Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Home network compromised?


  • This topic is locked This topic is locked
46 replies to this topic

#1 MrBlahh

MrBlahh

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 12 January 2016 - 08:19 PM

Hello,

 

I am so sorry but I cannot post a Farbar Recovery Scan log.

 

 

In Firefox when I try to download, the 'Opening FRST.exe' with the Save button gets a notification dialogue pop up stating:

 

C:\Users\pc\AppData\Local\Temp\e7xKkh8T.exe.part could not be saved, because the source file could not be read.

Try again later, or contact the server administrator.

 

I can press OK on this and attempt to save the file, but it is then 0 bytes on my hard drive and trying to open it I am informed it may be corrupted.

 

I tried with Google Chrome and received an Unknown network error.

 

-

 

Context

 

I recently moved to Viet Nam and am staying with a friend. It's a security nightmare because within a week he'd left the front door unlocked and someone took our 2 laptops. He immediately went out and bought a new one for himself and kindly got me a second hand old Dell Latitude. Now I've found this home network is probably compromised as well....

 

I had been setting up my new (old) Dell machine, including installing the drivers from Dell, and then Avast! informed me some files were infected. The files were all those drivers I had just downloaded from Dell's website. I'm now convinced that source (official Dell downloads) is secure and that the infection has come from this network somehow. Anyway, Avast! placed the Dell drivers into it's Virus Chest and seemed happy.

 

Then I ran Malwarebytes just to be sure and it found 22 infections with things like 'Worm' and 'PUP' in the names. I let it fix the problems and ran it again and this scan came up with Backdoor.Bot so I let it fix that and the next scan came up clean.

 

After that I scanned with Trend Micro's Housecall online scan and it gave me one result: a Rootkit. It said it fixed the problem but when I scanned again the exact same Rootkit result came up again.

 

I then tried Malwarebytes Anti-Rootkit Beta (sorry, memory is a little hazy here) but I think it fixed it and after a reboot of the system the problem was back again.

 

This was enough to know I am probably seriously compromised but I needed to ascertain if it was because it's a second hand computer from a dodgy background or if it was my friend's home network I'm using that was infected.

 

So before coming here I installed Malwarebytes on his brand new machine and it resulted in HackTool.Agent which pretty much confirms to me that this network has serious problems.

 

Whilst writing this post I forgot exactly the name of what Housecall found so I just scanned again and it's come up with a load of infected executables. These are programs I had copied over from formerly clean and protected external backup drives so it looks like something is jumping on any executables I download or copy onto the machine, and it's possibly even on my backup drives.

 

 

 

I've gone as far as I can and it's going to take a specialist to get me out of this mess. I can't download Farbar Recovery Tool from majorgeeks dot com either, after I desperately tried an alternative link.

 

 

 

I think I'm now drowning in a huge mess not of my own making, please save me!

 

 

 

 

 

[Edit]

 

I had the bright idea of downloading the Farbar Recovery Tool to my friend's laptop and copying to a USB drive. Since everything is compromised already it seemed worth trying. I pasted it onto my own laptop and the executable showed a correct file size this time... then after about 3 seconds it just completely disappeared. I tried again, same thing.


Edited by MrBlahh, 12 January 2016 - 10:27 PM.


BC AdBot (Login to Remove)

 


#2 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 16 January 2016 - 10:04 AM

I realize we've been asked not to bump our topics but now that others who posted a day after this thread have begun to be answered I figured I have nothing to lose (even ones posted just for one day).

 

And unfortunately I am forced to use this machine as I have no other.


Edited by MrBlahh, 16 January 2016 - 11:12 AM.


#3 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 06:25 AM

After 4 days waiting and using this infected computer since I first posted (and numerous other topics posted since then that are already receiving help) I must at least do something.

 

I scanned with Rkill and it reported no issues found on anything except for:

 

"Checking for processes to terminate:

 * C:\Windows\system32\srvany.exe (PID: 2620) [WD-HEUR]

1 proccess terminated!"

 

...which I believe is not necessarily a sign the process is infected.

 

 

 

I also scanned with Rogue Killer. It found nothing except for under the registry tab, where it came up with a PUM I believe related to KML Player for Pandora TV. I had already uninstalled the KML Player when I first received the machine since I use VLC so I allowed Rogue Killer to delete the loitering registry value for Pandora.



#4 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 02:24 PM

I guess I can make use of my alone-time with this topic to at least collate everything I've done so far before copying all the information to a community that will help myself and my friend. I've given up waiting for help from this particular site given I waited patiently for days. I was willing to wait for "on average five days" to get a response but have finally Iost faith my existence will ever be acknowledged after others who posted since I made my topic and were answered already, some within a day of posting theirs.

Having had my own computer stolen then ending up on an old, infected second hand machine as my only option, and with my friend also patiently waiting for me to help him with his machine, the following threads do nothing but depress me even more:

 

http://www.bleepingcomputer.com/forums/t/602449/please-see-my-list-thank-you/

http://www.bleepingcomputer.com/forums/t/602444/hijack-this-results/

http://www.bleepingcomputer.com/forums/t/602381/google-chrome-freezes-up/

http://www.bleepingcomputer.com/forums/t/602193/browser-hijack/

http://www.bleepingcomputer.com/forums/t/602265/dns-probe-finished-nxdomain/

http://www.bleepingcomputer.com/forums/t/602546/processes-running-rampant/

http://www.bleepingcomputer.com/forums/t/602117/requested-to-post-topic-here-to-check-if-infected-please-help/

http://www.bleepingcomputer.com/forums/t/602493/orionzerohorizon-promotebuy-targeted-traffic-popping-up-in-google-chrome/

http://www.bleepingcomputer.com/forums/t/602484/rundll32-requests-allowance-to-make-changes/

http://www.bleepingcomputer.com/forums/t/602194/infected-by-dnsapidll-block-all-internet-connection/

http://www.bleepingcomputer.com/forums/t/602464/computer-running-slow-and-internet-times-out-in-browser/

 

Apparently I am to sit here endlessly and not ask for help anywhere else unless I ask for this to be closed. Well once I have updated the thread with my latest attempt to get somewhere I shall indeed ask for this to be closed so I can take my miserable situation elsewhere having waited and wasted both my own and my friend's time with bleepingcomputer.



#5 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 02:34 PM

I have also now tried ESET's online scanner and it came up with 3 results:

 

C:\Users\pc\Downloads\Programs\AdobeFlashPlayer16.0.0.235nonIE.exe    a variant of Win32/VB.QOT trojan
C:\Windows\Resources\Themes\icsys.icn.exe    a variant of Win32/VB.QOT trojan
E:\Inbox\PES 6\PES6 Next Season Patch 2016.rar    BAT/BadJoke.AP trojan

 

The third one on the E: drive may be a false positive because it's a patch for a game made by a fan who is an upstanding member of the gaming community. It's a patch to bring the transfers up to date for an old football game. I realize I may be wrong and that it is a genuine trojan, but I believe the patch works by modifying the game which is necessary. It is not a crack in terms of piracy.

 

I will now run the ESET scanner again and this time I will instruct it to delete the 2 Win32/VB.QOT variants.

Then I shall test the apparently infected game file with other programs.

 

Then I will probably post back here one final time before seeking help somewhere.



#6 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 03:38 PM

As an experiment I moved the potentially infected game file (actually it's a .rar archive) to a USB stick so during the second ESET scan it was not physically present on the system.

 

ESEST Online Scanner settings used in attempted cleanup:

 

 

 

Enable detection of potentially unwanted applications

 

Remove found threats

Scan archives

Scan for potentially unsafe applications

Enable Anti-Stealth technology

 

-

 

Scan results:

 

C:\Users\pc\Downloads\Programs\AdobeFlashPlayer16.0.0.235nonIE.exe    a variant of Win32/VB.QOT trojan    cleaned by deleting
C:\Windows\Resources\Themes\icsys.icn.exe    a variant of Win32/VB.QOT trojan    cleaned by deleting

 

Threats found and cleaned!

 

Now I will do the Trend Micro online scan again, followed by Malwarebytes and Malwarebytes Rootkit programs (though I have less faith in these 2 programs after my previous experience).



#7 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 05:06 PM

Since I still had a few ideas to try myself before seeking outside help (again) I figured I would continue for now to use this thread as my personal diary.

 

Note that I did not restart the system after the ESET scans because I figured that was just an opportunity for anything nasty to restart itself after ESET claimed to have cleaned up the Win32/VB.QOT trojan variant.

 

Malwarebytes reports my system is clean.

Malwarebytes Anti-Rootkit reports my system is clean.

 

Neither of those results surprise me, in fact the intention was just to confirm these 2 Malwarebytes products are currently of no use to me, along with Avast!, rkill and RogueKiller.

 

 

Also not surprising, was the result again from Trend Micro's Housecall that I have 1 infection - a 'Hidden file' - that it reported previously. I did not bother to attempt to fix it because last time (I did it twice) it claimed to fix the problem and after telling me to restart the system, found it again.

This time, I clicked on the 'Hidden file' link in the scan results that opened an info webpage that gives very little info. However, their webpage did offer a link to Trend Micro's own Rootkit Buster application.

I proceeded to download that and its scan came up clean! Add another program to the growing list of things that are not helping.

 

Now I can only think of trying Combofix, but really I don't feel qualified to use it so I suppose this will be my last post here and I shall go and seek help from someone more knowledgeable than I.

 

Thanks for nothing wasting my time bleepingcomputer. I could have written what has turned out to be nothing but a personal diary on Notepad.



#8 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,660 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:09 PM

Posted 17 January 2016 - 08:20 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/602072 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#9 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 17 January 2016 - 09:30 PM

I do not have the original Windows 7 disc, as this operating system appears to have been installed by someone in the used computer shop where my friend bought it from (please see the OP).

 

I cannot supply an FRST log as described in the OP.



#10 satchfan

satchfan

  • Malware Response Team
  • 2,666 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:09:09 PM

Posted 18 January 2016 - 03:03 AM

Hello MrBlahh and welcome to Bleeping Computer.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please delete the previous copy you have and download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

If that still won't run, please try running it in safe mode:

How to start Windows in Safe Mode - Windows 7/Vista

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#11 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 18 January 2016 - 06:48 AM

Hello Satchfan,
 
Thank you for helping, it's greatly appreciated!

 

Between them, AdwCleaner and JRT already found some issues and it enabled me to also be able to download and run FRST, so great progress has being made.

 

Please find attached the AdwCleaner log as requested.

