20:19 - 2015-02-12 20:19 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2015-02-12 20:18 - 2015-02-12 20:18 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-02-12 20:18 - 2015-02-12 20:18 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-02-12 20:17 - 2015-02-12 20:17 - 00201216 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2015-02-12 20:17 - 2015-02-12 20:17 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2015-02-12 20:17 - 2015-02-12 20:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\w32tm.exe
2015-02-12 20:16 - 2015-02-12 20:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2015-02-12 20:16 - 2015-02-12 20:16 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe
2015-02-12 20:15 - 2015-02-12 20:15 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2015-02-12 20:15 - 2015-02-12 20:15 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiohlp.dll
2015-02-12 20:15 - 2015-02-12 20:15 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\NETSTAT.EXE
2015-02-12 20:15 - 2015-02-12 20:15 - 00028160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NETSTAT.EXE
2015-02-12 20:15 - 2015-02-12 20:15 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\beep.sys
2015-02-12 20:14 - 2015-02-12 20:14 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00402944 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00253440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2015-02-12 20:14 - 2015-02-12 20:14 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2015-02-12 20:14 - 2015-02-12 20:14 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2015-02-12 20:14 - 2015-02-12 20:14 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00119296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll
2015-02-12 20:13 - 2015-02-12 20:13 - 00097792 _____ () C:\Windows\system32\RDVGHelper.exe
2015-02-12 20:13 - 2015-02-12 20:13 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.dll
2015-02-12 20:12 - 2015-02-12 20:12 - 02566656 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2015-02-12 20:12 - 2015-02-12 20:12 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-02-12 20:12 - 2015-02-12 20:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2015-02-12 20:12 - 2015-02-12 20:12 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2015-02-12 20:12 - 2015-02-12 20:12 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2015-02-12 20:12 - 2015-02-12 20:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL
2015-02-12 20:11 - 2015-02-12 20:11 - 01245184 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2015-02-12 20:11 - 2015-02-12 20:11 - 00877568 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-02-12 20:11 - 2015-02-12 20:11 - 00732672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2015-02-12 20:11 - 2015-02-12 20:11 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-02-12 20:11 - 2015-02-12 20:11 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2015-02-12 20:11 - 2015-02-12 20:11 - 00392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2.dll
2015-02-12 20:10 - 2015-02-12 20:10 - 02870784 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-02-12 20:10 - 2015-02-12 20:10 - 02615808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-02-12 20:10 - 2015-02-12 20:10 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2015-02-12 20:10 - 2015-02-12 20:10 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2015-02-12 20:10 - 2015-02-12 20:10 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lsmproxy.dll
2015-02-12 20:09 - 2015-02-12 20:09 - 00900096 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2015-02-12 20:09 - 2015-02-12 20:09 - 00673792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2015-02-12 20:09 - 2015-02-12 20:09 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2015-02-12 20:09 - 2015-02-12 20:09 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\rdrleakdiag.exe
2015-02-12 20:09 - 2015-02-12 20:09 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdrleakdiag.exe
2015-02-12 20:08 - 2015-02-12 20:08 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2015-02-12 20:08 - 2015-02-12 20:08 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2015-02-12 20:08 - 2015-02-12 20:08 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetmib1.dll
2015-02-12 20:07 - 2015-02-12 20:07 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys
2015-02-12 20:07 - 2015-02-12 20:07 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2015-02-12 20:07 - 2015-02-12 20:07 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2015-02-12 20:07 - 2015-02-12 20:07 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2015-02-12 20:07 - 2015-02-12 20:07 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 02494464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 01808896 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 01750528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pnidui.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 00403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\uexfat.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uexfat.dll
2015-02-12 20:06 - 2015-02-12 20:06 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\chglogon.exe
2015-02-12 20:05 - 2015-02-12 20:05 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2015-02-12 20:05 - 2015-02-12 20:05 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2015-02-12 20:05 - 2015-02-12 20:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll
2015-02-12 20:05 - 2015-02-12 20:05 - 00134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2015-02-12 20:05 - 2015-02-12 20:05 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2015-02-12 20:05 - 2015-02-12 20:05 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe
2015-02-12 20:05 - 2015-02-12 20:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SCardDlg.dll
2015-02-12 20:05 - 2015-02-12 20:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\reg.exe
2015-02-12 20:05 - 2015-02-12 20:05 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2015-02-12 20:04 - 2015-02-12 20:04 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-02-12 20:03 - 2015-02-12 20:03 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2015-02-12 20:03 - 2015-02-12 20:03 - 00324608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2015-02-12 20:03 - 2015-02-12 20:03 - 00040280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys
2015-02-12 20:02 - 2015-02-12 20:02 - 02316288 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 02223104 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2015-02-12 20:02 - 2015-02-12 20:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2015-02-12 20:02 - 2015-02-12 20:02 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2015-02-12 20:01 - 2015-02-12 20:01 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2015-02-12 20:01 - 2015-02-12 20:01 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2015-02-12 20:01 - 2015-02-12 20:01 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\wsepno.dll
