Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Got infected Computer and tried so many soft but Still Slow Plz Help


  • This topic is locked This topic is locked
13 replies to this topic

#1 Evil13TM

Evil13TM

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 07 November 2016 - 01:53 PM

I tried to format and reinstall the windows 10 , try so much ways with almost Good anti Virus , Malware programs , ( KIS , Malwarebyte , SpyHunter ...)  but still have so many problem  , i c so many process what i dun know . When i open the process hacker and saw so much remote access to where i ddun know . Plz wat could i do , i will follow u . Im pretty sure about the rootkit , when i make USB BOOT allmost file BOOT rewrite the code like as "YYYYYYYYYYYYYYYYY" , i find everywhere in google and got the infected Master boot record , i c i have 2 disk C and D but when i show the partions i got 4 ...

1111f9401.th.jpg 3333333fd268.th.jpg 222222221ab3e.th.jpg

 

 

 

Log file :

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-11-2016
Ran by Admin (administrator) on QTICKET001 (08-11-2016 01:42:01)
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin (Available Profiles: Admin & Administrator)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\ggdllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\ggdllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\UniKey\UniKeyNT.exe
(Coc Coc Co., Ltd.) C:\Users\Admin\AppData\Local\CocCoc\Update\2.5.15.25\CocCocCrashHandler.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe