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Ultimate x86
Ran by pc (Administrator) on Mon 01/18/2016 at 18:13:24.92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 12

Failed to delete: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U7SBPVBG (Folder)
Failed to delete: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YODXBER0 (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30N2DZ5R (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\60YKPYUO (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HLB8KX06 (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HUIZ4DWG (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JN58N60S (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH770A2B (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PH6Q27T2 (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QX2WSBSG (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WIYXLOCU (Folder)
Successfully deleted: C:\Users\pc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XK4ZP3I5 (Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 01/18/2016 at 18:14:52.58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

 

Attached Files



#12 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 18 January 2016 - 06:51 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-01-2015
Ran by pc (administrator) on 0420141230TFW (18-01-2016 18:19:57)
Running from C:\Users\pc\Desktop
Loaded Profiles: pc (Available Profiles: pc)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AEstSrv.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
() C:\Windows\System32\srvany.exe
(O2Micro.) C:\Windows\System32\SDIOAssist.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [USB Security] => C:\Program Files\USB Disk Security\USBGuard.exe [670920 2013-05-30] (Zbshareware Lab)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [559448 2013-07-09] (Alps Electric Co., Ltd.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-17] (Renesas Electronics Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [536668 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5955072 2011-01-18] (Dell Inc.)
HKLM\...\Run: [FreeFallProtection] => C:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686744 2012-09-05] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2016-01-13] (AVAST Software)
HKU\S-1-5-21-715854880-2641705681-1363900585-1000\...\Run: [UniKey] => C:\unikey\UniKeyNT.exe [334848 2014-01-19] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-01-13] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2016-01-11]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 198.41.0.4
Tcpip\..\Interfaces\{379F7B74-7FE1-46E9-8BAA-3C1212B4E296}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4AD9E334-5EB2-47BE-A84C-F8C3A5294019}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5BB83769-4C8E-459C-88FC-2C91D1459876}: [NameServer] 208.67.222.222,208.67.220.220
Tcpip\..\Interfaces\{5BB83769-4C8E-459C-88FC-2C91D1459876}: [DhcpNameServer] 192.168.100.1 198.41.0.4

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-13] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\4n8orvp9.default
FF Homepage: hxxp://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-11] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-04] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Extension: Adblock Plus - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\4n8orvp9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-11]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-13]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-01-13]