2015-02-12 20:00 - 2015-02-12 20:00 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\serial.sys
2015-02-12 20:00 - 2015-02-12 20:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\rshx32.dll
2015-02-12 20:00 - 2015-02-12 20:00 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rshx32.dll
2015-02-12 20:00 - 2015-02-12 20:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys
2015-02-12 19:59 - 2015-02-14 05:45 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2015-02-12 19:59 - 2015-02-12 19:59 - 02755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2015-02-12 19:59 - 2015-02-12 19:59 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-02-12 19:59 - 2015-02-12 19:59 - 00207360 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2015-02-12 19:59 - 2015-02-12 19:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\taskkill.exe
2015-02-12 19:59 - 2015-02-12 19:59 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskkill.exe
2015-02-12 19:58 - 2015-02-12 19:58 - 01650176 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-02-12 19:58 - 2015-02-12 19:58 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\docprop.dll
2015-02-12 19:58 - 2015-02-12 19:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\docprop.dll
2015-02-12 19:57 - 2015-02-12 19:57 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2015-02-12 19:57 - 2015-02-12 19:57 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\umrdp.dll
2015-02-12 19:57 - 2015-02-12 19:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icsunattend.exe
2015-02-12 19:56 - 2015-02-12 19:56 - 01198080 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 01048064 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 00930304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\printui.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 00474112 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-02-12 19:56 - 2015-02-12 19:56 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2015-02-12 19:56 - 2015-02-12 19:56 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-02-12 19:56 - 2015-02-12 19:56 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmstp.exe
2015-02-12 19:56 - 2015-02-12 19:56 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\cmdl32.exe
2015-02-12 19:56 - 2015-02-12 19:56 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmdl32.exe
2015-02-12 19:55 - 2015-02-12 19:55 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2015-02-12 19:55 - 2015-02-12 19:55 - 00300032 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00282112 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00253440 _____ (Microsoft) C:\Windows\SysWOW64\DShowRdpFilter.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2015-02-12 19:55 - 2015-02-12 19:55 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpdr.sys
2015-02-12 19:55 - 2015-02-12 19:55 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp.dll
2015-02-12 19:55 - 2015-02-12 19:55 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2015-02-12 19:54 - 2015-02-12 19:54 - 00753152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-02-12 19:54 - 2015-02-12 19:54 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\cryptdll.dll
2015-02-12 19:54 - 2015-02-12 19:54 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdll.dll
2015-02-12 19:53 - 2015-02-12 19:53 - 00524800 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll
2015-02-12 19:53 - 2015-02-12 19:53 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2015-02-12 19:53 - 2015-02-12 19:53 - 00200192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2015-02-12 19:52 - 2015-02-12 19:52 - 01495040 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2015-02-12 19:52 - 2015-02-12 19:52 - 01294336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll
2015-02-12 19:52 - 2015-02-12 19:52 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2015-02-12 19:52 - 2015-02-12 19:52 - 00242176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tapisrv.dll
2015-02-12 19:52 - 2015-02-12 19:52 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2015-02-12 19:52 - 2015-02-12 19:52 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2015-02-12 19:52 - 2015-02-12 19:52 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUQ.DLL
2015-02-12 19:52 - 2015-02-12 19:52 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTUF.DLL
2015-02-12 19:51 - 2015-02-12 19:51 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2015-02-12 19:51 - 2015-02-12 19:51 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2015-02-12 19:51 - 2015-02-12 19:51 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2015-02-12 19:51 - 2015-02-12 19:51 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2015-02-12 19:50 - 2015-02-12 19:50 - 00669696 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll
2015-02-12 19:50 - 2015-02-12 19:50 - 00544256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiaaut.dll
2015-02-12 19:50 - 2015-02-12 19:50 - 00334704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2015-02-12 19:49 - 2015-02-12 19:49 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2015-02-12 19:49 - 2015-02-12 19:49 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2015-02-12 19:49 - 2015-02-12 19:49 - 00283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdv.dll
2015-02-12 19:49 - 2015-02-12 19:49 - 00251904 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2015-02-12 19:49 - 2015-02-12 19:49 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00611328 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfdisk.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\perfnet.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\mgmtapi.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfnet.dll
2015-02-12 19:48 - 2015-02-12 19:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mgmtapi.dll
2015-02-12 19:47 - 2015-02-12 19:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\tasklist.exe
2015-02-12 19:47 - 2015-02-12 19:47 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tasklist.exe
2015-02-12 19:46 - 2015-02-12 19:46 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00170496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00170352 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00148336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2015-02-12 19:46 - 2015-02-12 19:46 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptui.dll
2015-02-12 19:45 - 2015-02-12 19:45 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2015-02-12 19:45 - 2015-02-12 19:45 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2015-02-12 19:45 - 2015-02-12 19:45 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\discache.sys
2015-02-12 19:44 - 2015-02-14 05:45 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 02130944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\networkmap.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 01979392 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 01335296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnrollCtrl.exe