==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-07] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [GarenaPlus] => G:\New folder\Downloads\LienMinhHuyenThoai\GameData\GarenaMessenger.exe [9131560 2016-10-20] ()
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [Process Hacker 2] => C:\Program Files\Process Hacker 2\ProcessHacker.exe [1719840 2016-03-29] (wj32)
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [CocCoc Update] => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [113392 2016-11-07] (Coc Coc Co., Ltd.)
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [UniKey] => C:\Program Files\UniKey\UniKeyNT.exe [521216 2014-08-23] ()
IFEO\taskmgr.exe: [Debugger] "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{83476d9b-e0e6-45a1-b65b-712e26ba1d5d}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
FireFox:
========
FF DefaultProfile: nln44nnt.default
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nln44nnt.default [2016-11-07]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2016-09-23] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-07] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2016-11-07]
CHR Extension: (Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-07]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-07]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-07]
CHR Extension: (Thanh toán trên cửa hàng Chrome trực tuyến) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-07]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-11-07] (Microsoft Corporation)
S3 vmicguestinterface; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
S3 vmicheartbeat; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
S3 vmickvpexchange; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
S3 vmicshutdown; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
S3 vmictimesync; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
S3 vmicvmsession; C:\WINDOWS\System32\icsvc.dll [305152 2016-11-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 gkernel; C:\Users\Admin\AppData\Local\Temp\gkernel.sys [50680 2016-11-08] ()
R1 KProcessHacker3; C:\Program Files\Process Hacker 2\kprocesshacker.sys [45208 2016-03-29] (wj32)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [133064 2016-05-28] (BigNox Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R1 XQHDrv; C:\WINDOWS\system32\DRIVERS\XQHDrv.sys [281544 2016-05-28] (BigNox Corporation)
R1 XQHDrv; C:\Windows\SysWOW64\DRIVERS\XQHDrv.sys [281544 2016-05-28] (BigNox Corporation)
R3 ykinw8; C:\WINDOWS\System32\drivers\ykinx64.sys [288768 2016-07-16] (Marvell)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-08 01:42 - 2016-11-08 01:42 - 00009029 _____ C:\Users\Admin\Desktop\FRST.txt
2016-11-08 01:41 - 2016-11-08 01:42 - 00000000 ____D C:\FRST
2016-11-08 01:40 - 2016-11-08 01:41 - 02410496 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2016-11-07 17:36 - 2016-11-07 17:36 - 00014064 ____N C:\bootsqm.dat
2016-11-07 03:57 - 2016-11-06 13:25 - 00000000 ___DC C:\WINDOWS\Panther
2016-11-07 03:54 - 2016-11-07 03:54 - 00000000 ____D C:\Windows.old
2016-11-07 03:50 - 2016-11-07 03:50 - 00000041 _____ C:\Users\Admin\inst.ini
2016-11-07 03:50 - 2016-11-07 03:50 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Nox
2016-11-07 03:49 - 2016-11-07 03:50 - 00000000 ____D C:\Users\Admin\vmlogs
2016-11-07 03:49 - 2016-11-07 03:49 - 00000000 ____D C:\Program Files\DIFX
2016-11-07 03:49 - 2016-11-07 03:49 - 00000000 ____D C:\Program Files\Bignox
2016-11-07 03:49 - 2016-05-28 09:26 - 00281544 _____ (BigNox Corporation) C:\WINDOWS\system32\Drivers\XQHDrv.sys
2016-11-07 03:49 - 2016-05-28 09:26 - 00133064 _____ (BigNox Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2016-11-07 03:48 - 2016-11-07 03:54 - 00000000 ____D C:\Users\Admin\AppData\Local\Nox
2016-11-07 03:48 - 2016-11-07 03:48 - 23680000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 22568960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 19418112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 13441024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 13081600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 12349440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-11-07 03:48 - 2016-11-07 03:48 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-11-07 03:48 - 2016-11-07 03:48 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 08126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04747776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04129928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03778560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03307520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02781184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-11-07 03:48 - 2016-11-07 03:48 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-11-07 03:48 - 2016-11-07 03:48 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02481768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02446696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02256592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02256224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 02213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-11-07 03:48 - 2016-11-07 03:48 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-11-07 03:48 - 2016-11-07 03:48 - 01990648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01891328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01853776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01705976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01608896 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01472536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01320448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 01291264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01181536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01130496 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01000288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-11-07 03:48 - 2016-11-07 03:48 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00940032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00862064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2016-11-07 03:48 - 2016-11-07 03:48 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00798720 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00755656 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00725664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00691080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00649568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00640976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00628040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00512416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00498952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00450392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00446124 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-11-07 03:48 - 2016-11-07 03:48 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00424640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00409952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-11-07 03:48 - 2016-11-07 03:48 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00402352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00382272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00292872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00280472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2016-11-07 03:48 - 2016-11-07 03:48 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
2016-11-07 03:48 - 2016-11-07 03:48 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00218008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingFolder.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2016-11-07 03:48 - 2016-11-07 03:48 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovslegacy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00133472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chartv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00090400 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pwrshplugin.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManagerApi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00057400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 00023392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
2016-11-07 03:48 - 2016-11-07 03:48 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-11-07 03:48 - 2016-11-07 03:48 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2016-11-07 03:48 - 2016-11-07 03:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Nox
2016-11-07 03:47 - 2016-11-07 03:47 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 08158672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 07817568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 07792640 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 07654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 07468032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 06654616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 06108672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05622088 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 04136960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03435008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03287552 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03116544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 03054080 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02999808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 02947072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02914304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02827864 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02750384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02748928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02708992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02670592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02476544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02290176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02276736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02083840 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01980416 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01913344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01851696 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01738040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01556712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01554944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01512960 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01492480 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01424488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01358336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-11-07 03:47 - 2016-11-07 03:47 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01322848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 01292640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01267504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01263848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01112928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-11-07 03:47 - 2016-11-07 03:47 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01037312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00988512 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-11-07 03:47 - 2016-11-07 03:47 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00908640 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00894088 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00860512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00823136 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00773712 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00764936 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00749920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00742704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00681304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00658272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00650240 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00646136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00595296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00576400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00500064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00461312 _____ (Microsoft) C:\WINDOWS\SysWOW64\DbgModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00434528 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00406016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00340320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2016-11-07 03:47 - 2016-11-07 03:47 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00283488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00262960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00238056 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00232800 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\tspubwmi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00206096 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00204288 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00186424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00170960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00169056 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-11-07 03:47 - 2016-11-07 03:47 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00130912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00127328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00119648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00113504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-11-07 03:47 - 2016-11-07 03:47 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00083120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00081760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmifw.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00079200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00078688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00074080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00064352 _____ (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AddressParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactActivation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-11-07 03:47 - 2016-11-07 03:47 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stdole2.tlb