Chrome:
=======
CHR Profile: C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-01-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-11]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-01-13]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2016-01-13] (AVAST Software)
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [279024 2013-03-14] (Intel Corporation)
R2 Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [826312 2012-10-24] (Broadcom Corporation)
R2 Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [31688 2012-10-24] (Broadcom Corporation)
S2 DellDigitalDelivery; C:\Program Files\Dell Digital Delivery\DeliveryService.exe [202248 2014-04-11] (Dell Products, LP.)
R3 ICCS; C:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [169752 2012-04-24] (Intel Corporation)
R2 Intel® PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [121240 2013-01-03] (Intel Corporation)
S2 KMService; C:\Windows\system32\srvany.exe [8192 2014-03-31] () [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [72296 2010-02-11] (O2Micro International)
R2 O2SDIOAssist; C:\Windows\system32\srvany.exe [8192 2014-03-31] () [File not signed]
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [274514 2011-01-25] (IDT, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5210112 2011-01-18] (Dell Inc.) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Acceler; C:\Windows\System32\DRIVERS\accelern.sys [44144 2012-05-23] (ST Microelectronics)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2016-01-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2016-01-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2016-01-13] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2016-01-13] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2016-01-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436360 2016-01-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [117712 2016-01-13] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2016-01-13] (AVAST Software)
R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18496 2011-01-18] (Broadcom Corporation)
R3 BTWAMPFL; C:\Windows\System32\DRIVERS\btwampfl.sys [302120 2016-01-11] (Broadcom Corporation.)
R3 cvusbdrv; C:\Windows\System32\Drivers\cvusbdrv.sys [41480 2012-10-24] (Broadcom Corporation)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-08-30] (Windows ® Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2016-01-11] (Disc Soft Ltd)
R3 e1cexpress; C:\Windows\System32\DRIVERS\e1c6232.sys [368392 2013-02-20] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [48928 2013-01-24] (Intel Corporation)
S3 NETwNs32; C:\Windows\System32\DRIVERS\NETwsn00.sys [10385824 2014-12-15] (Intel Corporation)
R3 O2MDFRDR; C:\Windows\System32\DRIVERS\O2MDFw7.sys [60904 2011-01-05] (O2Micro )
R3 O2SDJRDR; C:\Windows\System32\DRIVERS\o2sdjw7.sys [63976 2011-03-24] (O2Micro )
R0 stdcfltn; C:\Windows\System32\DRIVERS\stdcfltn.sys [17904 2011-07-15] (ST Microelectronics)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-18 18:19 - 2016-01-18 18:20 - 00012322 _____ C:\Users\pc\Desktop\FRST.txt
2016-01-18 18:18 - 2016-01-18 18:19 - 00000000 ____D C:\FRST
2016-01-18 18:17 - 2016-01-18 18:17 - 01721856 _____ (Farbar) C:\Users\pc\Desktop\FRST.exe
2016-01-18 18:14 - 2016-01-18 18:14 - 00002024 _____ C:\Users\pc\Desktop\JRT.txt
2016-01-18 18:12 - 2016-01-18 18:12 - 01600184 _____ (Malwarebytes) C:\Users\pc\Desktop\JRT.exe
2016-01-18 18:10 - 2016-01-18 17:57 - 00001328 _____ C:\Users\pc\Desktop\AdwCleaner[C1].txt
2016-01-18 17:54 - 2016-01-18 17:57 - 00000000 ____D C:\AdwCleaner
2016-01-18 17:44 - 2016-01-18 17:44 - 01505280 _____ C:\Users\pc\Desktop\adwcleaner_5.030.exe
2016-01-18 06:21 - 2016-01-18 06:24 - 00000000 ____D C:\Users\pc\AppData\Roaming\Mp3tag
2016-01-18 06:20 - 2016-01-18 06:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2016-01-18 06:20 - 2016-01-18 06:20 - 00000000 ____D C:\Program Files\Mp3tag
2016-01-18 01:03 - 2016-01-18 01:03 - 00000000 ____D C:\Program Files\ESET
2016-01-18 00:51 - 2016-01-18 00:51 - 00000000 ____D C:\Users\pc\AppData\Local\CrashDumps
2016-01-17 22:34 - 2016-01-17 22:34 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2016-01-17 22:31 - 2016-01-17 22:31 - 00000000 ____D C:\Users\pc\Documents\KONAMI
2016-01-17 21:31 - 2016-01-17 21:31 - 00000000 _____ C:\Users\pc\Desktop\email.txt
2016-01-17 02:43 - 2016-01-17 02:43 - 00000000 ____H C:\Users\pc\Documents\Default.rdp
2016-01-17 02:06 - 2016-01-17 02:48 - 00030848 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-01-17 02:06 - 2016-01-17 02:42 - 00000000 ____D C:\ProgramData\RogueKiller
2016-01-14 03:21 - 2016-01-14 03:21 - 00000000 ____D C:\Users\Default\AppData\Roaming\AVAST Software
2016-01-14 03:21 - 2016-01-14 03:21 - 00000000 ____D C:\Users\Default User\AppData\Roaming\AVAST Software
2016-01-13 07:57 - 2016-01-13 07:57 - 00000010 _____ C:\Users\pc\AppData\Local\sponge.last.runtime.cache
2016-01-13 05:23 - 2016-01-18 04:24 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-01-13 05:09 - 2016-01-18 04:33 - 00458769 _____ C:\Users\pc\AppData\Local\census.cache
2016-01-13 05:09 - 2016-01-18 04:33 - 00131815 _____ C:\Users\pc\AppData\Local\ars.cache
2016-01-13 04:58 - 2016-01-13 04:58 - 00000036 _____ C:\Users\pc\AppData\Local\housecall.guid.cache
2016-01-13 04:58 - 2015-12-24 20:03 - 00305928 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2016-01-13 04:06 - 2016-01-18 04:06 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-01-13 04:06 - 2016-01-18 04:03 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-01-13 04:06 - 2016-01-13 04:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-01-13 04:06 - 2016-01-13 04:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-13 04:06 - 2016-01-13 04:06 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-01-13 04:06 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-01-13 04:06 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-01-13 03:43 - 2016-01-13 03:43 - 00000000 ___HD C:\Windows\PIF
2016-01-13 03:35 - 2016-01-13 03:35 - 00000000 __RSH C:\MSDOS.SYS
2016-01-13 03:35 - 2016-01-13 03:35 - 00000000 __RSH C:\IO.SYS
2016-01-13 02:58 - 2016-01-13 02:48 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-01-13 02:50 - 2016-01-13 02:50 - 00000000 ____D C:\Users\pc\AppData\Roaming\AVAST Software
2016-01-13 02:50 - 2016-01-13 02:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-01-13 02:49 - 2016-01-13 02:50 - 00436360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-01-13 02:49 - 2016-01-13 02:50 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-01-13 02:49 - 2016-01-13 02:49 - 00000000 ____D C:\Program Files\Common Files\AV
2016-01-13 02:49 - 2016-01-13 02:48 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-01-13 02:49 - 2016-01-13 02:48 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-01-13 02:49 - 2016-01-13 02:48 - 00117712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-01-13 02:49 - 2016-01-13 02:48 - 00081728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-01-13 02:49 - 2016-01-13 02:48 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-01-13 02:49 - 2016-01-13 02:48 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-01-13 02:48 - 2016-01-13 02:48 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-01-13 02:45 - 2016-01-13 02:45 - 00000000 ____D C:\Program Files\AVAST Software
2016-01-13 02:30 - 2016-01-13 02:30 - 00000000 ____D C:\ProgramData\AVAST Software
2016-01-13 01:23 - 2016-01-13 01:23 - 00000000 ____D C:\Users\pc\Documents\Darkest
2016-01-13 00:37 - 2016-01-13 00:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-01-13 00:37 - 2016-01-13 00:37 - 00000000 ____D C:\Program Files\7-Zip
2016-01-12 23:50 - 2016-01-13 01:43 - 00000000 ____D C:\Users\pc\AppData\LocalLow\uTorrent
2016-01-12 23:11 - 2016-01-12 23:11 - 00000000 ____D C:\Users\pc\AppData\Local\4kdownload.com
2016-01-12 23:10 - 2016-01-12 23:11 - 00000000 ____D C:\Users\pc\AppData\Roaming\Audacity
2016-01-12 21:59 - 2012-02-11 12:37 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2016-01-12 21:58 - 2011-02-25 12:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-01-12 21:56 - 2015-07-17 02:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-01-12 21:56 - 2015-07-17 02:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2016-01-12 21:56 - 2015-07-17 02:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2016-01-12 21:56 - 2015-07-16 22:14 - 00355840 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2016-01-12 21:56 - 2014-12-12 00:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2016-01-12 21:43 - 2015-06-10 02:35 - 02745856 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-01-12 21:43 - 2015-06-10 02:35 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-01-12 21:43 - 2015-06-09 22:17 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-01-12 21:00 - 2016-01-12 21:00 - 00000000 ____D C:\ProgramData\Brother
2016-01-12 20:59 - 2010-05-10 15:45 - 00103736 _____ (Brother Industries Ltd) C:\Windows\system32\BRRBTOOL.EXE
2016-01-12 20:59 - 2010-04-02 12:33 - 00025299 _____ (Brother Industries, Ltd) C:\Windows\system32\BRLM03A.DLL
2016-01-12 20:59 - 2010-02-05 09:42 - 00180224 _____ (Brother Industries, Ltd.) C:\Windows\system32\BROSNMP.DLL
2016-01-12 20:59 - 2005-01-17 14:10 - 00045056 _____ C:\Windows\system32\BRTCPCON.DLL
2016-01-12 20:59 - 2004-08-09 14:00 - 00000114 _____ C:\Windows\system32\BRLMW03A.INI
2016-01-12 20:59 - 2004-08-09 13:42 - 00077824 _____ (Brother Industries, Ltd.) C:\Windows\system32\BRLMW03A.DLL
2016-01-12 20:59 - 1999-10-26 23:00 - 00000050 _____ C:\Windows\system32\BRADM10A.DAT
2016-01-12 19:14 - 2015-10-09 06:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2016-01-12 19:14 - 2015-10-09 06:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2016-01-12 19:14 - 2015-10-09 06:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2016-01-12 19:14 - 2015-10-09 06:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2016-01-12 19:14 - 2015-10-09 02:13 - 00419928 _____ C:\Windows\system32\locale.nls
2016-01-12 18:51 - 2015-11-11 01:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-01-12 18:51 - 2015-11-11 01:39 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-01-12 18:51 - 2015-07-31 00:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2016-01-12 18:51 - 2015-02-03 10:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2016-01-12 18:51 - 2013-11-26 15:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-01-12 18:49 - 2015-02-04 09:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2016-01-12 18:16 - 2016-01-12 18:16 - 00000000 ____D C:\Users\pc\AppData\Local\GWX
2016-01-12 17:52 - 2014-06-27 08:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-01-12 17:48 - 2012-07-26 10:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2016-01-12 17:48 - 2012-07-26 10:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2016-01-12 17:48 - 2012-07-26 10:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2016-01-12 17:48 - 2012-07-26 10:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2016-01-12 17:48 - 2012-07-26 10:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2016-01-12 17:48 - 2012-07-26 09:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2016-01-12 17:48 - 2012-07-26 09:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2016-01-12 17:48 - 2012-06-02 21:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2016-01-12 17:45 - 2015-11-06 02:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-01-12 17:45 - 2015-08-06 00:40 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2016-01-12 17:45 - 2015-07-23 00:53 - 00937984 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-01-12 17:45 - 2015-07-23 00:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-12 17:45 - 2015-07-23 00:53 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2016-01-12 17:45 - 2015-07-22 23:38 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2016-01-12 17:45 - 2015-05-26 01:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2016-01-12 17:45 - 2015-05-26 01:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2016-01-12 17:45 - 2015-05-26 01:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2016-01-12 17:45 - 2015-05-26 01:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2016-01-12 17:45 - 2015-05-26 01:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2016-01-12 17:45 - 2015-05-26 01:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2016-01-12 17:45 - 2015-04-28 02:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-01-12 17:45 - 2015-04-28 02:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-01-12 17:45 - 2015-04-28 02:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-01-12 17:45 - 2015-04-28 02:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2016-01-12 17:45 - 2013-10-04 08:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2016-01-12 17:45 - 2013-10-04 08:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2016-01-12 17:44 - 2015-08-05 23:58 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2016-01-12 17:44 - 2015-07-18 20:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-01-12 17:44 - 2015-07-18 20:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-01-12 17:44 - 2015-06-25 16:48 - 00105408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2016-01-12 17:44 - 2015-06-25 16:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-01-12 17:44 - 2015-06-25 16:44 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2016-01-12 17:44 - 2015-01-29 10:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2016-01-12 17:44 - 2014-08-01 18:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2016-01-12 17:44 - 2014-02-04 09:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2016-01-12 17:44 - 2014-02-04 09:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2016-01-12 17:44 - 2014-02-04 09:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2016-01-12 17:44 - 2014-02-04 09:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2016-01-12 17:44 - 2014-01-28 09:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-01-12 17:44 - 2013-08-28 07:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2016-01-12 17:44 - 2013-03-19 10:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2016-01-12 17:44 - 2011-03-11 12:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2016-01-12 17:44 - 2011-03-11 12:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2016-01-12 17:44 - 2011-03-11 12:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2016-01-12 17:44 - 2011-03-11 12:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2016-01-12 17:44 - 2011-03-11 12:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2016-01-12 17:44 - 2011-03-11 12:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2016-01-12 17:44 - 2011-03-11 12:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2016-01-12 17:44 - 2011-03-11 11:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-01-12 17:43 - 2015-10-30 00:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2016-01-12 17:43 - 2015-10-30 00:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2016-01-12 17:43 - 2015-10-30 00:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2016-01-12 17:43 - 2015-10-30 00:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2016-01-12 17:43 - 2015-08-28 00:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2016-01-12 17:43 - 2015-08-28 00:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-01-12 17:43 - 2015-08-28 00:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2016-01-12 17:43 - 2015-08-28 00:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-01-12 17:43 - 2015-07-10 00:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2016-01-12 17:43 - 2015-07-10 00:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2016-01-12 17:43 - 2015-04-11 10:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2016-01-12 17:43 - 2014-11-26 10:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-01-12 17:43 - 2014-10-30 08:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2016-01-12 17:43 - 2014-07-09 08:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2016-01-12 17:43 - 2014-07-09 08:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2016-01-12 17:43 - 2014-07-09 08:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2016-01-12 17:43 - 2014-07-09 08:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2016-01-12 17:43 - 2014-07-09 08:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2016-01-12 17:43 - 2014-01-24 09:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-01-12 17:43 - 2013-10-30 09:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2016-01-12 17:43 - 2013-09-08 09:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-01-12 17:43 - 2013-08-05 08:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2016-01-12 17:43 - 2012-07-07 02:23 - 00393728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2016-01-12 17:43 - 2011-04-28 10:15 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2016-01-12 17:34 - 2014-10-03 08:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-01-12 17:34 - 2014-10-03 08:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2016-01-12 17:34 - 2014-10-03 08:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2016-01-12 17:34 - 2014-10-03 08:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2016-01-12 17:34 - 2014-10-03 08:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-01-12 14:15 - 2012-08-23 21:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2016-01-12 14:15 - 2012-08-23 18:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2016-01-12 14:14 - 2013-10-02 07:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2016-01-12 14:14 - 2013-10-02 07:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2016-01-12 14:14 - 2013-10-02 07:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-01-12 14:14 - 2013-10-02 07:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2016-01-12 14:14 - 2013-10-02 07:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2016-01-12 14:14 - 2013-10-02 06:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2016-01-12 14:14 - 2013-10-02 05:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2016-01-12 14:11 - 2012-12-07 19:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2016-01-12 14:11 - 2012-12-07 19:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2016-01-12 14:11 - 2012-12-07 17:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2016-01-12 14:11 - 2012-12-07 17:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2016-01-12 14:11 - 2012-01-04 15:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2016-01-12 14:10 - 2012-10-10 00:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2016-01-12 14:10 - 2012-10-10 00:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2016-01-12 14:09 - 2013-05-10 10:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2016-01-12 14:09 - 2013-01-24 11:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2016-01-12 14:09 - 2012-10-03 23:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2016-01-12 14:09 - 2012-10-03 23:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2016-01-12 14:09 - 2012-10-03 23:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2016-01-12 14:09 - 2012-10-03 22:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2016-01-12 14:09 - 2012-08-22 03:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2016-01-12 14:09 - 2012-07-05 02:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2016-01-12 14:09 - 2011-12-30 12:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2016-01-12 14:09 - 2011-06-16 11:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2016-01-12 14:09 - 2011-05-04 11:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2016-01-12 14:09 - 2011-05-04 11:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2016-01-12 14:09 - 2011-05-04 11:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2016-01-12 14:09 - 2011-05-04 11:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2016-01-12 14:09 - 2011-05-04 11:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2016-01-12 14:09 - 2011-05-04 11:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2016-01-12 14:09 - 2011-05-04 11:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2016-01-12 14:09 - 2011-05-04 11:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2016-01-12 14:09 - 2011-05-04 11:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2016-01-12 14:09 - 2011-02-18 12:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2016-01-12 14:06 - 2013-12-04 09:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2016-01-12 14:06 - 2013-12-04 09:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2016-01-12 14:06 - 2013-12-04 09:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2016-01-12 14:06 - 2013-12-04 09:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2016-01-12 14:06 - 2013-12-04 09:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2016-01-12 14:06 - 2013-12-04 08:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2016-01-12 14:06 - 2013-12-04 08:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2016-01-12 14:06 - 2013-12-04 08:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2016-01-12 14:06 - 2013-12-04 08:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-01-12 03:52 - 2016-01-12 03:52 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-01-12 03:52 - 2016-01-12 03:52 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2016-01-12 03:52 - 2016-01-12 03:52 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-01-12 03:52 - 2016-01-12 03:52 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2016-01-12 03:52 - 2016-01-12 03:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2016-01-12 03:52 - 2016-01-12 03:52 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2016-01-12 03:52 - 2016-01-12 03:52 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2016-01-12 03:49 - 2016-01-12 03:49 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2016-01-12 03:45 - 2016-01-12 03:45 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2016-01-12 01:51 - 2014-07-01 05:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2016-01-12 01:51 - 2014-06-06 13:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2016-01-12 01:51 - 2014-03-10 04:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2016-01-12 01:51 - 2014-03-10 04:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2016-01-12 01:51 - 2012-03-01 12:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2016-01-12 01:51 - 2012-03-01 12:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2016-01-12 01:23 - 2016-01-12 01:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2016-01-12 01:12 - 2015-07-16 00:59 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-01-12 01:12 - 2015-07-16 00:55 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2016-01-12 01:12 - 2015-07-16 00:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2016-01-12 01:11 - 2015-02-03 10:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2016-01-12 01:11 - 2015-02-03 10:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-01-12 01:11 - 2015-02-03 10:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-01-12 01:11 - 2015-02-03 10:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-01-12 01:11 - 2015-02-03 10:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2016-01-12 01:11 - 2015-02-03 10:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2016-01-12 01:11 - 2015-02-03 10:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2016-01-12 01:11 - 2015-02-03 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2016-01-12 01:11 - 2015-02-03 10:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2016-01-12 01:11 - 2014-11-01 05:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-01-12 01:11 - 2014-06-28 07:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2016-01-12 01:11 - 2014-06-28 07:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2016-01-12 01:11 - 2014-03-04 16:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2016-01-12 01:10 - 2015-10-20 07:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-01-12 01:10 - 2015-10-20 07:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-12 01:10 - 2015-10-20 07:52 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-01-12 01:10 - 2015-10-20 07:52 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-01-12 01:10 - 2015-10-20 07:48 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-01-12 01:10 - 2015-10-20 07:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-01-12 01:10 - 2015-10-20 07:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-01-12 01:10 - 2015-10-20 07:45 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-01-12 01:10 - 2015-10-20 07:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-01-12 01:10 - 2015-10-20 07:44 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-01-12 01:10 - 2015-10-20 07:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-01-12 01:10 - 2015-10-20 07:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-01-12 01:10 - 2015-10-20 07:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-01-12 01:10 - 2015-10-20 07:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-01-12 01:10 - 2015-10-20 06:29 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-01-12 01:10 - 2015-10-20 06:28 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-01-12 01:10 - 2015-10-20 06:28 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-01-12 01:10 - 2015-10-02 00:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-01-12 01:10 - 2015-10-02 00:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-01-12 01:10 - 2015-10-02 00:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-01-12 01:10 - 2015-10-02 00:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-01-12 01:10 - 2015-10-02 00:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-01-12 01:10 - 2015-10-01 23:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-01-12 01:10 - 2015-09-23 20:09 - 00371920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-01-12 01:10 - 2015-09-23 20:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 02956800 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 02062848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-01-12 01:09 - 2015-11-21 01:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-01-12 01:09 - 2015-11-21 01:33 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-01-12 01:09 - 2015-11-21 01:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-01-12 01:09 - 2015-11-21 01:33 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2016-01-12 01:09 - 2014-07-17 08:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2016-01-12 01:09 - 2014-07-17 08:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-01-12 01:09 - 2014-07-17 08:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2016-01-12 01:09 - 2014-07-17 08:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2016-01-12 01:09 - 2012-04-26 11:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2016-01-12 01:09 - 2012-04-26 11:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2016-01-12 01:08 - 2015-07-15 09:55 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2016-01-12 01:08 - 2015-04-18 09:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-01-12 01:07 - 2015-10-02 00:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-01-12 