2015-02-12 19:44 - 2015-02-12 19:44 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\networkitemfactory.dll
2015-02-12 19:44 - 2015-02-12 19:44 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\networkitemfactory.dll
2015-02-12 19:43 - 2015-02-12 19:43 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2015-02-12 19:43 - 2015-02-12 19:43 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasppp.dll
2015-02-12 19:43 - 2015-02-12 19:43 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\raserver.exe
2015-02-12 19:43 - 2015-02-12 19:43 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raserver.exe
2015-02-12 19:43 - 2015-02-12 19:43 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\setspn.exe
2015-02-12 19:42 - 2015-02-12 19:42 - 02086912 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-02-12 19:42 - 2015-02-12 19:42 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-02-12 19:42 - 2015-02-12 19:42 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2015-02-12 19:42 - 2015-02-12 19:42 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2015-02-12 19:42 - 2015-02-12 19:42 - 00184688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2015-02-12 19:42 - 2015-02-12 19:42 - 00068976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2015-02-12 19:41 - 2015-02-12 19:41 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2015-02-12 19:41 - 2015-02-12 19:41 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2015-02-12 19:41 - 2015-02-12 19:41 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2015-02-12 19:40 - 2015-02-12 19:40 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2015-02-12 19:40 - 2015-02-12 19:40 - 00330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2015-02-12 19:40 - 2015-02-12 19:40 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll
2015-02-12 19:40 - 2015-02-12 19:40 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2015-02-12 19:39 - 2015-02-12 19:39 - 00750592 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2015-02-12 19:39 - 2015-02-12 19:39 - 00464384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2015-02-12 19:38 - 2015-02-12 19:38 - 00161280 _____ (Microsoft Corporation) C:\Windows\system32\advpack.dll
2015-02-12 19:38 - 2015-02-12 19:38 - 00126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advpack.dll
2015-02-12 19:37 - 2015-02-12 19:37 - 03958272 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2015-02-12 19:36 - 2015-02-12 19:36 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2015-02-12 19:36 - 2015-02-12 19:36 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysdm.cpl
2015-02-12 19:36 - 2015-02-12 19:36 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2015-02-12 19:36 - 2015-02-12 19:36 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
2015-02-12 19:35 - 2015-02-12 19:35 - 00733696 _____ (Microsoft Corporation) C:\Windows\system32\psr.exe
2015-02-12 19:35 - 2015-02-12 19:35 - 00697344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psr.exe
2015-02-12 19:35 - 2015-02-12 19:35 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\activeds.dll
2015-02-12 19:35 - 2015-02-12 19:35 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\activeds.dll
2015-02-12 19:35 - 2015-02-12 19:35 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\activeds.tlb
2015-02-12 19:35 - 2015-02-12 19:35 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\activeds.tlb
2015-02-12 19:35 - 2015-02-12 19:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2015-02-12 19:34 - 2015-02-12 19:34 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2015-02-12 19:34 - 2015-02-12 19:34 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2015-02-12 19:34 - 2015-02-12 19:34 - 00380928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll
2015-02-12 19:34 - 2015-02-12 19:34 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2015-02-12 19:33 - 2015-02-12 19:33 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2015-02-12 19:32 - 2015-02-12 19:32 - 00215408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2015-02-12 19:32 - 2015-02-12 19:32 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2015-02-12 19:32 - 2015-02-12 19:32 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netjoin.dll
2015-02-12 19:32 - 2015-02-12 19:32 - 00068864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-02-12 19:31 - 2015-02-12 19:31 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2015-02-12 19:31 - 2015-02-12 19:31 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSATAPI.dll
2015-02-12 19:31 - 2015-02-12 19:31 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2015-02-12 19:31 - 2015-02-12 19:31 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdmaud.drv
2015-02-12 19:31 - 2015-02-12 19:31 - 00020336 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2015-02-12 19:30 - 2015-02-12 19:30 - 02056192 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2015-02-12 19:30 - 2015-02-12 19:30 - 01363456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2015-02-12 19:30 - 2015-02-12 19:30 - 00166912 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll
2015-02-12 19:30 - 2015-02-12 19:30 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powrprof.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00975360 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2015-02-12 19:29 - 2015-02-12 19:29 - 00860672 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00772608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMPOSE.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasplap.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2015-02-12 19:29 - 2015-02-12 19:29 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\FXSUTILITY.dll
2015-02-12 19:29 - 2015-02-12 19:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2015-02-12 19:28 - 2015-02-12 19:28 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll
2015-02-12 19:28 - 2015-02-12 19:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2015-02-12 19:28 - 2015-02-12 19:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleprn.dll
2015-02-12 19:28 - 2015-02-12 19:28 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2015-02-12 19:28 - 2015-02-12 19:28 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\fdWNet.dll
2015-02-12 19:28 - 2015-02-12 19:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWNet.dll
2015-02-12 19:27 - 2015-02-12 19:27 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspptp.sys
2015-02-12 19:26 - 2015-02-12 19:26 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2015-02-12 19:26 - 2015-02-12 19:26 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2015-02-12 19:25 - 2015-02-12 19:25 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-02-12 19:25 - 2015-02-12 19:25 - 00592384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-02-12 19:25 - 2015-02-12 19:25 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-02-12 19:25 - 2015-02-12 19:25 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-02-12 19:25 - 2015-02-12 19:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2015-02-12 19:24 - 2015-02-12 19:24 - 00534016 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2015-02-12 19:24 - 2015-02-12 19:24 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2015-02-12 19:24 - 2015-02-12 19:24 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2015-02-12 19:24 - 2015-02-12 19:24 - 00095088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-02-12 19:24 - 2015-02-12 19:24 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vds_ps.dll