2016-11-07 03:47 - 2016-11-07 03:47 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\stdole2.tlb
2016-11-07 03:47 - 2016-11-07 03:47 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
2016-11-07 03:47 - 2016-11-07 03:47 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccessRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneutilRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-11-07 03:43 - 2016-11-07 03:48 - 309542216 _____ (Duodian Technology Co. Ltd.) C:\Users\Admin\Downloads\nox_setup_v3.7.3.0_full_En.exe
2016-11-07 03:39 - 2016-07-16 10:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-11-07 03:39 - 2016-07-16 10:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-11-07 03:39 - 2016-07-16 10:28 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-11-07 03:39 - 2016-07-16 10:26 - 00376320 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2016-11-07 03:39 - 2016-07-16 10:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-11-07 03:39 - 2016-07-16 10:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2016-11-07 03:39 - 2016-07-16 10:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2016-11-07 03:39 - 2016-07-16 10:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2016-11-07 03:39 - 2016-07-16 10:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2016-11-07 03:39 - 2016-07-16 10:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-11-07 03:39 - 2016-07-16 10:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-11-07 03:39 - 2016-07-16 10:15 - 06582784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2016-11-07 03:39 - 2016-07-16 10:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-11-07 03:39 - 2016-07-16 10:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2016-11-07 03:39 - 2016-07-16 10:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-11-07 03:39 - 2016-07-16 10:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-11-07 03:39 - 2016-07-16 10:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2016-11-07 03:39 - 2016-07-16 10:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2016-11-07 03:39 - 2016-07-16 09:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2016-11-07 03:39 - 2016-07-16 09:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2016-11-07 03:39 - 2016-07-16 09:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2016-11-07 03:39 - 2016-07-16 09:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2016-11-07 03:39 - 2016-07-16 09:41 - 00355840 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2016-11-07 03:39 - 2016-07-16 09:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2016-11-07 03:39 - 2016-07-16 09:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2016-11-07 03:39 - 2016-07-16 09:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2016-11-07 03:39 - 2016-07-16 09:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2016-11-07 03:39 - 2016-07-16 09:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2016-11-07 03:39 - 2016-07-16 09:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2016-11-07 03:39 - 2016-07-16 09:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2016-11-07 03:39 - 2016-07-16 09:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2016-11-07 03:39 - 2016-07-16 09:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2016-11-07 03:39 - 2016-07-16 09:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2016-11-07 03:39 - 2016-07-16 09:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2016-11-07 03:39 - 2016-07-16 09:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2016-11-07 03:39 - 2016-07-16 09:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2016-11-07 03:38 - 2016-11-07 03:38 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-11-07 03:38 - 2016-11-06 12:59 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-11-07 03:37 - 2016-11-07 03:37 - 25397336 _____ (One Click Root) C:\Users\Admin\AppData\Local\TempOneClickRoot.exe
2016-11-07 03:37 - 2016-11-07 03:37 - 00001257 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One Click Root.lnk
2016-11-07 03:37 - 2016-11-07 03:37 - 00000000 ____D C:\Users\Admin\AppData\Local\oneClickRoot
2016-11-07 03:37 - 2016-11-07 03:37 - 00000000 ____D C:\Users\Admin\AppData\Local\AWSToolkit
2016-11-07 03:37 - 2016-11-07 03:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One Click Root
2016-11-07 03:37 - 2016-11-07 03:37 - 00000000 ____D C:\Program Files (x86)\One Click Root
2016-11-07 03:36 - 2016-11-07 03:36 - 00771376 _____ C:\Users\Admin\Downloads\OneClickRoot (1).exe
2016-11-07 03:35 - 2016-11-07 03:35 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-11-07 03:35 - 2016-11-07 03:35 - 00000000 ____D C:\Program Files\MSBuild
2016-11-07 03:35 - 2016-11-07 03:35 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-11-07 03:35 - 2016-11-07 03:35 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-11-07 03:35 - 2016-05-26 05:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-11-07 03:35 - 2016-05-26 05:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-11-07 03:35 - 2016-05-26 05:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-11-07 03:35 - 2016-05-26 02:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-11-07 03:35 - 2016-05-26 02:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-11-07 03:35 - 2016-05-26 02:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-11-07 03:34 - 2016-11-07 03:34 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2016-11-07 03:34 - 2016-11-07 03:34 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-11-07 03:22 - 2016-11-07 17:36 - 00001006 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-07 03:22 - 2016-11-07 17:36 - 00001002 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-07 03:22 - 2016-11-07 03:22 - 00004064 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-11-07 03:22 - 2016-11-07 03:22 - 00003832 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-11-07 03:22 - 2016-11-07 03:22 - 00002340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-07 03:22 - 2016-11-07 03:22 - 00002328 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-11-07 03:21 - 2016-11-07 03:22 - 00000000 ____D C:\Users\Admin\AppData\Local\Google
2016-11-07 03:21 - 2016-11-07 03:22 - 00000000 ____D C:\Program Files (x86)\Google
2016-11-07 03:21 - 2016-11-07 03:21 - 01065376 _____ (Google Inc.) C:\Users\Admin\Downloads\ChromeSetup (1).exe
2016-11-07 03:19 - 2016-11-07 03:19 - 00002469 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cốc Cốc.lnk
2016-11-07 03:19 - 2016-11-07 03:19 - 00002461 _____ C:\Users\Admin\Desktop\Cốc Cốc.lnk
2016-11-07 03:13 - 2016-11-07 19:05 - 00000000 ____D C:\Users\Admin\AppData\Local\Mozilla
2016-11-07 03:13 - 2016-11-07 03:15 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Mozilla
2016-11-07 03:13 - 2016-11-07 03:13 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-11-07 03:13 - 2016-11-07 03:13 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-11-07 03:13 - 2016-11-07 03:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-11-07 03:13 - 2016-11-07 03:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-07 03:12 - 2016-11-07 17:36 - 00001024 _____ C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA.job
2016-11-07 03:12 - 2016-11-07 17:36 - 00000972 _____ C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core.job
2016-11-07 03:12 - 2016-11-07 03:19 - 00000000 ____D C:\Users\Admin\AppData\Roaming\CocCoc
2016-11-07 03:12 - 2016-11-07 03:19 - 00000000 ____D C:\Users\Admin\AppData\Local\CocCoc
2016-11-07 03:12 - 2016-11-07 03:12 - 00663040 _____ (Coc Coc Co., Ltd.) C:\Users\Admin\Downloads\coccoc_vi (1).exe
2016-11-07 03:12 - 2016-11-07 03:12 - 00243520 _____ C:\Users\Admin\Downloads\Firefox Setup Stub 49.0.2.exe
2016-11-07 03:12 - 2016-11-07 03:12 - 00004140 _____ C:\WINDOWS\System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA
2016-11-07 03:12 - 2016-11-07 03:12 - 00003764 _____ C:\WINDOWS\System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core
2016-11-06 23:09 - 2016-11-06 23:11 - 00327740 _____ C:\WINDOWS\Minidump\110616-24140-01.dmp
2016-11-06 23:09 - 2016-11-06 23:09 - 738385450 _____ C:\WINDOWS\MEMORY.DMP
2016-11-06 23:09 - 2016-11-06 23:09 - 00000000 ____D C:\WINDOWS\Minidump
2016-11-06 22:28 - 2016-11-06 22:28 - 06080107 _____ C:\Users\Admin\Downloads\r3-galaxynexus-superboot.zip
2016-11-06 22:22 - 2016-11-07 03:24 - 00000000 ____D C:\root
2016-11-06 21:37 - 2016-11-06 21:37 - 00002042 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk
2016-11-06 21:37 - 2016-11-06 21:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2016-11-06 21:37 - 2016-11-06 21:37 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2016-11-06 20:10 - 2016-11-06 20:10 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Process Hacker 2
2016-11-06 19:59 - 2016-11-06 19:59 - 00001880 _____ C:\Users\Public\Desktop\Process Hacker 2.lnk
2016-11-06 19:59 - 2016-11-06 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2
2016-11-06 19:59 - 2016-11-06 19:59 - 00000000 ____D C:\Program Files\Process Hacker 2
2016-11-06 19:58 - 2016-11-06 19:59 - 02267848 _____ (wj32 ) C:\Users\Admin\Downloads\processhacker-2.39-setup.exe
2016-11-06 18:41 - 2016-11-06 18:52 - 00000000 ____D C:\Users\Admin\a
2016-11-06 13:59 - 2016-11-06 14:00 - 16044077 _____ C:\Users\Admin\Downloads\SAMSUNG_USB_Driver_for_Mobile_Phones.zip
2016-11-06 13:41 - 2016-11-06 13:41 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-11-06 13:40 - 2016-11-06 13:40 - 00000000 ____D C:\ProgramData\USOShared
2016-11-06 13:39 - 2016-11-06 13:39 - 00000020 ___SH C:\Users\Admin\ntuser.ini
2016-11-06 13:39 - 2016-11-06 13:39 - 00000000 ____D C:\Users\Admin\AppData\Local\ConnectedDevicesPlatform
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default\My Documents
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-11-06 13:24 - 2016-11-06 13:24 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-11-06 13:22 - 2016-11-08 01:24 - 00003716 _____ C:\WINDOWS\System32\Tasks\Garena+ Plugin Host Service
2016-11-06 13:22 - 2016-11-08 01:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-06 13:22 - 2016-11-06 13:24 - 00011433 _____ C:\WINDOWS\diagwrn.xml
2016-11-06 13:22 - 2016-11-06 13:24 - 00011433 _____ C:\WINDOWS\diagerr.xml
2016-11-06 13:22 - 2016-11-06 13:22 - 00003298 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4B3A6DA3-B131-4179-AFD1-8F2ADC565285}
2016-11-06 13:22 - 2016-11-06 13:22 - 00002822 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task
2016-11-06 13:17 - 2016-11-06 13:17 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-11-06 13:09 - 2016-11-06 13:09 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-11-06 13:08 - 2016-11-06 13:10 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-11-06 13:06 - 2016-11-07 03:50 - 00000000 ____D C:\Users\Admin
2016-11-06 13:06 - 2016-11-06 13:16 - 00000000 ____D C:\Users\Administrator
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Administrator\My Documents
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Administrator\Documents\My Videos
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Administrator\Documents\My Pictures
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Administrator\Documents\My Music
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Admin\My Documents
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Admin\Documents\My Videos
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Admin\Documents\My Pictures
2016-11-06 13:06 - 2016-11-06 13:06 - 00000000 _SHDL C:\Users\Admin\Documents\My Music
2016-11-06 13:01 - 2016-07-16 18:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-11-06 12:59 - 2016-11-08 01:23 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-11-06 12:58 - 2016-11-06 13:10 - 00194192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-11-06 03:26 - 2016-11-06 12:16 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2016-11-05 23:33 - 2016-11-05 23:33 - 00001025 _____ C:\Users\Admin\Downloads\BKshare.Com-KTS2018.rar
2016-11-05 23:24 - 2016-11-05 23:37 - 281396120 _____ (Kaspersky Lab) C:\Users\Admin\Downloads\kes10winsp1_mr2_vi_aes256.exe
2016-11-05 17:42 - 2016-11-07 02:27 - 00000000 ____D C:\Users\Admin\Downloads\ROOT M919 4.4.4
2016-11-05 17:20 - 2016-11-05 17:20 - 23923033 _____ C:\Users\Admin\Downloads\ROOT M919 4.4.4.rar
2016-11-05 17:03 - 2016-11-06 13:10 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-11-05 17:03 - 2016-11-06 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-11-05 17:03 - 2016-11-05 17:04 - 00000000 ____D C:\Users\Admin\Downloads\Root_I337_4.4.4
2016-11-05 17:03 - 2016-11-05 17:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\WinRAR
2016-11-05 17:03 - 2016-11-05 17:03 - 00000000 ____D C:\Program Files (x86)\WinRAR
2016-11-05 17:02 - 2016-11-05 17:03 - 01972424 _____ C:\Users\Admin\Downloads\wrar540.exe
2016-11-05 17:01 - 2016-11-05 17:01 - 00000000 ____D C:\Program Files\Samsung
2016-11-05 17:00 - 2016-11-05 17:00 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2016-11-05 16:59 - 2016-11-06 21:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Samsung
2016-11-05 16:59 - 2016-11-06 21:37 - 00000000 ____D C:\Program Files (x86)\Samsung
2016-11-05 16:59 - 2016-11-05 17:00 - 19468687 _____ C:\Users\Admin\Downloads\Root_I337_4.4.4.rar
2016-11-05 16:59 - 2016-11-05 17:00 - 00000000 ____D C:\ProgramData\Samsung