01:07 - 2015-10-02 00:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2016-01-12 01:07 - 2015-05-09 10:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-01-12 01:07 - 2015-05-09 10:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-01-12 01:07 - 2015-05-09 10:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-01-12 01:07 - 2015-05-09 10:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-01-12 01:07 - 2015-05-09 10:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 10:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 08:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 08:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 08:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-01-12 01:07 - 2015-05-09 08:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-01-12 01:07 - 2014-11-11 09:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2016-01-12 01:07 - 2013-05-13 10:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2016-01-12 01:07 - 2013-05-13 10:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2016-01-12 01:06 - 2015-11-11 01:39 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-01-12 01:06 - 2015-11-11 00:40 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-01-12 01:06 - 2015-08-07 00:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-01-12 01:06 - 2015-08-07 00:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-01-12 01:06 - 2015-08-06 00:41 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2016-01-12 01:06 - 2015-06-16 04:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-01-12 01:06 - 2015-06-16 04:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2016-01-12 01:06 - 2015-06-16 04:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2016-01-12 01:06 - 2015-06-16 04:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2016-01-12 01:06 - 2014-06-18 08:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2016-01-12 01:06 - 2014-04-05 09:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2016-01-12 01:06 - 2014-04-05 09:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2016-01-12 01:06 - 2013-11-26 18:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2016-01-12 01:06 - 2013-07-26 08:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2016-01-12 01:06 - 2012-06-06 12:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2016-01-12 01:06 - 2011-06-15 15:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2016-01-12 01:06 - 2011-06-15 15:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2016-01-12 01:06 - 2011-06-15 15:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2016-01-12 01:06 - 2011-06-15 15:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2016-01-12 01:06 - 2011-06-15 15:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2016-01-12 01:06 - 2011-03-11 12:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2016-01-12 01:06 - 2011-03-11 12:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2016-01-12 01:06 - 2011-02-23 11:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2016-01-12 01:06 - 2010-12-23 12:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2016-01-12 01:06 - 2010-12-23 12:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-01-12 01:06 - 2010-12-23 12:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2016-01-12 01:05 - 2015-11-06 02:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2016-01-12 01:05 - 2015-11-05 16:48 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2016-01-12 01:05 - 2015-04-30 01:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-01-12 01:05 - 2015-04-30 01:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-01-12 01:05 - 2015-04-30 01:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-01-12 01:05 - 2015-04-30 01:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-01-12 01:05 - 2015-04-30 01:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-01-12 01:05 - 2015-02-18 14:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2016-01-12 01:05 - 2014-12-06 10:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2016-01-12 01:05 - 2014-08-12 08:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2016-01-12 01:05 - 2014-06-19 05:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2016-01-12 01:05 - 2014-06-19 05:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2016-01-12 01:05 - 2014-06-19 05:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2016-01-12 01:05 - 2014-06-06 16:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-12 01:05 - 2014-01-29 09:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2016-01-12 01:05 - 2013-07-25 15:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-01-12 01:05 - 2013-07-12 17:08 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2016-01-12 01:05 - 2013-07-12 17:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2016-01-12 01:05 - 2013-07-03 10:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2016-01-12 01:05 - 2013-07-03 10:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2016-01-12 01:05 - 2013-02-12 10:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2016-01-12 01:05 - 2012-11-02 12:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2016-01-12 01:05 - 2012-10-03 23:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2016-01-12 01:05 - 2012-10-03 23:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2016-01-12 01:05 - 2011-08-17 11:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2016-01-12 01:05 - 2011-08-17 11:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2016-01-12 01:05 - 2011-05-03 11:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-01-12 01:05 - 2011-04-29 09:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-01-12 01:05 - 2011-04-29 09:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-01-12 01:05 - 2011-04-29 09:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-01-12 01:04 - 2015-11-04 01:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2016-01-12 01:04 - 2015-10-13 11:50 - 00712640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2016-01-12 01:04 - 2015-09-02 09:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-01-12 01:04 - 2015-09-02 09:48 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-01-12 01:04 - 2015-09-02 09:48 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-01-12 01:04 - 2015-09-02 09:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-01-12 01:04 - 2015-09-02 08:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-01-12 01:04 - 2015-07-05 00:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-01-12 01:04 - 2015-06-18 00:39 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-12 01:04 - 2015-03-04 11:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2016-01-12 01:04 - 2015-03-04 11:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2016-01-12 01:04 - 2015-01-17 09:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-01-12 01:04 - 2014-12-19 09:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2016-01-12 01:04 - 2014-10-25 08:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2016-01-12 01:04 - 2014-09-04 12:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2016-01-12 01:04 - 2013-11-27 08:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2016-01-12 01:04 - 2013-11-27 08:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2016-01-12 01:04 - 2013-10-19 08:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2016-01-12 01:04 - 2013-10-12 09:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2016-01-12 01:04 - 2013-10-12 09:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2016-01-12 01:04 - 2013-10-12 09:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2016-01-12 01:04 - 2013-10-12 09:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2016-01-12 01:04 - 2013-10-12 09:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2016-01-12 01:04 - 2013-10-12 08:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2016-01-12 01:04 - 2013-10-12 08:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2016-01-12 01:04 - 2013-06-26 05:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2016-01-12 01:04 - 2012-11-29 05:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2016-01-12 01:04 - 2012-11-29 05:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2016-01-12 01:04 - 2012-11-29 05:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2016-01-12 01:04 - 2012-09-26 05:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2016-01-12 01:04 - 2012-03-17 14:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2016-01-12 01:04 - 2012-02-17 12:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2016-01-12 01:04 - 2012-02-17 11:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2016-01-12 01:04 - 2011-11-17 12:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-01-12 01:04 - 2011-10-15 12:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-01-12 01:04 - 2011-05-24 17:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2016-01-12 01:04 - 2011-03-03 12:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2016-01-12 01:04 - 2011-03-03 12:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2016-01-12 01:04 - 2011-03-03 12:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2016-01-12 01:03 - 2015-11-12 01:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2016-01-12 01:03 - 2015-11-12 01:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2016-01-12 01:03 - 2015-11-04 01:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2016-01-12 01:03 - 2015-10-13 23:31 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2016-01-12 01:03 - 2015-10-13 23:31 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2016-01-12 01:03 - 2015-07-10 00:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2016-01-12 01:03 - 2015-07-10 00:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2016-01-12 01:03 - 2015-07-02 03:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-01-12 01:03 - 2015-07-02 03:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2016-01-12 01:03 - 2015-06-02 06:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2016-01-12 01:03 - 2015-04-25 00:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2016-01-12 01:03 - 2015-04-13 10:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2016-01-12 01:03 - 2015-02-25 10:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2016-01-12 01:03 - 2015-02-03 10:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2016-01-12 01:03 - 2014-12-19 08:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-01-12 01:03 - 2014-12-08 09:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2016-01-12 01:03 - 2014-06-16 08:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-01-12 01:03 - 2014-06-16 08:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-01-12 01:03 - 2014-06-16 08:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2016-01-12 01:03 - 2013-10-04 08:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2016-01-12 01:03 - 2013-10-04 08:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2016-01-12 01:03 - 2013-04-26 11:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-01-12 01:03 - 2012-11-23 09:48 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2016-01-12 01:03 - 2012-07-05 04:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2016-01-12 01:03 - 2012-07-05 04:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2016-01-12 01:03 - 2012-07-05 04:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2016-01-12 01:03 - 2012-05-14 11:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-01-12 01:03 - 2011-12-16 14:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2016-01-12 01:03 - 2011-08-27 11:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2016-01-12 01:03 - 2011-02-12 12:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2016-01-12 01:02 - 2014-10-14 08:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2016-01-11 22:31 - 2016-01-11 22:31 - 00000000 ____D C:\Windows\system32\SPReview
2016-01-11 22:31 - 2016-01-11 22:31 - 00000000 ____D C:\Windows\system32\EventProviders
2016-01-11 22:28 - 2010-11-20 19:36 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2016-01-11 22:28 - 2010-11-20 19:32 - 05066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2016-01-11 22:28 - 2010-11-20 19:30 - 00245632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00175360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00160128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00153984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00116096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00085376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sbp2port.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2016-01-11 22:28 - 2010-11-20 19:30 - 00028032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2016-01-11 22:28 - 2010-11-20 19:29 - 02217856 _____ (Microsoft Corporation) C:\Windows\system32\bootres.dll
2016-01-11 22:28 - 2010-11-20 19:29 - 00520064 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2016-01-11 22:28 - 2010-11-20 19:29 - 00274304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2016-01-11 22:28 - 2010-11-20 19:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2016-01-11 22:28 - 2010-11-20 19:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2016-01-11 22:28 - 2010-11-20 19:29 - 00014208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys
2016-01-11 22:28 - 2010-11-20 19:24 - 00271664 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-01-11 22:28 - 2010-11-20 19:23 - 00144768 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 02983424 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01712640 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01624064 _____ (Microsoft Corporation) C:\Windows\system32\WMPEncEn.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01363456 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01128448 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01115136 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01086976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 01063936 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00974336 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00907776 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00782336 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\scrptadm.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00380416 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\umrdp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00154624 _____ (Microsoft Corporation) C:\Windows\system32\tscfgwmi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\tspubwmi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\tssrvlic.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2016-01-11 22:28 - 2010-11-20 19:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\samcli.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 02504192 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2016-01-11 22:28 - 2010-11-20 19:20 - 02494464 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 01750528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00932352 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL
2016-01-11 22:28 - 2010-11-20 19:20 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\netdiagfx.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\QSHVHOST.DLL
2016-01-11 22:28 - 2010-11-20 19:20 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2016-01-11 22:28 - 2010-11-20 19:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\prncache.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 02151936 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00954752 _____ (Microsoft Corporation) C:\Windows\system32\mfc40.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00954288 _____ (Microsoft Corporation) C:\Windows\system32\mfc40u.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-01-11 22:28 - 2010-11-20 19:19 - 00732160 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2016-01-11 22:28 - 2010-11-20 19:19 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\hgprint.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\fde.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2016-01-11 22:28 - 2010-11-20 19:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\LSCSHostPolicy.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll
2016-01-11 22:28 - 2010-11-20 19:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 02522624 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 01828352 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 01334272 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00863744 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00854016 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00762880 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00546304 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2016-01-11 22:28 - 2010-11-20 19:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\appmgr.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00252928 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\dps.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cscobj.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2016-01-11 22:28 - 2010-11-20 19:18 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll
2016-01-11 22:28 - 2010-11-20 19:17 - 03367424 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\FXSSVC.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00161280 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\net1.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\setupcl.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00080896 _____ C:\Windows\system32\RDVGHelper.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\PushPrinterConnections.exe
2016-01-11 22:28 - 2010-11-20 19:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2016-01-11 22:28 - 2010-11-20 19:16 - 00776192 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2016-01-11 22:28 - 2010-11-20 19:16 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2016-01-11 22:28 - 2010-11-20 19:16 - 00668160 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2016-01-11 22:28 - 2010-11-20 19:16 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2016-01-11 22:28 - 2010-11-20 19:16 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2016-01-11 22:28 - 2010-11-20 19:16 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2016-01-11 22:28 - 2010-11-20 18:54 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-11 22:28 - 2010-11-20 17:24 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpdr.sys
2016-01-11 22:28 - 2010-11-20 17:22 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2016-01-11 22:28 - 2010-11-20 17:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2016-01-11 22:28 - 2010-11-20 16:59 - 00035968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusb.sys
2016-01-11 22:28 - 2010-11-20 16:14 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\vmicsvc.exe
2016-01-11 22:28 - 2010-11-20 15:44 - 00388096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\csc.sys
2016-01-11 22:28 - 2010-11-20 15:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2016-01-11 22:28 - 2010-11-20 15:42 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2016-01-11 22:28 - 2010-11-05 09:20 - 00146852 _____ C:\Windows\system32\systemsf.ebd
2016-01-11 22:28 - 2010-11-05 08:58 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2016-01-11 22:28 - 2010-11-05 08:58 - 00049488 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2016-01-11 22:28 - 2010-11-05 08:53 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2016-01-11 22:28 - 2010-11-05 08:53 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2016-01-11 22:27 - 2010-11-20 19:36 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\NAPHLPR.DLL
2016-01-11 22:27 - 2010-11-20 19:36 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2016-01-11 22:27 - 2010-11-20 19:30 - 00173440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2016-01-11 22:27 - 2010-11-20 19:30 - 00140160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scsiport.sys
2016-01-11 22:27 - 2010-11-20 19:30 - 00130432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2016-01-11 22:27 - 2010-11-20 19:30 - 00040704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmstorfl.sys
2016-01-11 22:27 - 2010-11-20 19:30 - 00028032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storvsc.sys
2016-01-11 22:27 - 2010-11-20 19:29 - 00137088 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2016-01-11 22:27 - 2010-11-20 19:29 - 00043392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winhv.sys
2016-01-11 22:27 - 2010-11-20 19:21 - 02202624 _____ (Microsoft Corporation) C:\Windows\system32\SensorsCpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 02157568 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 01326592 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 01003008 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\Vault.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-11 22:27 - 2010-11-20 19:21 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00750080 _____ (Microsoft Corporation) C:\Windows\system32\sdcpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00739328 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-11 22:27 - 2010-11-20 19:21 - 00738816 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00697344 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-01-11 22:27 - 2010-11-20 19:21 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00428544 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\wiadefui.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00410624 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\termmgr.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\WPDSp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese30.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\taskbarcpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\wavemsp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\unattend.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\wpdwcn.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\wmpsrcwp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\remotepg.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\recovery.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\sdrsvc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\uxlib.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\wiavideo.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WPDShServiceObj.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\wmpshell.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\sppinst.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\QUTIL.DLL
2016-01-11 22:27 - 2010-11-20 19:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountControlSettings.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\unimdmat.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\vfwwdm32.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\sppuinotify.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rdpd3d.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00051200 _____ (Twain Working Group) C:\Windows\twain_32.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\umb.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\RpcRtRemote.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wtsapi32.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\shimgvw.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\wdiasqmmodule.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\utildll.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\vpnikeapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\TRAPI.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\rdprefdrvapi.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\shgina.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\spopk.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\schedcli.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\syssetup.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wshirda.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\shunimpl.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\riched32.dll
2016-01-11 22:27 - 2010-11-20 19:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\rdpcfgex.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 02130944 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 01661440 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 01644032 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\onexui.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceStatus.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00395264 _____ (Microsoft Corporation) C:\Windows\system32\prnfldr.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\nshipsec.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\OnLineIDCpl.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\qcap.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceSyncProvider.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\QAGENT.DLL
2016-01-11 22:27 - 2010-11-20 19:20 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\QSVRMGMT.DLL
2016-01-11 22:27 - 2010-11-20 19:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\olethk32.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\QCLIPROV.DLL
2016-01-11 22:27 - 2010-11-20 19:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\napdsnap.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\PrintIsolationProxy.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\netutils.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\perfts.dll
2016-01-11 22:27 - 2010-11-20 19:20 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\nrpsrv.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 01066496 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\FirewallControlPanel.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\localsec.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\msdri.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\mspbda.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2016-01-11 22:27 - 2010-11-20 19:19 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\iTVData.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\mstask.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\msvfw32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\fphc.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00093696 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\mciavi32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00082944 _____ (Radius Inc.) C:\Windows\system32\iccvid.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\KMSVC.DLL