2015-02-12 19:24 - 2015-02-12 19:24 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-02-12 19:23 - 2015-02-12 19:23 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-02-12 19:23 - 2015-02-12 19:23 - 01358848 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-02-12 19:23 - 2015-02-12 19:23 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2015-02-12 19:23 - 2015-02-12 19:23 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2015-02-12 19:23 - 2015-02-12 19:23 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2015-02-12 19:22 - 2015-02-12 19:22 - 00375808 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2015-02-12 19:22 - 2015-02-12 19:22 - 00323584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
2015-02-12 19:22 - 2015-02-12 19:22 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffdisk.sys
2015-02-12 19:22 - 2015-02-12 19:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2015-02-12 19:22 - 2015-02-12 19:22 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_mmc.sys
2015-02-12 19:21 - 2015-02-12 19:21 - 01426944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvbvm60.dll
2015-02-12 19:21 - 2015-02-12 19:21 - 00363904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2015-02-12 19:21 - 2015-02-12 19:21 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2015-02-12 19:21 - 2015-02-12 19:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll
2015-02-12 19:21 - 2015-02-12 19:21 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\version.dll
2015-02-12 19:21 - 2015-02-12 19:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\version.dll
2015-02-12 19:20 - 2015-02-12 19:20 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2015-02-12 19:20 - 2015-02-12 19:20 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2015-02-12 19:20 - 2015-02-12 19:20 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2015-02-12 19:20 - 2015-02-12 19:20 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2015-02-12 19:20 - 2015-02-12 19:20 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 00181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpipcfg.dll
2015-02-12 19:19 - 2015-02-12 19:19 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2015-02-12 19:19 - 2015-02-12 19:19 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiougc.exe
2015-02-12 19:18 - 2015-02-12 19:18 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\fdprint.dll
2015-02-12 19:18 - 2015-02-12 19:18 - 00069632 _____ () C:\Windows\system32\BWContextHandler.dll
2015-02-12 19:18 - 2015-02-12 19:18 - 00064000 _____ () C:\Windows\SysWOW64\BWContextHandler.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00608256 _____ (Microsoft Corporation) C:\Windows\system32\clbcatq.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00522240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clbcatq.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00472576 _____ (Microsoft Corporation) C:\Windows\system32\catsrv.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00449536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrv.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\colbact.dll
2015-02-12 19:17 - 2015-02-12 19:17 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\colbact.dll
2015-02-12 19:16 - 2015-02-12 19:16 - 01684408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-02-12 19:16 - 2015-02-12 19:16 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll
2015-02-12 19:16 - 2015-02-12 19:16 - 00473088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll
2015-02-12 19:16 - 2015-02-12 19:16 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2015-02-12 19:16 - 2015-02-12 19:16 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2015-02-12 19:15 - 2015-02-12 19:15 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\tspubwmi.dll
2015-02-12 19:15 - 2015-02-12 19:15 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-02-12 19:15 - 2015-02-12 19:15 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-02-12 19:15 - 2015-02-12 19:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\rdpsign.exe
2015-02-12 19:15 - 2015-02-12 19:15 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2015-02-12 19:14 - 2015-02-12 19:14 - 00581632 _____ (Microsoft Corporation) C:\Windows\system32\p2pcollab.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00412672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\p2pcollab.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\P2PGraph.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2015-02-12 19:14 - 2015-02-12 19:14 - 00334848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2PGraph.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2015-02-12 19:14 - 2015-02-12 19:14 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
2015-02-12 19:14 - 2015-02-12 19:14 - 00264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\p2pnetsh.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\p2pnetsh.dll
2015-02-12 19:14 - 2015-02-12 19:14 - 00088960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Synth3dVsc.sys
2015-02-12 19:13 - 2015-02-12 19:13 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
2015-02-12 19:12 - 2015-02-12 19:12 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2015-02-12 19:12 - 2015-02-12 19:12 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2015-02-12 19:12 - 2015-02-12 19:12 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2015-02-12 19:12 - 2015-02-12 19:12 - 00148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2015-02-12 19:12 - 2015-02-12 19:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\dtsh.dll
2015-02-12 19:12 - 2015-02-12 19:12 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtsh.dll
2015-02-12 19:11 - 2015-02-12 19:11 - 00458240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSXP32.dll
2015-02-12 19:11 - 2015-02-12 19:11 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll
2015-02-12 19:11 - 2015-02-12 19:11 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys
2015-02-12 19:10 - 2015-02-12 19:10 - 04835328 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2015-02-12 19:10 - 2015-02-12 19:10 - 03405312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2015-02-12 19:10 - 2015-02-12 19:10 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\auditcse.dll
2015-02-12 19:10 - 2015-02-12 19:10 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll
2015-02-12 19:10 - 2015-02-12 19:10 - 00098816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdBth.dll