2016-11-05 16:59 - 2016-11-05 16:59 - 00000000 ____D C:\Users\Admin\Documents\samsung
2016-11-05 16:59 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\WINDOWS\SysWOW64\secman.dll
2016-11-05 16:57 - 2016-11-05 16:57 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2016-11-05 16:56 - 2016-11-05 16:58 - 40605640 _____ (Samsung Electronics Co., Ltd.) C:\Users\Admin\Downloads\Kies3Setup.exe
2016-11-05 16:09 - 2016-11-05 16:09 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-11-05 15:29 - 2016-11-05 15:29 - 00000000 ____D C:\Users\Admin\Documents\League of Legends
2016-11-05 14:30 - 2016-10-28 08:22 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-11-05 14:24 - 2016-11-05 14:24 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Admin\Downloads\iExplore.exe
2016-11-05 14:24 - 2016-11-05 14:24 - 01106888 _____ (Bleeping Computer, LLC) C:\Users\Admin\Downloads\iExplore64-27556.exe
2016-11-05 14:12 - 2016-11-05 14:12 - 00000000 _____ C:\WINDOWS\system32\reimage.rep
2016-11-05 14:11 - 2016-11-05 14:11 - 00022282 _____ C:\WINDOWS\system32\.crusader
2016-11-05 13:52 - 2016-11-05 14:11 - 00000000 ____D C:\ProgramData\HitmanPro
2016-11-05 13:49 - 2016-11-05 13:49 - 00000650 _____ C:\WINDOWS\Tasks\Reimage-Post-Reboot.job
2016-11-05 13:37 - 2016-11-05 13:49 - 00000000 ____D C:\ReimageUndo
2016-11-05 13:37 - 2016-11-05 13:37 - 00012710 _____ C:\WINDOWS\system32\Native.exe
2016-11-05 13:10 - 2016-11-05 13:10 - 00000000 _____ C:\Users\Admin\Desktop\New Text Document.txt
2016-11-05 12:49 - 2016-11-05 12:49 - 00000344 _____ C:\WINDOWS\Tasks\ReimageUpdater.job
2016-11-05 12:36 - 2016-11-07 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-11-05 12:35 - 2016-11-07 02:32 - 00000000 ____D C:\Users\Admin\Desktop\mbar
2016-11-05 12:21 - 2016-11-08 01:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-11-05 12:20 - 2016-11-07 01:47 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-11-05 12:20 - 2016-11-06 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-11-05 12:20 - 2016-11-05 12:35 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Admin\Desktop\maytao2.exe
2016-11-05 12:20 - 2016-11-05 12:20 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-11-05 12:20 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-11-05 12:19 - 2016-11-05 12:19 - 22851472 _____ (Malwarebytes ) C:\Users\Admin\Desktop\maytao.exe
2016-11-05 12:07 - 2016-11-05 12:20 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-11-05 12:07 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-11-05 11:37 - 2016-11-05 12:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes
2016-11-05 11:37 - 2016-11-05 12:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-11-05 11:31 - 2016-11-05 12:05 - 00000000 ____D C:\ProgramData\RogueKiller
2016-11-05 11:31 - 2016-11-05 11:31 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-11-05 11:28 - 2016-11-05 13:53 - 11579432 _____ (SurfRight B.V.) C:\Users\Admin\Desktop\Hitman3game.exe
2016-11-05 11:22 - 2016-11-05 11:31 - 25288776 _____ C:\Users\Admin\Desktop\Rllerbe.exe
2016-11-05 11:14 - 2016-11-05 11:14 - 28079126 _____ C:\Users\Admin\Desktop\rpwd.zip
2016-11-05 10:58 - 2016-11-05 11:06 - 00000000 ____D C:\Users\Admin\AppData\Local\ElevatedDiagnostics
2016-11-05 10:55 - 2016-11-05 10:55 - 00000000 ____D C:\TDSSKiller_Quarantine
2016-11-05 10:36 - 2016-11-05 10:53 - 00000000 ____D C:\AdwCleaner
2016-11-05 10:34 - 2016-11-05 11:08 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-11-05 10:33 - 2016-11-05 14:02 - 00597474 _____ C:\WINDOWS\ntbtlog.txt
2016-11-05 10:30 - 2016-11-05 10:30 - 02915320 _____ (Google) C:\Users\Admin\Downloads\chrome_cleanup_tool.exe
2016-11-05 10:26 - 2016-11-05 14:27 - 00001888 _____ C:\Users\Admin\Desktop\Rkill.txt
2016-11-05 10:24 - 2016-11-05 10:56 - 05658651 _____ (Swearware) C:\Users\Admin\Desktop\CF4.exe
2016-11-05 10:11 - 2016-11-05 10:36 - 03910208 _____ C:\Users\Admin\Desktop\winitn1.exe
2016-10-31 18:22 - 2016-10-31 18:22 - 00000000 __SHD C:\found.000
2016-10-31 18:17 - 2016-10-31 18:17 - 00000000 ____D C:\Users\Admin\AppData\Local\PeerDistRepub
2016-10-31 14:53 - 2016-10-31 14:53 - 00001085 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UnikeyNT.lnk
2016-10-31 14:53 - 2016-10-31 14:53 - 00000849 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UniKey.lnk
2016-10-31 14:53 - 2016-10-31 14:53 - 00000837 _____ C:\Users\Public\Desktop\UniKey.lnk
2016-10-31 14:53 - 2016-10-31 14:53 - 00000000 ____D C:\Program Files\UniKey
2016-10-31 14:52 - 2016-10-31 14:52 - 00780571 _____ (UniKey ) C:\Users\Admin\Downloads\UniKey-4.2RC4-140823-Setup_x64.exe
2016-10-31 11:10 - 2016-11-05 16:11 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-30 22:06 - 2016-10-30 22:06 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2016-10-30 19:59 - 2016-10-30 19:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Macromedia
2016-10-30 19:59 - 2016-10-30 19:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\LolClient
2016-10-30 19:58 - 2016-10-30 19:58 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Garena
2016-10-30 19:58 - 2016-10-30 19:58 - 00000000 ____D C:\ProgramData\Garena
2016-10-30 19:57 - 2016-11-07 20:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\GarenaPlus
2016-10-30 19:57 - 2016-11-07 20:03 - 00000000 ____D C:\ProgramData\GarenaMessenger
2016-10-30 19:57 - 2016-11-06 23:30 - 00001615 _____ C:\Users\Admin\Desktop\GarenaMessenger.exe - Shortcut.lnk
2016-10-30 12:23 - 2016-11-06 13:22 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-10-30 12:23 - 2016-11-06 13:08 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-10-30 12:23 - 2016-10-30 12:23 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2016-10-30 12:23 - 2016-10-30 12:20 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2016-10-30 12:23 - 2016-10-30 12:20 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2016-10-30 12:23 - 2016-10-30 12:20 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2016-10-30 12:23 - 2016-10-30 12:20 - 00000219 _____ C:\WINDOWS\system.ini
2016-10-30 12:23 - 2016-10-30 12:20 - 00000092 _____ C:\WINDOWS\win.ini
2016-10-30 12:23 - 2016-10-29 21:54 - 00000000 ____D C:\WINDOWS\CSC
2016-10-30 11:57 - 2016-11-06 13:10 - 00000000 ____D C:\Users\Default.migrated
2016-10-30 11:56 - 2016-10-30 19:56 - 00000000 ___HD C:\$SysReset
2016-10-30 06:35 - 2016-10-30 06:35 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-10-30 01:24 - 2016-10-30 20:03 - 00000000 ____D C:\Users\Admin\AppData\Local\MicrosoftEdge
2016-10-29 22:22 - 2016-10-29 22:22 - 00000000 ____D C:\Users\Admin\AppData\Local\Comms
2016-10-29 22:10 - 2016-11-05 12:34 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Enigma Software Group
2016-10-29 22:10 - 2016-10-29 22:10 - 00000000 _____ C:\autoexec.bat
2016-10-29 22:08 - 2016-11-05 12:34 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-10-29 22:05 - 2016-11-06 13:42 - 00002363 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-10-29 22:04 - 2016-10-29 22:04 - 00000000 ____D C:\Users\Admin\AppData\Local\ActiveSync
2016-10-29 22:02 - 2016-10-29 22:02 - 00000000 ____D C:\Users\Admin\AppData\Local\Publishers
2016-10-29 22:01 - 2016-11-08 01:28 - 00978608 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-29 22:01 - 2016-11-06 13:56 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages
2016-10-29 22:01 - 2016-10-29 22:01 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe
2016-10-29 22:01 - 2016-10-29 22:01 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore
2016-10-29 22:01 - 2016-10-29 22:01 - 00000000 ____D C:\Users\Admin\AppData\Local\TileDataLayer
2016-10-29 22:00 - 2016-10-29 22:00 - 00000000 _SHDL C:\Users\Default.migrated\Documents\My Videos
2016-10-29 22:00 - 2016-10-29 22:00 - 00000000 _SHDL C:\Users\Default.migrated\Documents\My Pictures
2016-10-29 22:00 - 2016-10-29 22:00 - 00000000 _SHDL C:\Users\Default.migrated\Documents\My Music
2016-10-29 21:59 - 2016-10-29 21:59 - 00008798 _____ C:\Users\Administrator\AppData\Local\Application.xml
2016-10-29 21:56 - 2016-10-29 21:57 - 00000000 ____D C:\Users\DefaultAppPool
2016-10-29 21:56 - 2016-10-29 21:56 - 00000000 _SHDL C:\Users\DefaultAppPool\My Documents
2016-10-29 21:56 - 2016-10-29 21:56 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Videos
2016-10-29 21:56 - 2016-10-29 21:56 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Pictures
2016-10-29 21:56 - 2016-10-29 21:56 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Music
2016-10-23 21:35 - 2016-10-23 21:35 - 00000000 _____ C:\Recovery.txt
2016-10-22 20:13 - 2016-10-22 20:13 - 00291606 _____ C:\Users\Admin\Desktop\TCPView.zip
2016-10-22 12:11 - 2016-10-22 12:11 - 00000055 _____ C:\Users\Administrator\Desktop\New Text Document.txt
2016-10-22 05:37 - 2016-10-22 12:12 - 00000000 ____D C:\Users\Administrator\Downloads\SpyHunter 4.23.2.4686
2016-10-22 05:35 - 2016-10-22 05:36 - 10799407 _____ C:\Users\Administrator\Downloads\SpyHunter 4.23.2.4686.rar
2016-10-22 04:55 - 2016-10-22 04:55 - 00117209 _____ C:\Users\Admin\Desktop\cports-x64.zip
2016-10-22 02:23 - 2016-10-22 02:23 - 00001601 _____ C:\Users\Admin\Desktop\Microsoft Edge.lnk
2016-10-21 06:25 - 2016-10-21 06:26 - 30639184 _____ (Igor Pavlov) C:\Users\Admin\Downloads\vulnerabilityscanner(1).exe
2016-10-21 03:50 - 2016-10-21 03:50 - 00000000 ____D C:\Users\Admin\Downloads\TienIchMayTinh.Com___Repack KIS 16.0.0.614vi
2016-10-21 03:46 - 2016-10-21 03:50 - 166705873 _____ C:\Users\Admin\Downloads\TienIchMayTinh.Com___Repack KIS 16.0.0.614vi.rar
2016-10-20 16:46 - 2016-10-20 16:46 - 00001972 _____ C:\Users\Admin\Desktop\ICQ.lnk
2016-10-18 18:02 - 2016-10-18 18:02 - 00011349 _____ C:\Users\Admin\Downloads\p.txt
2016-10-17 20:35 - 2016-10-17 20:37 - 00000000 ____D C:\AppServ
2016-10-17 15:45 - 2016-10-17 15:46 - 00001845 _____ C:\Users\Admin\Desktop\qticket.pem
2016-10-15 20:30 - 2016-10-15 21:33 - 00001317 _____ C:\Users\Admin\Desktop\Dumpper - Shortcut.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-07 17:39 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-11-07 03:57 - 2016-07-16 18:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-11-07 03:52 - 2016-02-02 20:32 - 00000000 ____D C:\Users\Admin\.android
2016-11-07 03:50 - 2016-07-16 21:29 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2016-11-07 03:50 - 2016-07-16 18:47 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ___RD C:\Program Files\Windows Defender
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\setup
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\Provisioning
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-11-07 03:50 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-11-07 03:50 - 2016-07-16 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-11-07 03:50 - 2016-07-16 13:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-11-07 03:50 - 2016-07-01 07:28 - 00001001 _____ C:\Users\Admin\Desktop\Multi-Drive.lnk
2016-11-07 03:50 - 2016-07-01 07:28 - 00000920 _____ C:\Users\Admin\Desktop\Nox.lnk
2016-11-07 03:50 - 2016-07-01 07:27 - 00000000 ____D C:\Users\Admin\.BigNox
2016-11-07 03:49 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\Registration
2016-11-07 03:49 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-11-07 03:49 - 2016-07-16 18:45 - 00000000 ____D C:\WINDOWS\INF
2016-11-07 03:11 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-11-07 02:45 - 2016-07-16 13:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-11-06 17:55 - 2016-07-16 18:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-11-06 15:41 - 2016-07-16 18:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-11-06 15:13 - 2015-12-10 11:00 - 00000701 _____ C:\Users\Admin\Desktop\UniKey.lnk
2016-11-06 14:58 - 2016-04-13 15:38 - 00000000 ____D C:\Users\Admin\Downloads\aa
2016-11-06 14:22 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-11-06 13:42 - 2016-04-11 01:27 - 00000000 ___RD C:\Users\Admin\OneDrive
2016-11-06 13:40 - 2016-07-16 18:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-11-06 13:39 - 2016-07-16 18:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-11-06 13:39 - 2016-02-13 20:22 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-11-06 13:26 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\rescache
2016-11-06 13:24 - 2016-07-16 13:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-11-06 13:22 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-11-06 13:17 - 2016-07-16 18:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-11-06 13:13 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-11-06 13:04 - 2016-07-16 13:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-11-06 13:02 - 2016-07-16 18:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-11-06 13:02 - 2016-07-16 18:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-11-06 13:02 - 2016-07-16 18:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-11-06 12:17 - 2016-07-16 22:17 - 00000000 ___HD C:\$WINDOWS.~BT
2016-11-05 15:59 - 2016-05-17 05:52 - 00000000 ____D C:\Users\Admin\Downloads\Dumpper-50.5-Viet
2016-11-05 13:49 - 2016-07-10 02:58 - 00000000 ____D C:\Users\Admin\Downloads\aakho
2016-10-29 21:57 - 2009-07-14 14:45 - 00000000 ____D C:\Users\Public\Recorded TV
2016-10-25 06:30 - 2016-07-16 18:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-25 06:30 - 2016-07-16 18:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-21 09:52 - 2016-04-27 06:46 - 00000000 ____D C:\Users\Admin\Downloads\tx
2016-10-21 08:41 - 2016-08-11 05:16 - 00001879 _____ C:\Users\Admin\Desktop\Remote Desktop Connection.lnk
2016-10-19 18:17 - 2016-04-26 21:02 - 00373140 _____ C:\Users\Admin\Downloads\data.rar
2016-10-16 03:59 - 2016-09-22 14:15 - 00000000 ____D C:\Users\Admin\Downloads\229
==================== Files in the root of some directories =======
2016-11-07 03:37 - 2016-11-07 03:37 - 25397336 _____ (One Click Root) C:\Users\Admin\AppData\Local\TempOneClickRoot.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-11-06 12:58
==================== End of FRST.txt ============================