2016-01-11 22:27 - 2010-11-20 19:19 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Mcx2Svc.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\luainstall.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\FXSMON.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\mciqtz32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\msdmo.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\HotStartUserAgent.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2016-01-11 22:27 - 2010-11-20 19:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 03727872 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 01400320 _____ (Microsoft Corporation) C:\Windows\system32\DxpTaskSync.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\DiagCpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 01040384 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00685056 _____ (Microsoft Corporation) C:\Windows\system32\dsuiext.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00537600 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenterCPL.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00438272 _____ (Microsoft Corporation) C:\Windows\system32\AdmTmpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\biocpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00418816 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\dot3ui.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\azroleui.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\dpx.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\audiodev.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\defaultlocationcpl.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingFolder.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\dxdiagn.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\activeds.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\dskquoui.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\adsldp.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cfgmgr32.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\bcdsrv.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\CscMig.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\avifil32.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\cabinet.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\amstream.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\CertPolEng.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dsauth.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\AzSqlExt.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\elsTrans.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\bitsperf.dll
2016-01-11 22:27 - 2010-11-20 19:18 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\C_ISCII.DLL
2016-01-11 22:27 - 2010-11-20 19:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll
2016-01-11 22:27 - 2010-11-20 19:17 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\fsquirt.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\recdisc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\PresentationSettings.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\iscsicli.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\MdSched.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\mobsync.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00098816 _____ (Microsoft) C:\Windows\system32\Robocopy.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\isoburn.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\cmstp.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\MuiUnattend.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00066048 _____ C:\Windows\system32\PrintBrmUi.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\djoin.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\repair-bde.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\rdpsign.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\takeown.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\runonce.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tzutil.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\unlodctr.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\userinit.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\qwinsta.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netcfg.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\qprocess.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msg.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\quser.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\tskill.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\tsdiscon.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\tscon.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\qappsrv.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\logoff.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\shadow.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\rwinsta.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\reset.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\query.exe
2016-01-11 22:27 - 2010-11-20 19:17 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\LogonUI.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\Bubbles.scr
2016-01-11 22:27 - 2010-11-20 19:16 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2016-01-11 22:27 - 2010-11-20 19:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2016-01-11 22:27 - 2010-11-20 19:16 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\ssText3d.scr
2016-01-11 22:27 - 2010-11-20 19:16 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2016-01-11 22:27 - 2010-11-20 19:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\Mystify.scr
2016-01-11 22:27 - 2010-11-20 19:16 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\Ribbons.scr
2016-01-11 22:27 - 2010-11-20 19:16 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\bitsadmin.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2016-01-11 22:27 - 2010-11-20 19:16 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\desk.cpl
2016-01-11 22:27 - 2010-11-20 19:16 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\BdeHdCfg.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00065024 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\g711codc.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2016-01-11 22:27 - 2010-11-20 19:16 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\chgport.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\chglogon.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\chgusr.exe
2016-01-11 22:27 - 2010-11-20 19:16 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\change.exe
2016-01-11 22:27 - 2010-11-20 19:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2016-01-11 22:27 - 2010-11-20 19:07 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwizres.dll
2016-01-11 22:27 - 2010-11-20 19:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\RDPENCDD.dll
2016-01-11 22:27 - 2010-11-20 19:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\pifmgr.dll
2016-01-11 22:27 - 2010-11-20 19:03 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\vmicres.dll
2016-01-11 22:27 - 2010-11-20 19:03 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\vmbusres.dll
2016-01-11 22:27 - 2010-11-20 19:03 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\vmstorfltres.dll
2016-01-11 22:27 - 2010-11-20 19:00 - 01027584 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2016-01-11 22:27 - 2010-11-20 19:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2016-01-11 22:27 - 2010-11-20 19:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDSG.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdlk41a.dll
2016-01-11 22:27 - 2010-11-20 19:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDCZ1.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDSF.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDPO.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDNEPR.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGR1.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGKL.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUS.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUGHR1.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTURME.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAJIK.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMON.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMAORI.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDLT1.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBULG.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBLR.DLL
2016-01-11 22:27 - 2010-11-20 19:00 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDGEO.DLL
2016-01-11 22:27 - 2010-11-20 18:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2016-01-11 22:27 - 2010-11-20 18:56 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2016-01-11 22:27 - 2010-11-20 17:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2016-01-11 22:27 - 2010-11-20 17:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RDPCDD.sys
2016-01-11 22:27 - 2010-11-20 17:21 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\RDPREFDD.dll
2016-01-11 22:27 - 2010-11-20 17:21 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdpipe.sys
2016-01-11 22:27 - 2010-11-20 17:07 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2016-01-11 22:27 - 2010-11-20 17:07 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2016-01-11 22:27 - 2010-11-20 17:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2016-01-11 22:27 - 2010-11-20 17:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2016-01-11 22:27 - 2010-11-20 17:06 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2016-01-11 22:27 - 2010-11-20 17:00 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2016-01-11 22:27 - 2010-11-20 17:00 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\umbus.sys
2016-01-11 22:27 - 2010-11-20 17:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys
2016-01-11 22:27 - 2010-11-20 17:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys
2016-01-11 22:27 - 2010-11-20 16:59 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2016-01-11 22:27 - 2010-11-20 16:59 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2016-01-11 22:27 - 2010-11-20 16:50 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2016-01-11 22:27 - 2010-11-20 16:50 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\CompositeBus.sys
2016-01-11 22:27 - 2010-11-20 16:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2016-01-11 22:27 - 2010-11-20 16:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2016-01-11 22:27 - 2010-11-20 16:24 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2016-01-11 22:27 - 2010-11-20 16:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2016-01-11 22:27 - 2010-11-20 16:14 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\VmbusCoinstaller.dll
2016-01-11 22:27 - 2010-11-20 16:14 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\VmdCoinstall.dll
2016-01-11 22:27 - 2010-11-20 16:14 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\IcCoinstall.dll
2016-01-11 22:27 - 2010-11-20 16:14 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\vmictimeprovider.dll
2016-01-11 22:27 - 2010-11-20 16:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\VMBusHID.sys
2016-01-11 22:27 - 2010-11-20 16:14 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\vmbuspipe.dll
2016-01-11 22:27 - 2010-11-20 16:14 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vms3cap.sys
2016-01-11 22:27 - 2010-11-20 15:54 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2016-01-11 22:27 - 2010-11-20 15:47 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpipmi.sys
2016-01-11 22:27 - 2010-11-20 15:42 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-01-11 22:27 - 2010-11-20 15:39 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2016-01-11 22:27 - 2010-11-20 15:39 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdi.sys
2016-01-11 22:27 - 2010-11-20 15:38 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2016-01-11 22:27 - 2010-11-20 12:23 - 00053600 _____ C:\Windows\system32\dosx.exe
2016-01-11 22:27 - 2010-11-10 08:45 - 00010429 _____ C:\Windows\system32\ScavengeSpace.xml
2016-01-11 22:27 - 2010-11-05 09:20 - 00105559 _____ C:\Windows\system32\RacRules.xml
2016-01-11 22:27 - 2010-11-05 09:11 - 00312168 _____ (Microsoft Corporation) C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2016-01-11 22:26 - 2010-11-20 19:21 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn.dll
2016-01-11 22:26 - 2010-11-20 19:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll
2016-01-11 21:56 - 2016-01-11 22:00 - 00000979 _____ C:\Users\pc\Desktop\Notes.lnk
2016-01-11 21:49 - 2016-01-11 21:49 - 00000916 _____ C:\ProgramData\Microsoft\Windows\Start Menu\LINE.lnk
2016-01-11 21:49 - 2016-01-11 21:49 - 00000000 ____D C:\Users\pc\AppData\Local\LINE
2016-01-11 21:49 - 2016-01-11 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LINE
2016-01-11 21:49 - 2016-01-11 21:49 - 00000000 ____D C:\Program Files\LINE
2016-01-11 17:44 - 2016-01-11 17:44 - 00000000 ____D C:\Program Files\Adobe Photoshop CS5
2016-01-11 17:32 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2016-01-11 17:32 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2016-01-11 17:32 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2016-01-11 17:32 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2016-01-11 17:32 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2016-01-11 17:32 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2016-01-11 17:32 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2016-01-11 17:32 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2016-01-11 17:32 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2016-01-11 17:32 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2016-01-11 17:32 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2016-01-11 17:32 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2016-01-11 17:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2016-01-11 17:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2016-01-11 17:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2016-01-11 17:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2016-01-11 17:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2016-01-11 17:31 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2016-01-11 17:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2016-01-11 17:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2016-01-11 17:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2016-01-11 17:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2016-01-11 17:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2016-01-11 17:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2016-01-11 17:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2016-01-11 17:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2016-01-11 17:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2016-01-11 17:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2016-01-11 17:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2016-01-11 17:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2016-01-11 17:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2016-01-11 17:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2016-01-11 17:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2016-01-11 17:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2016-01-11 17:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2016-01-11 17:31 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2016-01-11 17:31 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2016-01-11 17:31 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2016-01-11 17:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2016-01-11 17:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2016-01-11 17:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2016-01-11 17:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2016-01-11 17:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2016-01-11 17:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2016-01-11 17:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2016-01-11 17:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2016-01-11 17:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2016-01-11 17:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2016-01-11 17:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2016-01-11 17:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2016-01-11 17:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2016-01-11 17:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2016-01-11 17:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2016-01-11 17:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2016-01-11 17:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2016-01-11 17:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2016-01-11 17:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2016-01-11 17:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2016-01-11 17:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2016-01-11 17:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2016-01-11 17:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2016-01-11 17:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2016-01-11 17:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2016-01-11 17:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2016-01-11 17:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2016-01-11 17:31 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2016-01-11 17:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2016-01-11 17:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2016-01-11 17:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2016-01-11 17:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2016-01-11 17:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2016-01-11 17:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2016-01-11 17:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2016-01-11 17:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2016-01-11 17:31 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2016-01-11 17:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2016-01-11 17:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2016-01-11 17:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2016-01-11 17:31 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-01-11 17:31 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-01-11 17:31 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-01-11 17:31 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-01-11 17:31 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-01-11 17:31 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-01-11 17:31 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-01-11 17:31 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-01-11 17:31 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-01-11 17:31 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-01-11 17:31 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-01-11 17:31 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-01-11 17:25 - 2016-01-12 23:07 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-01-11 17:19 - 2016-01-11 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2016-01-11 17:18 - 2016-01-15 21:44 - 00000000 ____D C:\Users\pc\AppData\Roaming\Winamp
2016-01-11 17:18 - 2016-01-11 17:19 - 00000000 ____D C:\Program Files\Winamp
2016-01-11 17:18 - 2016-01-11 17:18 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2016-01-11 17:17 - 2016-01-11 17:17 - 00000000 ____D C:\Program Files\Lame For Audacity
2016-01-11 17:16 - 2016-01-11 17:16 - 00000978 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-01-11 17:16 - 2016-01-11 17:16 - 00000000 ____D C:\Program Files\Audacity
2016-01-11 17:09 - 2016-01-11 17:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-01-11 17:08 - 2016-01-11 17:08 - 00243128 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2016-01-11 17:08 - 2016-01-11 17:08 - 00000000 ____D C:\Users\pc\AppData\Roaming\DAEMON Tools Lite
2016-01-11 17:08 - 2016-01-11 17:08 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2016-01-11 17:05 - 2016-01-11 17:05 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-01-11 17:04 - 2016-01-11 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AML Free Registry Cleaner
2016-01-11 17:04 - 2016-01-11 17:04 - 00000000 ____D C:\Program Files\AML Products
2016-01-11 17:04 - 2002-01-05 11:37 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr70.dll
2016-01-11 17:04 - 2002-01-05 06:48 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\mfc70.dll
2016-01-11 17:04 - 2002-01-05 05:40 - 00487424 _____ (Microsoft Corporation) C:\Windows\system32\msvcp70.dll
2016-01-11 17:04 - 2000-05-22 16:58 - 00608448 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.ocx
2016-01-11 16:52 - 2016-01-11 16:52 - 00000000 ____D C:\Program Files\SAMSUNG
2016-01-11 16:51 - 2016-01-11 16:51 - 00000000 ____D C:\ProgramData\Samsung
2016-01-11 10:04 - 2016-01-12 20:19 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-01-11 10:04 - 2016-01-11 10:04 - 00000000 ____D C:\Windows\system32\appraiser
2016-01-11 09:27 - 2015-09-18 23:32 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-01-11 09:27 - 2015-09-18 23:30 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-11 09:27 - 2015-09-18 23:30 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-11 09:27 - 2015-09-18 23:30 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-11 09:27 - 2015-09-18 23:30 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-11 09:27 - 2015-09-18 23:30 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-01-11 09:27 - 2015-01-28 06:28 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2016-01-11 08:56 - 2016-01-11 09:00 - 00000000 ____D C:\Windows\system32\MRT
2016-01-11 08:56 - 2015-11-23 19:09 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-11 07:17 - 2016-01-11 07:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-01-11 07:16 - 2016-01-11 07:16 - 00000000 ____D C:\Program Files\4KDownload
2016-01-11 06:41 - 2016-01-11 06:52 - 00000000 ____D C:\Users\pc\AppData\Local\Adobe
2016-01-11 06:38 - 2016-01-11 06:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-01-11 06:38 - 2016-01-11 06:38 - 00000000 ____D C:\Program Files\VideoLAN
2016-01-11 06:07 - 2016-01-11 06:07 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc
2016-01-11 06:07 - 2016-01-11 06:07 - 00000000 ____D C:\Users\HomeGroupUser$
2016-01-11 05:44 - 2014-04-29 18:06 - 05193792 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL6.SYS
2016-01-11 05:44 - 2014-04-29 18:06 - 04247552 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv.dll
2016-01-11 05:44 - 2014-04-29 18:06 - 03645440 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui.dll
2016-01-11 05:44 - 2014-04-29 18:06 - 00091448 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2016-01-11 05:44 - 2014-04-29 18:06 - 00033832 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwl2cap.sys
2016-01-11 05:01 - 2016-01-11 05:01 - 00000000 ____D C:\Windows\system32\SDA
2016-01-11 05:00 - 2016-01-11 05:00 - 00000000 ____D C:\Users\pc\Documents\Bluetooth Exchange Folder
2016-01-11 05:00 - 2016-01-11 05:00 - 00000000 ____D C:\Users\pc\AppData\Local\Broadcom
2016-01-11 04:58 - 2016-01-11 04:56 - 00302120 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwampfl.sys
2016-01-11 04:58 - 2016-01-11 04:56 - 00114728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwavdt.sys
2016-01-11 04:58 - 2016-01-11 04:56 - 00093224 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwaudio.sys
2016-01-11 04:58 - 2016-01-11 04:56 - 00020008 _____ (Broadcom Corporation.) C:\Windows\system32\btwcoins.dll
2016-01-11 04:58 - 2016-01-11 04:56 - 00018728 _____ (Broadcom Corporation.) C:\Windows\system32\Drivers\btwrchid.sys
2016-01-11 04:57 - 2016-01-11 04:57 - 00000000 ____D C:\Program Files\WIDCOMM
2016-01-11 04:45 - 2016-01-11 04:45 - 00015322 _____ C:\Windows\system32\results.xml
2016-01-11 04:30 - 2016-01-11 04:30 - 00000000 ____D C:\Program Files\STMicroelectronics
2016-01-11 04:30 - 2012-05-23 10:22 - 00081520 _____ (ST Microelectronics) C:\Windows\system32\accelernco01.dll
2016-01-11 04:30 - 2012-05-23 10:22 - 00044144 _____ (ST Microelectronics) C:\Windows\system32\Drivers\accelern.sys
2016-01-11 04:30 - 2011-07-15 21:30 - 00017904 _____ (ST Microelectronics) C:\Windows\system32\Drivers\stdcfltn.sys
2016-01-11 04:27 - 2012-10-24 17:09 - 00308624 _____ C:\Windows\system32\brcmbsp.dll
2016-01-11 04:27 - 2012-10-24 17:09 - 00208304 _____ C:\Windows\system32\bipbsp.dll
2016-01-11 04:26 - 2016-01-11 04:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_cvusbdrv_01009.Wdf
2016-01-11 04:26 - 2016-01-11 04:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broadcom
2016-01-11 04:26 - 2016-01-11 04:26 - 00000000 ____D C:\ProgramData\Broadcom
2016-01-11 04:26 - 2016-01-11 04:26 - 00000000 ____D C:\Program Files\Broadcom Corporation
2016-01-11 04:15 - 2016-01-11 04:15 - 00000000 ____D C:\Program Files\Common Files\postureAgent
2016-01-11 04:15 - 2013-01-24 06:19 - 00008192 _____ C:\Windows\system32\Drivers\IntelMEFWVer.dll
2016-01-11 04:14 - 2013-01-24 06:19 - 00048928 _____ (Intel Corporation) C:\Windows\system32\Drivers\HECI.sys
2016-01-11 04:11 - 2016-01-11 04:11 - 00001783 _____ C:\Windows\system32\WmiConf.txt
2016-01-11 04:06 - 2013-02-20 22:13 - 00368392 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1c6232.sys
2016-01-11 04:06 - 2012-12-06 03:21 - 00073032 _____ (Intel Corporation) C:\Windows\system32\e1cmsg.dll
2016-01-11 04:06 - 2012-11-14 04:07 - 00083808 _____ (Intel Corporation) C:\Windows\system32\NicInstC.dll
2016-01-11 04:06 - 2012-01-06 14:02 - 00003109 _____ C:\Windows\system32\e1c6232.din
2016-01-11 04:05 - 2016-01-11 04:05 - 00000000 ____D C:\Program Files\Cisco
2016-01-11 04:03 - 2016-01-11 04:03 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DW WLAN
2016-01-11 04:02 - 2016-01-11 04:02 - 00000000 ____D C:\Windows\system32\vs08
2016-01-11 04:02 - 2011-01-18 08:50 - 02682880 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x86.exe
2016-01-11 04:02 - 2011-01-18 08:50 - 00052224 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll
2016-01-11 04:02 - 2011-01-18 08:50 - 00000457 _____ C:\Windows\system32\vcredist_x86.bat
2016-01-11 04:02 - 2011-01-18 08:49 - 07558656 _____ (Dell Inc.) C:\Windows\system32\BCMWLCPL.CPL
2016-01-11 04:02 - 2011-01-18 08:49 - 04526080 _____ (Dell Inc.) C:\Windows\system32\bcmttls.dll
2016-01-11 04:02 - 2011-01-18 08:49 - 01066496 _____ (Dell Inc.) C:\Windows\system32\BCMLogon.dll
2016-01-11 04:02 - 2011-01-18 08:49 - 00050704 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys
2016-01-11 04:02 - 2011-01-18 08:49 - 00018496 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys
2016-01-11 04:02 - 2011-01-18 08:49 - 00006656 _____ C:\Windows\system32\bcmwlrc.dll
2016-01-11 04:00 - 2016-01-11 04:02 - 00000000 ____D C:\Program Files\Dell
2016-01-11 04:00 - 2016-01-11 04:00 - 00000000 ____D C:\Windows\{B7231620-E76C-4C8E-ADD5-594B1C9FF72F}
2016-01-11 03:03 - 2016-01-12 23:12 - 00000000 ____D C:\Users\pc\AppData\Local\Deployment
2016-01-11 03:03 - 2016-01-11 03:03 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2016-01-11 03:03 - 2016-01-11 03:03 - 00000000 ____D C:\Users\pc\AppData\Local\Apps\2.0
2016-01-11 03:02 - 2016-01-11 03:02 - 00417064 ___SH () C:\Users\pc\Downloads\dellsystemdetectlauncher.exe
2016-01-11 02:30 - 2016-01-13 03:47 - 00000000 ____D C:\Users\pc\AppData\Local\ElevatedDiagnostics
2016-01-11 02:22 - 2016-01-11 02:22 - 00985600 _____ C:\Users\pc\Downloads\MicrosoftFixit50123 (1).msi
2016-01-11 01:57 - 2016-01-11 01:57 - 00847856 ___SH (Google Inc.) C:\Users\pc\Downloads\chromesetup.exe
2016-01-11 01:50 - 2016-01-11 01:50 - 00985600 _____ C:\Users\pc\Downloads\MicrosoftFixit50123.msi
2016-01-04 00:38 - 2016-01-11 04:30 - 00000000 ____D C:\Program Files\DIFX
2016-01-04 00:37 - 2016-01-04 00:37 - 00000000 ____D C:\3DP