2015-02-12 19:10 - 2015-02-12 19:10 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2015-02-12 19:10 - 2015-02-12 19:10 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2015-02-12 19:09 - 2015-02-12 19:09 - 01159680 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2015-02-12 19:09 - 2015-02-12 19:09 - 00782336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00977920 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\glu32.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twext.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glu32.dll
2015-02-12 19:08 - 2015-02-12 19:08 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2015-02-12 19:07 - 2015-02-12 19:07 - 00573952 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2015-02-12 19:07 - 2015-02-12 19:07 - 00257536 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2015-02-12 19:07 - 2015-02-12 19:07 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2015-02-12 19:07 - 2015-02-12 19:07 - 00228864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2015-02-12 19:07 - 2015-02-12 19:07 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spp.dll
2015-02-12 19:06 - 2015-02-12 19:06 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-02-12 19:06 - 2015-02-12 19:06 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2015-02-12 19:06 - 2015-02-12 19:06 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll
2015-02-12 19:06 - 2015-02-12 19:06 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2015-02-12 19:06 - 2015-02-12 19:06 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2015-02-12 19:06 - 2015-02-12 19:06 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2015-02-12 19:05 - 2015-02-12 19:05 - 00958464 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-02-12 19:05 - 2015-02-12 19:05 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2015-02-12 19:05 - 2015-02-12 19:05 - 00346624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2015-02-12 19:05 - 2015-02-12 19:05 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-02-12 19:05 - 2015-02-12 19:05 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\format.com
2015-02-12 19:05 - 2015-02-12 19:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\format.com
2015-02-12 19:05 - 2015-02-12 19:05 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwf.sys
2015-02-12 19:04 - 2015-02-12 19:04 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-02-12 19:04 - 2015-02-12 19:04 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-02-12 19:04 - 2015-02-12 19:04 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2015-02-12 19:04 - 2015-02-12 19:04 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\proquota.exe
2015-02-12 19:03 - 2015-02-12 19:03 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-02-12 19:03 - 2015-02-12 19:03 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
2015-02-12 19:03 - 2015-02-12 19:03 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-02-12 19:03 - 2015-02-12 19:03 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-02-12 19:03 - 2015-02-12 19:03 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 03243008 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 01942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00112568 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-02-12 19:02 - 2015-02-12 19:02 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-02-12 19:02 - 2015-02-12 19:02 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-02-12 19:02 - 2015-02-12 19:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-02-12 19:02 - 2015-02-12 19:02 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-02-12 19:02 - 2015-02-12 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-02-12 19:02 - 2015-02-12 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 01727928 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00533200 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-02-12 19:01 - 2015-02-12 19:01 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-02-12 19:01 - 2015-02-12 19:01 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-02-12 19:01 - 2015-02-12 19:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-02-12 19:00 - 2015-02-12 19:00 - 01480704 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 01175040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-02-12 19:00 - 2015-02-12 19:00 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-02-12 19:00 - 2015-02-12 19:00 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-02-12 19:00 - 2015-02-12 19:00 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-02-12 18:59 - 2015-02-12 18:59 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-02-12 18:59 - 2015-02-12 18:59 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-02-12 18:59 - 2015-02-12 18:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-02-12 18:58 - 2015-02-12 18:58 - 00192448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-02-12 18:58 - 2015-02-12 18:58 - 00186808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2015-02-12 18:58 - 2015-02-12 18:58 - 00050616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2015-02-12 18:58 - 2015-02-12 18:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Magnification.dll
2015-02-12 18:58 - 2015-02-12 18:58 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnification.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 00145408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\korwbrkr.dll
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2015-02-12 18:57 - 2015-02-12 18:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2015-02-12 18:56 - 2015-02-12 18:56 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-12 18:56 - 2015-02-12 18:56 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-12 18:56 - 2015-02-12 18:56 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-12 18:56 - 2015-02-12 18:56 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-12 18:55 - 2015-02-12 18:55 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-02-12 18:55 - 2015-02-12 18:55 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-02-12 18:55 - 2015-02-12 18:55 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-02-12 18:55 - 2015-02-12 18:55 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2015-02-12 18:55 - 2015-02-12 18:55 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2015-02-12 18:55 - 2015-02-12 18:55 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2015-02-12 18:54 - 2015-02-12 18:54 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2015-02-12 18:54 - 2015-02-12 18:54 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2015-02-12 18:54 - 2015-02-12 18:54 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2015-02-12 18:54 - 2015-02-12 18:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2015-02-12 18:54 - 2015-02-12 18:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2015-02-12 18:53 - 2015-02-12 18:53 - 04357632 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2015-02-12 18:53 - 2015-02-12 18:53 