Attached Files


Edited by Evil13TM, 08 November 2016 - 04:36 AM.


BC AdBot (Login to Remove)

 


#2 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 07 November 2016 - 02:10 PM

And additon.txt log :

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
Ran by Admin (08-11-2016 01:44:22)
Running from C:\Users\Admin\Desktop
Windows 10 Pro Version 1607 (X64) (2016-11-06 06:25:16)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================
Admin (S-1-5-21-2844419887-631773965-2609765522-1000 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-2844419887-631773965-2609765522-500 - Administrator - Disabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-2844419887-631773965-2609765522-503 - Limited - Disabled)
Guest (S-1-5-21-2844419887-631773965-2609765522-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Cốc Cốc (HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\CocCocBrowser) (Version: 52.3.2743.136 - Đơn vị chủ quản Cốc Cốc)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{02A39130-2CF3-30CA-8623-30F6071A4221}) (Version: 9.0.21022 - Microsoft Corporation)
Mozilla Firefox 49.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 en-US)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2 - Mozilla)
Nox APP Player (HKLM-x32\...\Nox) (Version: 3.7.3.0 - Duodian Technology Co. Ltd.)
One Click Root (HKLM-x32\...\{6EAD0BE5-D1CF-4BE8-A66F-53FE9B8D89CC}) (Version: 1.0.0.3 - One Click Root)
Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.16044.2 - Samsung Electronics Co., Ltd.) Hidden
UniKey version 4.2 RC4 (HKLM\...\{8DB56539-5BB2-4D7E-B4E3-5DB718C99CF3}_is1) (Version: 4.2 RC4 - UniKey)
Windows Driver Package - BigNox Corporation XQHDrv System  (05/27/2016 4.3.12) (HKLM\...\94C2625000FDEC5DD549EADDF8698D48672C3037) (Version: 05/27/2016 4.3.12 - BigNox Corporation)
Windows Driver Package - Oracle Corporation (VBoxUSB) USB  (05/27/2016 4.3.12) (HKLM\...\9B8A57D7ECC2B5D3115B5A1361FAE29AC92E355B) (Version: 05/27/2016 4.3.12 - Oracle Corporation)
Windows Driver Package - Oracle Corporation VBoxUSBMon System  (05/27/2016 4.3.12) (HKLM\...\2B96D1320C797F081985B7C1EA9A2DABAC2644BF) (Version: 05/27/2016 4.3.12 - Oracle Corporation)
WinRAR 5.40 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileCoAuth.exe (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {433128C5-E70B-4F0C-9356-2B109BF16E18} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-07] (Google Inc.)
Task: {586C697A-EF35-48E9-8E96-9EEDF4DDD355} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: {A89CE705-CC2E-4D58-9C66-B8C2959F1E07} - System32\Tasks\Garena+ Plugin Host Service => C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\ggdllhost.exe [2016-02-22] ()
Task: {BC340245-4A36-4A5A-A152-5E7A2AB10E90} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: {E53B3B8F-B90F-4490-B3A0-77B0761F08B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-07] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Reimage-Post-Reboot.job => C:\ReimageUndo\PostReboot\PostRebootExecuter.exe©false shek C:\Program Files\Reimage\Reimage Repair\Reimage.exe C:\ReimageUndo\PostReboot\post_reboot.htm <==== ATTENTION
Task: C:\WINDOWS\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 18:42 - 2016-07-16 18:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-07-01 19:42 - 2016-02-22 18:24 - 00174632 _____ () C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\ggdllhost.exe
2016-11-07 03:47 - 2016-11-07 03:47 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-11-06 13:41 - 2016-11-06 13:41 - 01864384 _____ () C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll
2016-11-07 03:47 - 2016-11-07 03:47 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2012-11-27 13:54 - 2012-11-27 13:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2016-10-31 14:53 - 2014-08-23 16:24 - 00521216 _____ () C:\Program Files\UniKey\UniKeyNT.exe
2016-11-07 03:48 - 2016-11-07 03:48 - 09760256 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 02424832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-07 03:48 - 2016-11-07 03:48 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-01 19:42 - 2016-09-29 11:26 - 03437008 _____ () C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\ggspawn.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-10-30 12:23 - 2016-10-30 12:20 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\...\StartupApproved\Run: => "MouseDriver"
HKLM\...\StartupApproved\Run: => "WindowsDefender"
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{7DFA6EB9-FF8A-49C0-BEBD-27247DBB8C27}] => (Allow) LPort=6985
FirewallRules: [{5460CB29-AE00-4458-9E6F-F1DE85294C1A}] => (Allow) LPort=6985
FirewallRules: [{115CB5AD-2F57-4677-B0BF-92F1A7B34AB4}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{6668B4BB-1212-41B8-B10E-9F659FF7BD84}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{05F796CE-EAAE-4888-9321-63CF2E3FFA67}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{E0F464C8-4D56-403B-9FEE-12290DB27050}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{08D3EC3B-CE84-4E4F-891C-9B54AE42FC54}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{CF64EF32-A0A6-4911-9B4F-9CAB4E7BA43E}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{D168AEAF-85C9-4DFA-8353-14996E57AC93}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{2EC6984D-C72F-412F-8203-A21EAC8CC89B}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{3E9386C9-248C-4AF8-95ED-0183982DE0B9}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\lol.exe
FirewallRules: [{840CDF86-F956-4A59-A257-77179F10853F}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\lol.exe
FirewallRules: [{86A0E337-8798-4DDE-BE61-67302F76B107}] => (Allow) LPort=6982
FirewallRules: [{EE46A490-F6C4-4867-88E1-0B1A14D9C9DC}] => (Allow) LPort=6982
FirewallRules: [{90E32C2F-3809-411C-970C-1B64E4F0510B}] => (Allow) LPort=6972
FirewallRules: [{4BDFCF6E-D43D-4AB8-A855-F954EBB19677}] => (Allow) LPort=6972
FirewallRules: [{19E45048-4BFA-4AC0-B144-28D2AECBB8BC}] => (Allow) LPort=6995
FirewallRules: [{FF1FB653-9265-4984-A65C-793F0A34E06C}] => (Allow) LPort=6995
FirewallRules: [{C76634F5-A935-45B8-9AFF-5180360463CF}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{EA5DF2B8-3966-40AA-B15E-482A29966453}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{FCE862BF-90FA-4DC9-A812-0B000D0D634A}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{5C69C930-BAA4-4DB0-B30B-E07035408E72}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{F14AE5FA-2B1E-4EB9-93EB-F445AF44BECB}] => (Allow) LPort=8370
FirewallRules: [{13C44F41-75A6-447A-ADF6-B7F6B98F7CFF}] => (Allow) LPort=8370
FirewallRules: [{4500B60D-CC88-4B1E-BBE0-B27359D153F0}] => (Allow) LPort=6955
FirewallRules: [{F43589BF-8DF6-4CA4-B453-8F3B407385F7}] => (Allow) LPort=6955
FirewallRules: [{84E31095-36D5-4322-849F-0F1A7C833480}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{23D82859-8971-4CFF-9526-1B24F71BE361}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Game\League of Legends.exe
FirewallRules: [{AC3FF2D4-D3E1-45BA-A7EA-2B6176CC3D70}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{D2342453-3521-4F50-B734-1E4F64427BD9}] => (Allow) G:\New folder\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\Air\LolClient.exe
FirewallRules: [{E234F535-6A25-4EF1-902E-DB0AF4BA5D73}] => (Allow) LPort=8370
FirewallRules: [{8C7798F0-1F78-48F8-8D1D-515C4A30E6D1}] => (Allow) LPort=8370
FirewallRules: [{63B6F267-A0AE-4802-AAF9-6FF09ADB5728}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D50DC00C-D559-43E0-85AD-334124840C03}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4A2E9AB0-F37E-4B5E-93D8-E466FE2EC10A}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
FirewallRules: [UDP Query User{B4CFDF83-C1D2-4265-8587-F21411D8104F}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
FirewallRules: [{0F59FEF6-A9F5-48B4-9469-49616C57B6B8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0E5BD749-0CD2-40D8-80BD-04C220B29223}] => (Allow) C:\Users\Admin\AppData\Roaming\Nox\bin\Nox.exe
FirewallRules: [{99CDFD57-9267-419E-A10C-564418E74D80}] => (Allow) C:\Program Files\Bignox\BigNoxVM\RTNoxVMHandle.exe
FirewallRules: [{EA2AFF51-4E08-46DD-948A-8A5F81A16DE1}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\lol.exe
FirewallRules: [{DAA23125-8F46-4B31-8F6E-E07B9B4924DB}] => (Allow) C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\Apps\lolVN\lol.exe
FirewallRules: [{65F98BCD-3530-4377-AFCE-67CFB1748C76}] => (Allow) LPort=8393
FirewallRules: [{FFDD1D67-6D0E-41AE-A14A-3E39E8FC9F5A}] => (Allow) LPort=8393
FirewallRules: [{C2EBF44F-95A7-4CBA-9DE2-B107F55C772B}] => (Allow) LPort=8390
FirewallRules: [{F212E5E1-D250-4173-BB3F-3E16BE494183}] => (Allow) LPort=8390
FirewallRules: [{1CB0E89E-C258-4527-A603-C36674261EA6}] => (Allow) LPort=6925
FirewallRules: [{2D5CAB80-079C-4A7C-8CCB-84C04EB575C1}] => (Allow) LPort=6925
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Ricoh PCIe SD/MMC Host Controller
Description: Ricoh PCIe SD/MMC Host Controller
Class Guid: {4d36e96a-e325-11ce-bfc1-08002be10318}
Manufacturer: Ricoh Company
Service: risdpcie
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

==================== Event log errors: =========================
Application errors:
==================
Error: (11/07/2016 08:03:42 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\GarenaTalkWeb.dll".
Dependent Assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (11/07/2016 08:03:40 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\GarenaTalkWeb.dll".
Dependent Assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (11/07/2016 07:08:34 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\GarenaTalkWeb.dll".
Dependent Assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (11/07/2016 07:08:31 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\GarenaTalkWeb.dll".
Dependent Assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (11/07/2016 05:37:17 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)
Error: (11/07/2016 05:37:17 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)
Error: (11/07/2016 05:37:11 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)
Error: (11/07/2016 05:36:53 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)
Error: (11/07/2016 05:36:53 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)
Error: (11/07/2016 05:36:53 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
 (HRESULT : 0x80040210) (0x80040210)

System errors:
=============
Error: (11/08/2016 01:28:11 AM) (Source: DCOM) (EventID: 10010) (User: QTICKET001)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
Error: (11/08/2016 01:26:11 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error
Error: (11/08/2016 01:24:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (11/08/2016 01:23:44 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:56:44 AM on ‎11/‎8/‎2016 was unexpected.
Error: (11/08/2016 12:51:56 AM) (Source: DCOM) (EventID: 10010) (User: QTICKET001)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
Error: (11/08/2016 12:49:56 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error
Error: (11/07/2016 10:49:22 PM) (Source: DCOM) (EventID: 10010) (User: QTICKET001)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
Error: (11/07/2016 10:47:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error
Error: (11/07/2016 07:03:53 PM) (Source: DCOM) (EventID: 10010) (User: QTICKET001)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
Error: (11/07/2016 07:01:53 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error

==================== Memory info ===========================
Processor: Intel® Core™ i5 CPU M 520 @ 2.40GHz
Percentage of memory in use: 25%
Total physical RAM: 7854.09 MB
Available physical RAM: 5827.81 MB
Total Virtual: 9774.09 MB
Available Virtual: 7838.55 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:102.24 GB) (Free:46.84 GB) NTFS
Drive g: (du lieu) (Fixed) (Total:195.31 GB) (Free:88.06 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=102.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=195.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================


#3 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 09 November 2016 - 02:20 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

You have a very nasty Virut infection
https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Virus:Win32/Virut.gen!AO
http://www.systemlookup.com/Startup/27138.html
---

ATTENTION: System Restore is disabled
Turn System Restore On for Drives in Windows 10
http://www.tenforums.com/tutorials/4533-system-protection-turn-off-drives-windows-10-a.html
===

Remove this program via the Control Panel > Programs > Programs and Features.
C?c C?c (HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\CocCocBrowser) (Version: 52.3.2743.136 - Ðon v? ch? qu?n C?c C?c)

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(Coc Coc Co., Ltd.) C:\Users\Admin\AppData\Local\CocCoc\Update\2.5.15.25\CocCocCrashHandler.exe
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [CocCoc Update] => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [113392 2016-11-07] (Coc Coc Co., Ltd.)
IFEO\taskmgr.exe: [Debugger] "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
CHR Extension: (Thanh toán trên c?a hàng Chrome tr?c tuy?n) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-07]
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
Task: {586C697A-EF35-48E9-8E96-9EEDF4DDD355} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: {BC340245-4A36-4A5A-A152-5E7A2AB10E90} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\Reimage-Post-Reboot.job => C:\ReimageUndo\PostReboot\PostRebootExecuter.exe©false shek C:\Program Files\Reimage\Reimage Repair\Reimage.exe C:\ReimageUndo\PostReboot\post_reboot.htm <==== ATTENTION
Task: C:\WINDOWS\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION
FirewallRules: [TCP Query User{4A2E9AB0-F37E-4B5E-93D8-E466FE2EC10A}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
FirewallRules: [UDP Query User{B4CFDF83-C1D2-4265-8587-F21411D8104F}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
C:\Users\Admin\AppData\Local\CocCoc
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Program Files\Reimage\Reimage Repair
End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Download and Run FlashDisinfector

You may have a flash drive infection. These worms travel through your portable drives. If they have been connected to other machines, they may now be infected.
  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    Note: Some security programs will flag Flash_Disinfector as being some sort of malware, you can safely ignore these warnings
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
===

--RogueKiller--
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or above, right-click the program file and select "Run as Administrator"
  • Accept the user agreements.
  • Execute the scan and wait until it has finished.
  • If a Windows opens to explain what [PUM's] are, read about it.
  • Click the RoguKiller icon on your taksbar to return to the report.
  • Click open the Report
  • Click Export TXT button
  • Save the file as ReportRogue.txt
  • Click the Remove button to delete the items in RED
  • Click Finish and close the program.
  • Locate the ReportRogue.txt file on your Desktop and copy/paste the contents in your next.
=======


Please post the logs and let me know what problem persists with this computer.

p.s.
Now that the trojan has been removed I suggests you change all you passwords.