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-18 18:18 - 2009-07-14 09:37 - 00000000 ____D C:\Windows
2016-01-18 18:09 - 2009-07-14 11:34 - 00016352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-18 18:09 - 2009-07-14 11:34 - 00016352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-18 18:03 - 2014-03-31 17:15 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-18 18:00 - 2009-07-14 11:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-18 17:57 - 2014-03-31 17:15 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-18 02:46 - 2014-03-30 20:48 - 00393022 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-18 02:46 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\inf
2016-01-17 22:42 - 2009-07-14 11:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-01-17 21:37 - 2014-03-31 19:00 - 00000000 ____D C:\Users\pc\AppData\Roaming\vlc
2016-01-13 07:19 - 2014-03-31 19:15 - 00000000 ____D C:\Users\pc\AppData\Local\Google
2016-01-13 04:21 - 2009-07-14 14:49 - 00000000 ____D C:\Windows\ShellNew
2016-01-13 04:21 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\Resources
2016-01-13 03:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\AppCompat
2016-01-12 20:20 - 2009-07-14 11:33 - 00350688 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-12 20:19 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\tracing
2016-01-12 18:33 - 2014-03-31 18:34 - 00088288 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-12 18:07 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\Dism
2016-01-12 18:07 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2016-01-12 16:10 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-01-12 03:18 - 2009-07-14 11:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-01-12 03:09 - 2009-07-14 14:50 - 00000000 ____D C:\Program Files\Windows Journal
2016-01-12 03:09 - 2009-07-14 09:37 - 00000000 ____D C:\Program Files\Common Files\System
2016-01-12 03:08 - 2009-07-14 11:52 - 00000000 ____D C:\Program Files\Windows Defender
2016-01-12 01:20 - 2014-03-31 19:10 - 00000000 ____D C:\Users\pc\AppData\Roaming\Foxit Software
2016-01-11 22:44 - 2014-03-30 21:13 - 00000000 ____D C:\Windows\Panther
2016-01-11 22:40 - 2009-07-14 14:49 - 00000000 __SHD C:\Windows\BitLockerDiscoveryVolumeContents
2016-01-11 22:40 - 2009-07-14 11:52 - 00000000 ____D C:\Program Files\Windows Sidebar
2016-01-11 22:40 - 2009-07-14 11:52 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-01-11 22:40 - 2009-07-14 11:52 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-01-11 22:40 - 2009-07-14 11:52 - 00000000 ____D C:\Program Files\DVD Maker
2016-01-11 22:40 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\servicing
2016-01-11 22:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\sysprep
2016-01-11 22:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\Setup
2016-01-11 22:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\oobe
2016-01-11 22:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\migwiz
2016-01-11 22:39 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\manifeststore
2016-01-11 22:35 - 2009-07-14 09:05 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2016-01-11 21:45 - 2014-03-31 19:04 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-01-11 21:45 - 2014-03-31 18:56 - 00000000 ____D C:\Program Files\WinRAR
2016-01-11 16:59 - 2014-03-31 18:56 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-01-11 16:59 - 2014-03-31 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-01-11 16:18 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\rescache
2016-01-11 06:52 - 2014-03-31 19:51 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-01-11 06:52 - 2014-03-31 19:51 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-01-11 06:25 - 2014-03-31 19:11 - 00000000 ____D C:\Program Files\CCleaner
2016-01-11 05:21 - 2014-12-30 17:21 - 00000000 ____D C:\Users\pc\AppData\Local\Dell
2016-01-11 05:21 - 2014-12-30 17:20 - 00000000 ____D C:\ProgramData\Dell
2016-01-11 04:30 - 2014-12-30 17:28 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-01-11 04:15 - 2014-12-30 16:52 - 00000000 ____D C:\Program Files\Intel
2016-01-11 04:02 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\lv-LV
2016-01-11 04:02 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\lt-LT
2016-01-11 04:02 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\system32\et-EE
2016-01-11 04:02 - 2009-07-14 09:37 - 00000000 ____D C:\Windows\Help
2016-01-11 04:00 - 2014-12-30 17:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2016-01-11 01:14 - 2009-07-14 09:37 - 00000000 __RHD C:\Users\Public\Libraries
2016-01-04 00:31 - 2014-12-30 17:25 - 00000000 ____D C:\Intel