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2015-02-12 18:53 - 2015-02-12 18:53 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2015-02-12 18:53 - 2015-02-12 18:53 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2015-02-12 18:53 - 2015-02-12 18:53 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2015-02-12 18:53 - 2015-02-12 18:53 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2015-02-12 18:52 - 2015-02-12 18:52 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-02-12 18:52 - 2015-02-12 18:52 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-02-12 18:51 - 2015-02-12 18:51 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2015-02-12 18:51 - 2015-02-12 18:51 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2015-02-12 18:51 - 2015-02-12 18:51 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2015-02-12 18:50 - 2015-02-12 18:50 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2015-02-12 18:50 - 2015-02-12 18:50 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00237568 _____ (Microsoft Corporation) C:\Windows\system32\wecsvc.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\wecutil.exe
2015-02-12 18:49 - 2015-02-12 18:49 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wecapi.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecutil.exe
2015-02-12 18:49 - 2015-02-12 18:49 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_AuthenticAMD.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecapi.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2015-02-12 18:49 - 2015-02-12 18:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2015-02-12 18:48 - 2015-02-12 18:48 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2015-02-12 18:48 - 2015-02-12 18:48 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2015-02-12 18:46 - 2015-02-12 18:46 - 01742848 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 01065984 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 01039872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00240128 _____ (Microsoft Corporation) C:\Windows\system32\cscobj.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00213848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2015-02-12 18:46 - 2015-02-12 18:46 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\appmgmts.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00149504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgmts.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscobj.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\CscMig.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3msm.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2015-02-12 18:46 - 2015-02-12 18:46 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3api.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3gpclnt.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\tcpmonui.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00071680 _____ () C:\Windows\system32\PrintBrmUi.exe
2015-02-12 18:46 - 2015-02-12 18:46 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpmonui.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwififlt.sys
2015-02-12 18:46 - 2015-02-12 18:46 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2015-02-12 18:46 - 2015-02-12 18:46 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\dot3gpclnt.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2015-02-12 18:46 - 2015-02-12 18:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3dlg.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\gpprnext.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\tcpmib.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscapi.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprnext.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpmib.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\svchost.exe
2015-02-12 18:46 - 2015-02-12 18:46 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscdll.dll
2015-02-12 18:46 - 2015-02-12 18:46 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
2015-02-12 18:46 - 2015-02-12 18:46 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwifimp.sys
2015-02-12 18:46 - 2015-02-12 18:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2015-02-12 18:45 - 2015-02-12 18:45 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2015-02-12 18:45 - 2015-02-12 18:45 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2015-02-12 18:45 - 2015-02-12 18:45 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2015-02-12 18:45 - 2015-02-12 18:45 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2015-02-12 18:45 - 2015-02-12 18:45 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2015-02-12 18:45 - 2015-02-12 18:45 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2015-02-12 18:44 - 2015-02-12 18:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2015-02-12 18:44 - 2015-02-12 18:44 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscmmc.dll
2015-02-12 18:44 - 2015-02-12 18:44 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2015-02-12 18:44 - 2015-02-12 18:44 - 00043520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2015-02-12 18:44 - 2015-02-12 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2015-02-12 18:44 - 2015-02-12 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2015-02-12 18:43 - 2015-02-12 18:43 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2015-02-12 18:43 - 2015-02-12 18:43 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2015-02-12 18:42 - 2015-02-12 18:42 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2015-02-12 18:42 - 2015-02-12 18:42 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2015-02-12 18:42 - 2015-02-12 18:42 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2015-02-12 18:42 - 2015-02-12 18:42 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2015-02-12 18:42 - 2015-02-12 18:42 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2015-02-12 18:42 - 2015-02-12 18:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2015-02-12 18:42 - 2015-02-12 18:42 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-02-12 18:42 - 2015-02-12 18:42 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2015-02-12 18:42 - 2015-02-12 18:42 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-02-12 18:42 - 2015-02-12 18:42 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-02-12 18:42 - 2015-02-12 18:42 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-02-12 18:41 - 2015-02-12 18:41 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-02-12 18:41 - 2015-02-12 18:41 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-02-12 18:40 - 2015-02-12 18:40 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2015-02-12 18:40 - 2015-02-12 18:40 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2015-02-12 18:40 - 2015-02-12 18:40 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2015-02-12 18:40 - 2015-02-12 18:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2015-02-12 18:39 - 2015-02-12 18:39 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2015-02-12 18:39 - 2015-02-12 18:39 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2015-02-12 18:39 - 2015-02-12 18:39 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\modem.sys