#4 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 10 November 2016 - 05:56 PM

Here the fixlog

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
Ran by Admin (11-11-2016 05:09:21) Run:1
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin &  (Available Profiles: Admin & Administrator)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
(Coc Coc Co., Ltd.) C:\Users\Admin\AppData\Local\CocCoc\Update\2.5.15.25\CocCocCrashHandler.exe
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\...\Run: [CocCoc Update] => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [113392 2016-11-07] (Coc Coc Co., Ltd.)
IFEO\taskmgr.exe: [Debugger] "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
CHR Extension: (Thanh toán trên c?a hàng Chrome tr?c tuy?n) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-07]
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
Task: {586C697A-EF35-48E9-8E96-9EEDF4DDD355} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: {BC340245-4A36-4A5A-A152-5E7A2AB10E90} - System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe [2016-11-07] (Coc Coc Co., Ltd.)
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA.job => C:\Users\Admin\AppData\Local\CocCoc\Update\CocCocUpdate.exe
Task: C:\WINDOWS\Tasks\Reimage-Post-Reboot.job => C:\ReimageUndo\PostReboot\PostRebootExecuter.exe©false shek C:\Program Files\Reimage\Reimage Repair\Reimage.exe C:\ReimageUndo\PostReboot\post_reboot.htm <==== ATTENTION
Task: C:\WINDOWS\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION
FirewallRules: [TCP Query User{4A2E9AB0-F37E-4B5E-93D8-E466FE2EC10A}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
FirewallRules: [UDP Query User{B4CFDF83-C1D2-4265-8587-F21411D8104F}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe] => (Allow) C:\users\admin\appdata\local\coccoc\browser\application\browser.exe
C:\Users\Admin\AppData\Local\CocCoc
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Program Files\Reimage\Reimage Repair
End
*****************
Error: (0) Failed to create a restore point.
Processes closed successfully.
C:\Users\Admin\AppData\Local\CocCoc\Update\2.5.15.25\CocCocCrashHandler.exe => No running process found
HKU\S-1-5-21-2844419887-631773965-2609765522-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CocCoc Update => value not found.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" => key removed successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}" => key removed successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}" => key removed successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}" => key removed successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}" => key removed successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}" => key removed successfully
"HKU\S-1-5-21-2844419887-631773965-2609765522-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{586C697A-EF35-48E9-8E96-9EEDF4DDD355} => key not found.
C:\WINDOWS\System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC340245-4A36-4A5A-A152-5E7A2AB10E90} => key not found.
C:\WINDOWS\System32\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core => key not found.
C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000Core.job => not found.
C:\WINDOWS\Tasks\CocCocUpdateTaskUserS-1-5-21-2844419887-631773965-2609765522-1000UA.job => not found.
C:\WINDOWS\Tasks\Reimage-Post-Reboot.job => moved successfully
C:\WINDOWS\Tasks\ReimageUpdater.job => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4A2E9AB0-F37E-4B5E-93D8-E466FE2EC10A}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B4CFDF83-C1D2-4265-8587-F21411D8104F}C:\users\admin\appdata\local\coccoc\browser\application\browser.exe => value removed successfully
C:\Users\Admin\AppData\Local\CocCoc => moved successfully
"C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda" => not found.
"C:\Program Files\Reimage\Reimage Repair" => not found.
=========== EmptyTemp: ==========
BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19605002 B
Java, Flash, Steam htmlcache => 3388 B
Windows/system/drivers => 199315 B
Edge => 62093396 B
Chrome => 16507021 B
Firefox => 135113781 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 21558 B
Admin => 612325151 B
Administrator => 0 B
RecycleBin => 0 B
EmptyTemp: => 806.7 MB temporary data Removed.
================================

The system needed a reboot.
==== End of Fixlog 05:10:39 ====

 

When i Double-click Flash_Disinfector.exe I didnt c any scan or the flash didnt work .

​Here the rogue log :

RogueKiller V12.8.0.0 (x64) [Nov  7 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : Admin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 11/11/2016 05:20:54 (Duration : 00:28:34)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 0 ¤¤¤
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032B9SA00 +++++
--- User ---
[MBR] 042ee3f20407bced1739cb5d58b6cd90
[BSP] cd27ed3eb96aab5c994ff939e1f9cca6 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 104694 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 214620160 | Size: 450 MB
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 215541760 | Size: 199998 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


#5 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 11 November 2016 - 09:31 AM

Just to be on the safe side run this cleaning tool.

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zoek tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint;
autoclean;
emptyclsid;
emptyffcache;
FFdefaults;
emptyiecache;
iedefaults;
emptychrcache;
CHRdefaults;
emptyalltemp;
emptyfolderscheck;delete
ipconfig /flushdns;b
Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.
===

Also, please provide an update on how the computer is behaving after running the above script.

#6 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 12 November 2016 - 09:24 AM

here the log :

 


Zoek.exe v5.0.0.1 Updated 19-September-2016
Tool run by Admin on Sat 11/12/2016 at 20:55:52.78.
Microsoft Windows 10 Pro 10.0.14393  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Admin\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
11/12/2016 8:57:56 PM Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\Program Files\Enigma Software Group deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\Users\DefaultAppPool\AppData\LocalLow deleted successfully
C:\Users\Admin\AppData\Local\ActiveSync deleted successfully
C:\Users\Admin\AppData\Local\PeerDistRepub deleted successfully
C:\Users\Admin\AppData\Local\VirtualStore deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully
==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

==== FireFox Fix ======================
Deleted from C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nln44nnt.default\prefs.js:
Added to C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nln44nnt.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Batch Command(s) Run By Tool======================

==== Deleting Files \ Folders ======================
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\Users\Admin\.android deleted
C:\found.000 deleted
C:\Users\Admin\AppData\Local\TempOneClickRoot.exe deleted
C:\Users\Public\Documents\GenieSoft deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
"C:\Users\Admin\AppData\Roaming\CocCoc\hid" deleted
"C:\Users\Admin\AppData\Roaming\CocCoc\uid" deleted
"C:\Users\Admin\AppData\Roaming\CocCoc" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nln44nnt.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\nln44nnt.default
3D1FEE688C03D53129CB8306A8A56FFA - C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll - Garena Talk Plugin

==== Chromium Look ======================
Docs - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
==== Reset Google Chrome ======================
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\nln44nnt.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=44 folders=11 1133279283 bytes)
==== Empty Temp Folders ======================
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Admin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on Sat 11/12/2016 at 21:22:20.31 ======================


#7 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 12 November 2016 - 10:36 AM

How is the computer running now?

#8 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 12 November 2016 - 11:53 AM

still slow , and when i open Edge . its still show problem with process hacker :

aaaaa.png



#9 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 12 November 2016 - 02:00 PM

I do not know anything about the process hacker tool.

b]--RogueKiller--[/b]
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or above, right-click the program file and select "Run as Administrator"
  • Accept the user agreements.
  • Execute the scan and wait until it has finished.
  • If a Windows opens to explain what [PUM's] are, read about it.
  • Click the RoguKiller icon on your taksbar to return to the report.
  • Click open the Report
  • Click Export TXT button
  • Save the file as ReportRogue.txt
  • Click the Remove button to delete the items in RED
  • Click Finish and close the program.
  • Locate the ReportRogue.txt file on your Desktop and copy/paste the contents in your next.
=======

We will check your BIOS and Master boot record.

Read carefully and follow these steps.
TDSS
  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application.
  • Then click on Start Scan.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.

    TDSSKillerSuspicious-1.png
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • Important: Do NOT change the default action on your own unless instructed by a malware Helper! Doing so may render your computer unbootable.
    TDSSKillerMal-1.png
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

    TDSSKillerCompleted.png
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
===

Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it.
aswMBRScan.gif
  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please paste the contents of that log in your next reply.
  • There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
    ===

    Wait for further instructions.


#10 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 12 November 2016 - 05:03 PM

Have a problem with aswMBR , when i double click a windows appear ask me start or not , i click yes and got Blue Screen and auto restart , i try 3 times still again .

 

and here the log of 2 step rouge and tdss :

 

 