==================== Files in the root of some directories =======

2016-01-13 05:09 - 2016-01-18 04:33 - 0131815 _____ () C:\Users\pc\AppData\Local\ars.cache
2016-01-13 05:09 - 2016-01-18 04:33 - 0458769 _____ () C:\Users\pc\AppData\Local\census.cache
2016-01-13 04:58 - 2016-01-13 04:58 - 0000036 _____ () C:\Users\pc\AppData\Local\housecall.guid.cache
2016-01-13 07:57 - 2016-01-13 07:57 - 0000010 _____ () C:\Users\pc\AppData\Local\sponge.last.runtime.cache

Some files in TEMP:
====================
C:\Users\pc\AppData\Local\Temp\dllnt_dump.dll
C:\Users\pc\AppData\Local\Temp\DSETUP.dll
C:\Users\pc\AppData\Local\Temp\dsetup32.dll
C:\Users\pc\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\pc\AppData\Local\Temp\Foxit Updater.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-01-11 05:40

==================== End of FRST.txt ============================



#13 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 18 January 2016 - 06:52 AM

Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-01-2015
Ran by pc (2016-01-18 18:20:45)
Running from C:\Users\pc\Desktop
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) (2014-12-30 09:28:29)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-715854880-2641705681-1363900585-500 - Administrator - Disabled)
Guest (S-1-5-21-715854880-2641705681-1363900585-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-715854880-2641705681-1363900585-1002 - Limited - Enabled)
pc (S-1-5-21-715854880-2641705681-1363900585-1000 - Administrator - Enabled) => C:\Users\pc