2015-02-12 18:39 - 2015-02-12 18:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2015-02-12 18:39 - 2015-02-12 18:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2015-02-12 18:38 - 2015-02-12 18:38 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2015-02-12 18:38 - 2015-02-12 18:38 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2015-02-12 18:38 - 2015-02-12 18:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAL.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINDEV.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTAM.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINORI.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAR.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAL.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINKAN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINHIN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINDEV.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBEN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINPUN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINGUJ.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINEN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE2.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE1.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINASA.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTEL.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINPUN.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINGUJ.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE2.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE1.DLL
2015-02-12 18:38 - 2015-02-12 18:38 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINASA.DLL
2015-02-12 18:37 - 2015-02-12 18:37 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2015-02-12 18:37 - 2015-02-12 18:37 - 00601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PerfCenterCPL.dll
2015-02-12 18:37 - 2015-02-12 18:37 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\netcfg.exe
2015-02-12 18:36 - 2015-02-12 18:36 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2015-02-12 18:36 - 2015-02-12 18:36 - 00296960 _____ (Microsoft Corporation) C:\Windows\winhlp32.exe
2015-02-12 18:36 - 2015-02-12 18:36 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
2015-02-12 18:36 - 2015-02-12 18:36 - 00195072 _____ (Microsoft Corporation) C:\Windows\system32\ftsrch.dll
2015-02-12 18:36 - 2015-02-12 18:36 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2015-02-12 18:36 - 2015-02-12 18:36 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2015-02-12 18:36 - 2015-02-12 18:36 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2015-02-12 18:36 - 2015-02-12 18:36 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2015-02-12 18:36 - 2015-02-12 18:36 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2015-02-12 18:36 - 2015-02-12 18:36 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2015-02-12 18:36 - 2015-02-12 18:36 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
2015-02-12 18:36 - 2015-02-12 18:36 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\ftlx041e.dll
2015-02-12 18:36 - 2015-02-12 18:36 - 00009216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
2015-02-12 18:36 - 2015-02-12 18:36 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\ftlx0411.dll
2015-02-06 15:36 - 2014-11-29 04:07 - 00180648 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-15 11:20 - 2010-11-21 07:17 - 00010290 _____ () C:\Windows\PFRO.log
2015-02-15 11:17 - 2009-07-14 08:15 - 00016864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-15 11:17 - 2009-07-14 08:15 - 00016864 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-15 11:15 - 2009-07-14 08:38 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-15 11:15 - 2009-07-14 08:21 - 00025028 _____ () C:\Windows\setupact.log
2015-02-14 23:04 - 2014-10-17 14:28 - 00000000 ____D () C:\Users\Administrator\Desktop\New folder
2015-02-14 18:16 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\rescache
2015-02-14 17:04 - 2009-07-14 08:43 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-14 13:50 - 2009-07-14 09:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-02-14 13:50 - 2009-07-14 08:16 - 00002814 _____ () C:\Windows\DtcInstall.log
2015-02-14 13:50 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\sysprep
2015-02-14 13:47 - 2010-11-21 10:46 - 00000000 ____D () C:\Windows\CSC
2015-02-14 13:45 - 2009-07-14 09:08 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-02-14 13:45 - 2009-07-14 09:02 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-02-14 05:45 - 2009-07-14 03:24 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\themeservice.dll
2015-02-14 05:41 - 2009-07-14 06:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-14 05:40 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-02-14 05:16 - 2009-07-14 08:15 - 00269512 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-14 04:45 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\Resources
2015-02-14 04:44 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\Web
2015-02-14 04:43 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\Globalization
2015-02-14 02:46 - 2009-07-14 09:02 - 00000000 ____D () C:\Windows\system32\restore
2015-02-14 02:43 - 2009-07-14 06:50 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-02-14 02:39 - 2009-07-14 08:27 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-02-14 02:32 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\Recovery
2015-02-12 21:20 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-02-12 21:20 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\Dism
2015-02-12 21:04 - 2009-07-14 09:02 - 00000000 ____D () C:\Program Files\Windows Defender
2015-02-12 21:04 - 2009-07-14 09:02 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-02-12 20:57 - 2009-07-14 06:50 - 00000000 ____D () C:\Program Files\Common Files\System
2015-02-12 19:58 - 2009-07-14 06:06 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2015-02-12 19:58 - 2009-07-14 06:06 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2015-02-12 19:31 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\oobe
2015-02-12 19:27 - 2009-07-14 09:02 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-02-12 19:27 - 2009-07-14 09:02 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-02-12 19:03 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\tracing
2015-02-12 18:59 - 2010-11-21 10:46 - 00000000 ____D () C:\Program Files\Windows Journal
2015-02-12 18:56 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\AppCompat
2015-02-12 18:41 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2015-02-12 18:41 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2015-02-12 18:41 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\zh-HK
2015-02-12 18:41 - 2009-07-14 06:50 - 00000000 ____D () C:\Windows\system32\tr-TR