RogueKiller V12.8.0.0 (x64) [Nov  7 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : Admin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 11/13/2016 04:13:39 (Duration : 00:32:55)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 103.199.16.62 8.8.8.8 ([Vietnam][-])  -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{83476d9b-e0e6-45a1-b65b-712e26ba1d5d} | DhcpNameServer : 103.199.16.62 8.8.8.8 ([Vietnam][-])  -> Replaced ()
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.NewTab][Firefox:Config] nln44nnt.default : user_pref("browser.newtab.url", "about:newtab"); -> Deleted
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS545032B9SA00 +++++
--- User ---
[MBR] 042ee3f20407bced1739cb5d58b6cd90
[BSP] cd27ed3eb96aab5c994ff939e1f9cca6 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 104694 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 214620160 | Size: 450 MB
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 215541760 | Size: 199998 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
========================================================================
 TDSSKiller report :
04:59:27.0694 0x1494  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
04:59:32.0366 0x1494  ============================================================
04:59:32.0366 0x1494  Current date / time: 2016/11/13 04:59:32.0366
04:59:32.0366 0x1494  SystemInfo:
04:59:32.0366 0x1494 
04:59:32.0366 0x1494  OS Version: 10.0.14393 ServicePack: 0.0
04:59:32.0366 0x1494  Product type: Workstation
04:59:32.0366 0x1494  ComputerName: QTICKET001
04:59:32.0366 0x1494  UserName: Admin
04:59:32.0366 0x1494  Windows directory: C:\WINDOWS
04:59:32.0366 0x1494  System windows directory: C:\WINDOWS
04:59:32.0366 0x1494  Running under WOW64
04:59:32.0366 0x1494  Processor architecture: Intel x64
04:59:32.0366 0x1494  Number of processors: 4
04:59:32.0366 0x1494  Page size: 0x1000
04:59:32.0366 0x1494  Boot type: Normal boot
04:59:32.0366 0x1494  CodeIntegrityOptions = 0x00000001
04:59:32.0366 0x1494  ============================================================
04:59:32.0647 0x1494  KLMD registered as C:\WINDOWS\system32\drivers\91785504.sys
04:59:32.0647 0x1494  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
04:59:34.0600 0x1494  System UUID: {1FD49761-C671-97BF-2043-3F2A6945CAD1}
04:59:36.0647 0x1494  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
04:59:36.0663 0x1494  ============================================================
04:59:36.0663 0x1494  \Device\Harddisk0\DR0:
04:59:36.0663 0x1494  MBR partitions:
04:59:36.0663 0x1494  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
04:59:36.0663 0x1494  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xCC7B000
04:59:36.0663 0x1494  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xCD8E800, BlocksNum 0x1869F000
04:59:36.0663 0x1494  ============================================================
04:59:36.0725 0x1494  C: <-> \Device\Harddisk0\DR0\Partition2
04:59:36.0819 0x1494  G: <-> \Device\Harddisk0\DR0\Partition3
04:59:36.0819 0x1494  ============================================================
04:59:36.0819 0x1494  Initialize success
04:59:36.0819 0x1494  ============================================================
04:59:38.0616 0x19b0  ============================================================
04:59:38.0616 0x19b0  Scan started
04:59:38.0616 0x19b0  Mode: Manual;
04:59:38.0616 0x19b0  ============================================================
04:59:38.0616 0x19b0  KSN ping started
04:59:39.0257 0x19b0  KSN ping finished: true
04:59:47.0617 0x19b0  ================ Scan system memory ========================
04:59:47.0617 0x19b0  System memory - ok
04:59:47.0617 0x19b0  ================ Scan services =============================
04:59:48.0898 0x19b0  1394ohci - ok
04:59:48.0898 0x19b0  3ware - ok
04:59:48.0945 0x19b0  ACPI - ok
04:59:48.0945 0x19b0  AcpiDev - ok
04:59:48.0945 0x19b0  acpiex - ok
04:59:48.0976 0x19b0  acpipagr - ok
04:59:49.0007 0x19b0  AcpiPmi - ok
04:59:49.0007 0x19b0  acpitime - ok
04:59:49.0023 0x19b0  ADP80XX - ok
04:59:49.0054 0x19b0  AFD - ok
04:59:49.0101 0x19b0  ahcache - ok
04:59:49.0132 0x19b0  AJRouter - ok
04:59:49.0163 0x19b0  ALG - ok
04:59:49.0195 0x19b0  AmdK8 - ok
04:59:49.0195 0x19b0  AmdPPM - ok
04:59:49.0210 0x19b0  amdsata - ok
04:59:49.0226 0x19b0  amdsbs - ok
04:59:49.0226 0x19b0  amdxata - ok
04:59:49.0273 0x19b0  AppID - ok
04:59:49.0289 0x19b0  AppIDSvc - ok
04:59:49.0320 0x19b0  Appinfo - ok
04:59:49.0351 0x19b0  applockerfltr - ok
04:59:49.0429 0x19b0  AppMgmt - ok
04:59:49.0445 0x19b0  AppReadiness - ok
04:59:49.0476 0x19b0  AppVClient - ok
04:59:49.0492 0x19b0  AppvStrm - ok
04:59:49.0585 0x19b0  AppvVemgr - ok
04:59:49.0617 0x19b0  AppvVfs - ok
04:59:49.0695 0x19b0  AppXSvc - ok
04:59:49.0695 0x19b0  arcsas - ok
04:59:49.0710 0x19b0  AsyncMac - ok
04:59:49.0757 0x19b0  atapi - ok
04:59:49.0804 0x19b0  athr - ok
04:59:49.0882 0x19b0  AudioEndpointBuilder - ok
04:59:49.0929 0x19b0  Audiosrv - ok
04:59:49.0945 0x19b0  AxInstSV - ok
04:59:49.0960 0x19b0  b06bdrv - ok
04:59:49.0992 0x19b0  BasicDisplay - ok
04:59:49.0992 0x19b0  BasicRender - ok
04:59:50.0007 0x19b0  bcmfn - ok
04:59:50.0007 0x19b0  bcmfn2 - ok
04:59:50.0085 0x19b0  BDESVC - ok
04:59:50.0117 0x19b0  Beep - ok
04:59:50.0163 0x19b0  BFE - ok
04:59:50.0195 0x19b0  BITS - ok
04:59:50.0226 0x19b0  bowser - ok
04:59:50.0242 0x19b0  BrokerInfrastructure - ok
04:59:50.0288 0x19b0  Browser - ok
04:59:50.0335 0x19b0  BthAvrcpTg - ok
04:59:50.0398 0x19b0  BthEnum - ok
04:59:50.0398 0x19b0  BthHFEnum - ok
04:59:50.0429 0x19b0  bthhfhid - ok
04:59:50.0835 0x19b0  BthHFSrv - ok
04:59:50.0976 0x19b0  BTHMODEM - ok
04:59:51.0085 0x19b0  BthPan - ok
04:59:51.0101 0x19b0  BTHPORT - ok
04:59:51.0117 0x19b0  bthserv - ok
04:59:51.0132 0x19b0  BTHUSB - ok
04:59:51.0148 0x19b0  buttonconverter - ok
04:59:51.0148 0x19b0  CapImg - ok
04:59:51.0164 0x19b0  cdfs - ok
04:59:51.0195 0x19b0  CDPSvc - ok
04:59:51.0195 0x19b0  CDPUserSvc - ok
04:59:51.0320 0x19b0  cdrom - ok
04:59:51.0367 0x19b0  CertPropSvc - ok
04:59:51.0476 0x19b0  cht4iscsi - ok
04:59:51.0476 0x19b0  cht4vbd - ok
04:59:51.0523 0x19b0  circlass - ok
04:59:51.0570 0x19b0  CLFS - ok
04:59:51.0601 0x19b0  ClipSVC - ok
04:59:51.0601 0x19b0  clreg - ok
04:59:51.0648 0x19b0  CmBatt - ok
04:59:51.0695 0x19b0  CNG - ok
04:59:51.0695 0x19b0  cnghwassist - ok
04:59:51.0882 0x19b0  CompositeBus - ok
04:59:51.0882 0x19b0  COMSysApp - ok
04:59:51.0914 0x19b0  condrv - ok
04:59:51.0976 0x19b0  CoreMessagingRegistrar - ok
04:59:52.0039 0x19b0  CryptSvc - ok
04:59:52.0054 0x19b0  CSC - ok
04:59:52.0085 0x19b0  CscService - ok
04:59:52.0101 0x19b0  dam - ok
04:59:52.0148 0x19b0  DcomLaunch - ok
04:59:52.0179 0x19b0  DcpSvc - ok
04:59:52.0226 0x19b0  defragsvc - ok
04:59:52.0257 0x19b0  DeviceAssociationService - ok
04:59:52.0273 0x19b0  DeviceInstall - ok
04:59:52.0335 0x19b0  DevQueryBroker - ok
04:59:52.0367 0x19b0  Dfsc - ok
04:59:52.0476 0x19b0  [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus      C:\WINDOWS\system32\DRIVERS\ssudbus.sys
04:59:52.0820 0x19b0  dg_ssudbus - ok
04:59:53.0039 0x19b0  Dhcp - ok
04:59:53.0164 0x19b0  diagnosticshub.standardcollector.service - ok
04:59:53.0195 0x19b0  DiagTrack - ok
04:59:53.0226 0x19b0  disk - ok
04:59:53.0257 0x19b0  DmEnrollmentSvc - ok
04:59:53.0289 0x19b0  dmvsc - ok
04:59:53.0336 0x19b0  dmwappushservice - ok
04:59:53.0351 0x19b0  Dnscache - ok
04:59:53.0367 0x19b0  dot3svc - ok
04:59:53.0398 0x19b0  DPS - ok
04:59:53.0461 0x19b0  drmkaud - ok
04:59:53.0492 0x19b0  DsmSvc - ok
04:59:53.0507 0x19b0  DsSvc - ok
04:59:53.0539 0x19b0  DXGKrnl - ok
04:59:53.0570 0x19b0  EapHost - ok