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

4K Video Downloader 3.8 (HKLM\...\4K Video Downloader_is1) (Version: 3.8.0.1830 - Open Media LLC)
7-Zip 15.14 (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov)
AccelerometerP11 (HKLM\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 2.00.10.34 - STMicroelectronics)
Adobe Flash Player 20 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 20.0.0.270 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated)
AML Free Registry Cleaner 4.25 (HKLM\...\{315F5FFC-1A5C-4A2A-B8E7-1C5B1174C198}_is1) (Version:  - AML SOFT, Inc.)
Audacity 2.0.6 (HKLM\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast) (Version: 11.1.2245 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.03 - Piriform)
Cisco EAP-FAST Module (Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (Version: 1.1.6 - Cisco Systems, Inc.) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dell Command | Update (HKLM\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.0.0 - Dell Inc.)
Dell ControlVault Host Components Installer (HKLM\...\{B75554EF-1A58-4476-8532-853F159AB263}) (Version: 2.3.24.1437 - Broadcom Corporation)
Dell Digital Delivery (HKLM\...\{D850CB7E-72BC-4510-BA4F-48932BFAB295}) (Version: 2.9.901.0 - Dell Products, LP)
Dell System Detect (HKU\S-1-5-21-715854880-2641705681-1363900585-1000\...\58d94f3ce2c27db0) (Version: 6.12.0.5 - Dell)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.1200.101.134 - ALPS ELECTRIC CO., LTD.)
DW WLAN Card Utility (HKLM\...\DW WLAN Card Utility) (Version: 5.100.235.13 - Dell Inc.)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 7.2.8.1124 - Foxit Software Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel® Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.1.70.1205 - Intel Corporation)
Intel® Network Connections 18.1.59.00 (HKLM\...\PROSetDX) (Version: 18.1.59.00 - Intel)
Intel® Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3040 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version:  - )
LINE (HKLM\...\LINE) (Version: 4.3.0.724 - LINE Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 43.0.4 (x86 en-US) (HKLM\...\Mozilla Firefox 43.0.4 (x86 en-US)) (Version: 43.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 43.0.4.5848 - Mozilla)
Mp3tag v2.73 (HKLM\...\Mp3tag) (Version: v2.73 - Florian Heidenreich)
O2Micro Flash Memory Card Windows Driver (HKLM\...\InstallShield_{0CB3B7EE-52C7-4136-AF40-605567D90318}) (Version: 3.0.07.23 - O2Micro International LTD.)
O2Micro Flash Memory Card Windows Driver (Version: 3.0.07.23 - O2Micro International LTD.) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.39.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.39.0 - Renesas Electronics Corporation) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
USB Disk Security (HKLM\...\USB Disk Security_is1) (Version:  - Zbshareware Lab)
VC_CRT_x86 (Version: 1.02.0000 - Intel Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7900 - Broadcom Corporation)
Winamp (HKLM\...\Winamp) (Version: 5.56  - Nullsoft, Inc)
Windows Driver Package - Broadcom (BCM43XX) Net  (09/04/2014 6.34.223.5) (HKLM\...\2A31EA3D7C17F73EDC1C5275544C8B1D34746852) (Version: 09/04/2014 6.34.223.5 - Broadcom)
WinRAR 5.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0CB4E621-DCFA-4FDF-AF90-6527F8909E92} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-01-13] (AVAST Software)
Task: {1F1931BE-B8D6-4BDF-B608-7D30D206041C} - System32\Tasks\{977F8761-C4C2-4129-B3D1-356DC54BAC3C} => E:\Inbox\Pro Evolution Soccer 6\Pro Evolution Soccer 6\pes6.exe
Task: {2460815C-C2D3-45CE-A7F8-E1F7EE666380} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-04] (Google Inc.)
Task: {301DCFC4-8F81-4F40-BC9A-77833B4CC391} - System32\Tasks\{4ADA3B43-1FBD-4B8D-AB35-D888386F2114} => E:\Inbox\Pro Evolution Soccer 6\Pro Evolution Soccer 6\pes6.exe
Task: {5346EAFB-DDF5-48C8-94E1-61503E855451} - System32\Tasks\{A9EB12FA-027D-4EFE-BC22-4B4AF8283411} => E:\Inbox\Pro Evolution Soccer 6\Pro Evolution Soccer 6\pes6.exe
Task: {5754806E-B919-4E12-A12C-669C0688075A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-04] (Google Inc.)
Task: {6AEF0C98-2CB4-4B67-8C70-4C977C7355CC} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
Task: {910350BA-C131-4720-ABDA-888408445386} - System32\Tasks\{5D4BDF9C-1387-485A-86FE-618449EA1093} => E:\Inbox\Pro Evolution Soccer 6\Pro Evolution Soccer 6\pes6.exe
Task: {CDCDAADE-43F3-41B3-909F-B16DA20B97E0} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-01-13] (AVAST Software)
Task: {D622195C-D680-4FEA-9C56-59660C7C9E94} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {E6F98017-AAE0-4188-BDC6-8F901345C590} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-01-13 02:48 - 2016-01-13 02:48 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-01-13 02:48 - 2016-01-13 02:48 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-01-18 03:54 - 2016-01-18 03:54 - 02818048 _____ () C:\Program Files\AVAST Software\Avast\defs\16011704\algo.dll
2016-01-13 02:48 - 2016-01-13 02:48 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-01-18 18:01 - 2016-01-18 18:01 - 02818048 _____ () C:\Program Files\AVAST Software\Avast\defs\16011800\algo.dll
2014-03-31 17:18 - 2014-03-31 17:18 - 00008192 _____ () C:\Windows\system32\srvany.exe
2016-01-13 02:48 - 2016-01-13 02:48 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-715854880-2641705681-1363900585-1000\...\dell.com -> dell.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2014-03-31 19:54 - 2014-03-31 19:54 - 00000927 ____A C:\Windows\system32\Drivers\etc\hosts

#7.0.0.1 www.internetdownloadmanager.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-715854880-2641705681-1363900585-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\pc\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 208.67.222.222 - 208.67.220.220
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{534D40A2-7056-47C1-932F-D16BCF0DE175}] => (Allow) C:\Program Files\LINE\LINE.exe
FirewallRules: [{29AB64E2-E3F7-45FA-8165-C1D0F6B4DFFA}] => (Allow) C:\Program Files\LINE\LINE.exe
FirewallRules: [{9C426F08-3274-4921-AF3E-8C21B0B5290C}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EB3BFB69-6C17-4664-B07A-35F23552757D}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EFFE80EB-8B23-49C4-B1FD-DF26DCB06E85}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9FBAB7B5-F4D8-4616-96AF-DAC059D8F134}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F96A2EE6-7C56-4E29-8169-66B964F9AC1E}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{256A6F71-B725-42DB-9D3C-1BFE97BDEE2C}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{FF21B015-93B2-4B23-99EF-A763883BA57F}C:\users\pc\appdata\roaming\utorrent\utorrent.exe ] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{E76B2B04-F4F5-458A-AA85-F7113246AB54}C:\users\pc\appdata\roaming\utorrent\utorrent.exe ] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{629DE58E-12A7-4736-B5BD-4E88A9E997AA}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{F2B31524-2E1B-4D78-93BA-9DF77A7F012B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

18-01-2016 18:13:25 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/18/2016 12:50:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pes6.exe, version: 1.0.0.1, time stamp: 0x4502a65a
Faulting module name: d3d9.dll, version: 0.0.0.0, time stamp: 0x51a79c8e
Exception code: 0xc0000005
Fault offset: 0x000074d7
Faulting process id: 0x1740
Faulting application start time: 0xpes6.exe0
Faulting application path: pes6.exe1
Faulting module path: pes6.exe2
Report Id: pes6.exe3

Error: (01/13/2016 01:38:09 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.

Details:
    The registry value cannot be read because the configuration is invalid. Recreate the content index configuration by removing the content index.  (HRESULT : 0x80040d03) (0x80040d03)

Error: (01/13/2016 01:38:09 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.

Context: Windows Application

Details:
    The registry value cannot be read because the configuration is invalid. Recreate the content index configuration by removing the content index.  (HRESULT : 0x80040d03) (0x80040d03)

Error: (01/13/2016 01:38:09 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
    The registry value cannot be read because the configuration is invalid. Recreate the content index configuration by removing the content index.  (HRESULT : 0x80040d03) (0x80040d03)

Error: (01/13/2016 01:38:07 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (01/13/2016 01:38:07 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: The search service has detected corrupted data files in the index {id=431}. The service will attempt to automatically correct this problem by rebuilding the index.

Details:
    The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (01/13/2016 01:38:07 AM) (Source: Windows Search Service) (EventID: 3038) (User: )
Description: The gatherer is unable to read the registry Path.

Context:  Application, SystemIndex Catalog

Details:
    The registry value cannot be read because the configuration is invalid. Recreate the content index configuration by removing the content index.  (HRESULT : 0x80040d03) (0x80040d03)

Error: (01/13/2016 01:30:03 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1d90

Start Time: 01d14d64da0f7ac4

Termination Time: 78

Application Path: C:\Windows\explorer.exe

Report Id:

Error: (01/13/2016 01:12:53 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: b40

Start Time: 01d14d4cf7a6b83b

Termination Time: 14929

Application Path: C:\Windows\Explorer.EXE

Report Id:

Error: (01/11/2016 10:47:09 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (3740) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.


System errors:
=============
Error: (01/18/2016 06:02:16 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (01/18/2016 05:59:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\bcmihvsrv.dll

Error: (01/18/2016 05:59:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\bcmihvsrv.dll

Error: (01/18/2016 05:59:51 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\bcmihvsrv.dll

Error: (01/18/2016 05:57:39 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056

Error: (01/18/2016 05:57:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Management and Security Application User Notification Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (01/18/2016 05:57:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (01/18/2016 05:57:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (01/18/2016 05:57:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Integrated Clock Controller Service - Intel® ICCS service terminated unexpectedly.  It has done this 1 time(s).

Error: (01/18/2016 05:57:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SAMSUNG Mobile Connectivity Service service terminated unexpectedly.  It has done this 1 time(s).


==================== Memory info ===========================

Processor: Intel® Core™ i5-2520M CPU @ 2.50GHz
Percentage of memory in use: 40%
Total physical RAM: 1929.05 MB
Available physical RAM: 1144.25 MB
Total Virtual: 3858.11 MB
Available Virtual: 2982.17 MB

==================== Drives ================================

Drive c: © (Fixed) (Total:48.83 GB) (Free:21.76 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive e: (New Volume) (Fixed) (Total:184.05 GB) (Free:143.23 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: D90EDE85)
Partition 1: (Active) - (Size=48.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=184 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


Edited by MrBlahh, 18 January 2016 - 07:00 AM.


#14 MrBlahh

MrBlahh
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:03:09 AM

Posted 18 January 2016 - 07:21 AM

Please note from the OP that my friend's machine on the same network is also compromised, so please instruct us when ready as to whether you want this to be treated as the same case or if you want to treat it in a separate topic afterwards (or even simultaneously).

 

-

 

Just for your further info, when I received this machine I immediately uninstalled some programs I knew I didn't want, such as KML Player and Yahoo Instant Messenger. There are all sorts of other stuff on the system I would need to Google first to see what they are, and I never did get to that point because my priority after getting rid of some obvious programs was to update Windows and Dell drivers. It was towards the end of this process that Avast! notified me that the system was infected.

 

Daemon Tools, however, is one I installed so I could later start adding some programs I have had for years backed up on external drives.

 

Therefore, if anything else, beyond malware, strikes you, such as programs for which there are better alternatives or are generally useless please feel free to let me know. If only I could have just formatted the daylights out of this system and set up everything myself!

 

Later maybe that will be an option but really I intend to get a brand new, more modern machine that is more appropriate for everything I use a computer for.



#15 satchfan

satchfan

  • Malware Response Team
  • 2,666 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:09:09 PM

Posted 18 January 2016 - 11:08 AM

Please note from the OP that my friend's machine on the same network is also compromised, so please instruct us when ready as to whether you want this to be treated as the same case or if you want to treat it in a separate topic afterwards (or even simultaneously).

 

I would suggest that your friend starts his/her own topic so that there is no confusion and no further delay.

 

Thank you for the logs. I am going to look at them but may not reply for a few hours as I have just got in from work and have a few things to attend to.

 

Sorry for yet another delay. :)


Edited by satchfan, 18 January 2016 - 11:08 AM.

My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users