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\bassmod.dll
C:\Users\Administrator\AppData\Local\Temp\devcon.exe
C:\Users\Administrator\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Administrator\AppData\Local\Temp\sfareca00001.dll
C:\Users\Administrator\AppData\Local\Temp\sfextra.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-02-14 03:25

==================== End Of Log ============================



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,532 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:44 AM

Posted 15 February 2015 - 09:34 AM

Greetings,

What symptoms are you seeing that leads you to believe you are infected?

After the fresh install of the operating system did you transfer files (like documents, pictures, etc.) back onto the computer from an external drive or other device?

Did you use the cloud to import information back onto your computer?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 16 February 2015 - 07:01 AM

Hi Oh My!

No i didn't transfer any data to new OS. about symptoms:

state of some folders and files changed to "Shared" and after that, again svchost - netsvcs started to fill memory and pagefile .....

Here some of changed file and folders:

 

Internet Explorer folder both x86 and x64

C:\ProgramData\Microsoft\Windows\Start Menu

C:\Windows\TEMP

C:\Windows\Installer

C:\Windows\SysWOW64\pngfilt.dll
C:\Windows\SysWOW64\tdc.ocx
C:\Windows\SysWOW64\url.dll
C:\Windows\SysWOW64\webcheck.dll
C:\Windows\SysWOW64\wextract.exe
C:\Windows\SysWOW64\iexpress.exe
C:\Windows\SysWOW64\inseng.dll
C:\Windows\SysWOW64\licmgr10.dll

C:\Windows\System32\msfeedssync.exe
C:\Windows\System32\msls31.dll
C:\Windows\System32\RegisterIEPKEYs.exe
C:\Windows\System32\SetIEInstalledDate.exe
C:\Windows\System32\html.iec
C:\Windows\System32\icardie.dll
C:\Windows\System32\ieapfltr.dat
C:\Windows\System32\iesysprep.dll
C:\Windows\System32\ieuinit.inf
C:\Windows\System32\iexpress.exe
C:\Windows\System32\inseng.dll
C:\Windows\System32\licmgr10.dll
C:\Windows\System32\mshtmler.dll
C:\Windows\System32\tdc.ocx
C:\Windows\System32\url.dll
C:\Windows\System32\webcheck.dll
C:\Windows\System32\wextract.exe
C:\Windows\System32\iepeers.dll
C:\Windows\System32\IEAdvpack.dll
C:\Windows\System32\jsIntl.dll
C:\Windows\System32\msfeedsbs.dll

 

Thank



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,532 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:44 AM

Posted 16 February 2015 - 03:36 PM

There is no evidence of malware on your computer. Can you tell me if you have done a factory reset of your router?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 alir32a

alir32a
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:01:14 PM

Posted 17 February 2015 - 12:59 PM

Hi Oh My!

 

Yes i've done factory reset my router. Also i called my ISP provider support about strange IP changes. My IP was changing each day, once Greek, once Romania, once Unknown and ....

They said problem comes from their Server and will fixed!

It seems this time ISP server is hacked   :thumbdown:

 

Now it's about 2 days, i've no problem!

I again installed new fresh OS and now i'm using these protections toghether:

ESET Smart Security

Malwarebyte Anti-Malware

Malwarebyte Anti-Exploit

 

It's first time after about 15 years that i have to use these protection softwares! 2015 is bad year! Beware!   B)

 

Any way Thank you and Thank Great Bleepingcomputer!



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,532 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:44 AM

Posted 17 February 2015 - 01:51 PM

You are quite welcome, I am glad you were able to resolve it. I must say this is the first time I have dealt with this.....

Allow me to leave you with some general information to consider before we part ways.

===================================================

Keeping Your Computer Safe

----------

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read: Simple and easy ways to keep your computer safe and secure on the Internet.

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:In addition, here are some more links you might find of interest:Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. OhMy_done.gif
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users