04:59:53.0586 0x19b0  ebdrv - ok
04:59:53.0632 0x19b0  EFS - ok
04:59:53.0664 0x19b0  EhStorClass - ok
04:59:53.0711 0x19b0  EhStorTcgDrv - ok
04:59:53.0773 0x19b0  embeddedmode - ok
04:59:53.0789 0x19b0  EntAppSvc - ok
04:59:53.0820 0x19b0  ErrDev - ok
04:59:53.0882 0x19b0  EventSystem - ok
04:59:53.0882 0x19b0  exfat - ok
04:59:53.0914 0x19b0  fastfat - ok
04:59:53.0929 0x19b0  fdc - ok
04:59:53.0945 0x19b0  fdPHost - ok
04:59:53.0945 0x19b0  FDResPub - ok
04:59:53.0976 0x19b0  fhsvc - ok
04:59:54.0039 0x19b0  FileCrypt - ok
04:59:54.0054 0x19b0  FileInfo - ok
04:59:54.0070 0x19b0  Filetrace - ok
04:59:54.0070 0x19b0  flpydisk - ok
04:59:54.0086 0x19b0  FltMgr - ok
04:59:54.0101 0x19b0  FontCache - ok
04:59:54.0257 0x19b0  FontCache3.0.0.0 - ok
04:59:54.0273 0x19b0  FrameServer - ok
04:59:54.0289 0x19b0  FsDepends - ok
04:59:54.0304 0x19b0  Fs_Rec - ok
04:59:54.0320 0x19b0  fvevol - ok
04:59:54.0367 0x19b0  gencounter - ok
04:59:54.0382 0x19b0  genericusbfn - ok
04:59:54.0586 0x19b0  [ 4E651936256CC920C8049DA70C2063F5, 21A1BD314716FD456183942A40F22A3C9480A8F0AC0B856D5A087748BEB98CCD ] gkernel         C:\Users\Admin\AppData\Local\Temp\gkernel.sys
04:59:54.0586 0x19b0  gkernel - ok
04:59:54.0632 0x19b0  GPIOClx0101 - ok
04:59:54.0664 0x19b0  gpsvc - ok
04:59:54.0679 0x19b0  GpuEnergyDrv - ok
04:59:54.0851 0x19b0  [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
04:59:54.0851 0x19b0  gupdate - ok
04:59:54.0882 0x19b0  [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
04:59:54.0898 0x19b0  gupdatem - ok
04:59:54.0929 0x19b0  HdAudAddService - ok
04:59:54.0976 0x19b0  HDAudBus - ok
04:59:55.0023 0x19b0  [ B6AC71AAA2B10848F57FC49D55A651AF, 4FAD833654E86F9FAF972AC8AF87FD4A9A765B26B96F096BBD63506B5D521A91 ] HECIx64         C:\WINDOWS\System32\drivers\HECIx64.sys
04:59:55.0039 0x19b0  HECIx64 - ok
04:59:55.0039 0x19b0  HidBatt - ok
04:59:55.0070 0x19b0  HidBth - ok
04:59:55.0086 0x19b0  hidi2c - ok
04:59:55.0086 0x19b0  hidinterrupt - ok
04:59:55.0117 0x19b0  HidIr - ok
04:59:55.0164 0x19b0  hidserv - ok
04:59:55.0195 0x19b0  HidUsb - ok
04:59:55.0226 0x19b0  HomeGroupListener - ok
04:59:55.0242 0x19b0  HomeGroupProvider - ok
04:59:55.0304 0x19b0  HpSAMD - ok
04:59:55.0320 0x19b0  HTTP - ok
04:59:55.0383 0x19b0  HvHost - ok
04:59:55.0414 0x19b0  hvservice - ok
04:59:55.0414 0x19b0  hwpolicy - ok
04:59:55.0461 0x19b0  hyperkbd - ok
04:59:55.0492 0x19b0  i8042prt - ok
04:59:55.0492 0x19b0  iagpio - ok
04:59:55.0507 0x19b0  iai2c - ok
04:59:55.0523 0x19b0  iaLPSS2i_GPIO2 - ok
04:59:55.0523 0x19b0  iaLPSS2i_I2C - ok
04:59:55.0539 0x19b0  iaLPSSi_GPIO - ok
04:59:55.0539 0x19b0  iaLPSSi_I2C - ok
04:59:55.0586 0x19b0  [ D1753C06EE17E29352B065EACF3F10D0, 4DD4C991FAA3CCF99DF8DC9F8F5DEEDEECD55977F0C3AA8C404DEFD21E32A62B ] iaStor          C:\WINDOWS\system32\drivers\iaStor.sys
04:59:55.0601 0x19b0  iaStor - ok
04:59:55.0633 0x19b0  iaStorAV - ok
04:59:55.0633 0x19b0  iaStorV - ok
04:59:55.0648 0x19b0  ibbus - ok
04:59:55.0695 0x19b0  icssvc - ok
04:59:56.0914 0x19b0  [ E6D200304A8D739597678807820ABB43, 05194D2625F48C5065318C28B242A03A1C3BDC441087DAFF777203506CE4CF6E ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
04:59:57.0476 0x19b0  igfx - ok
04:59:57.0523 0x19b0  IKEEXT - ok
04:59:57.0539 0x19b0  IndirectKmd - ok
04:59:57.0586 0x19b0  intelide - ok
04:59:57.0601 0x19b0  intelpep - ok
04:59:57.0617 0x19b0  intelppm - ok
04:59:57.0648 0x19b0  iorate - ok
04:59:57.0648 0x19b0  IpFilterDriver - ok
04:59:57.0695 0x19b0  iphlpsvc - ok
04:59:57.0726 0x19b0  IPMIDRV - ok
04:59:57.0773 0x19b0  IPNAT - ok
04:59:57.0773 0x19b0  irda - ok
04:59:57.0773 0x19b0  IRENUM - ok
04:59:57.0789 0x19b0  irmon - ok
04:59:57.0804 0x19b0  isapnp - ok
04:59:57.0820 0x19b0  iScsiPrt - ok
04:59:57.0883 0x19b0  kbdclass - ok
04:59:57.0898 0x19b0  kbdhid - ok
04:59:57.0961 0x19b0  kdnic - ok
04:59:57.0961 0x19b0  KeyIso - ok
04:59:58.0101 0x19b0  [ 1B5C3C458E31BEDE55145D0644E88D75, 70211A3F90376BBC61F49C22A63075D1D4DDD53F0AEFA976216C46E6BA39A9F4 ] KProcessHacker3 C:\Program Files\Process Hacker 2\kprocesshacker.sys
04:59:58.0117 0x19b0  KProcessHacker3 - ok
04:59:58.0133 0x19b0  KSecDD - ok
04:59:58.0148 0x19b0  KSecPkg - ok
04:59:58.0164 0x19b0  ksthunk - ok
04:59:58.0211 0x19b0  KtmRm - ok
04:59:58.0242 0x19b0  LanmanServer - ok
04:59:58.0258 0x19b0  LanmanWorkstation - ok
04:59:58.0304 0x19b0  lfsvc - ok
04:59:58.0320 0x19b0  LicenseManager - ok
04:59:58.0367 0x19b0  lltdio - ok
04:59:58.0383 0x19b0  lltdsvc - ok
04:59:58.0430 0x19b0  lmhosts - ok
04:59:58.0492 0x19b0  LSI_SAS - ok
04:59:58.0508 0x19b0  LSI_SAS2i - ok
04:59:58.0508 0x19b0  LSI_SAS3i - ok
04:59:58.0523 0x19b0  LSI_SSS - ok
04:59:58.0555 0x19b0  LSM - ok
04:59:58.0555 0x19b0  luafv - ok
04:59:58.0570 0x19b0  MapsBroker - ok
04:59:58.0617 0x19b0  [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector   C:\WINDOWS\system32\drivers\mbam.sys
04:59:58.0633 0x19b0  MBAMProtector - ok
04:59:59.0383 0x19b0  [ 9611577752E293259C7DCE19E9026362, 8CB5DFD63FA15603BB6FA6B501E09ED7F4DE0E8F68CB28B78CECAC3711BEFD24 ] MBAMScheduler   C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
04:59:59.0445 0x19b0  MBAMScheduler - ok
04:59:59.0570 0x19b0  [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
04:59:59.0633 0x19b0  MBAMService - ok
04:59:59.0742 0x19b0  [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy   C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
04:59:59.0758 0x19b0  MBAMSwissArmy - ok
04:59:59.0805 0x19b0  [ 898415AC0B5F1D2A9A48ABCB68A6DC4B, E1FD9AE5E22E3E5A18288E66A6184E92A4B63A1274DCE147A7728BB09C6A225E ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
04:59:59.0805 0x19b0  MBAMWebAccessControl - ok
04:59:59.0851 0x19b0  megasas - ok
04:59:59.0867 0x19b0  megasas2i - ok
04:59:59.0867 0x19b0  megasr - ok
04:59:59.0930 0x19b0  MessagingService - ok
04:59:59.0976 0x19b0  mlx4_bus - ok
05:00:00.0008 0x19b0  MMCSS - ok
05:00:00.0008 0x19b0  Modem - ok
05:00:00.0023 0x19b0  monitor - ok
05:00:00.0039 0x19b0  mouclass - ok
05:00:00.0070 0x19b0  mouhid - ok
05:00:00.0070 0x19b0  mountmgr - ok
05:00:00.0211 0x19b0  [ 572BD5A99648652147A5D3C6DA946C99, FFDAD4A5682864977C926A5DDDB632CDB2A166BF025757801CC56F2828720023 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
05:00:00.0289 0x19b0  MozillaMaintenance - ok
05:00:00.0289 0x19b0  mpsdrv - ok
05:00:00.0351 0x19b0  MpsSvc - ok
05:00:00.0398 0x19b0  MRxDAV - ok
05:00:00.0414 0x19b0  mrxsmb - ok
05:00:00.0430 0x19b0  mrxsmb10 - ok
05:00:00.0430 0x19b0  mrxsmb20 - ok
05:00:00.0461 0x19b0  MsBridge - ok
05:00:00.0476 0x19b0  MSDTC - ok
05:00:00.0492 0x19b0  Msfs - ok
05:00:00.0539 0x19b0  msgpiowin32 - ok
05:00:00.0586 0x19b0  mshidkmdf - ok
05:00:00.0586 0x19b0  mshidumdf - ok
05:00:00.0586 0x19b0  msisadrv - ok
05:00:00.0680 0x19b0  MSiSCSI - ok
05:00:00.0680 0x19b0  msiserver - ok
05:00:00.0726 0x19b0  MSKSSRV - ok
05:00:00.0773 0x19b0  MsLldp - ok
05:00:00.0773 0x19b0  MSPCLOCK - ok
05:00:00.0773 0x19b0  MSPQM - ok
05:00:00.0789 0x19b0  MsRPC - ok
05:00:00.0789 0x19b0  MsSecFlt - ok
05:00:00.0805 0x19b0  mssmbios - ok
05:00:00.0820 0x19b0  MSTEE - ok
05:00:00.0820 0x19b0  MTConfig - ok
05:00:00.0836 0x19b0  Mup - ok
05:00:00.0836 0x19b0  mvumis - ok
05:00:00.0930 0x19b0  NativeWifiP - ok
05:00:00.0961 0x19b0  NcaSvc - ok
05:00:01.0008 0x19b0  NcbService - ok
05:00:01.0039 0x19b0  NcdAutoSetup - ok
05:00:01.0055 0x19b0  ndfltr - ok
05:00:01.0070 0x19b0  NDIS - ok
05:00:01.0102 0x19b0  NdisCap - ok
05:00:01.0133 0x19b0  NdisImPlatform - ok
05:00:01.0164 0x19b0  NdisTapi - ok
05:00:01.0211 0x19b0  Ndisuio - ok
05:00:01.0226 0x19b0  NdisVirtualBus - ok
05:00:01.0242 0x19b0  NdisWan - ok
05:00:01.0242 0x19b0  ndiswanlegacy - ok
05:00:01.0242 0x19b0  ndproxy - ok
05:00:01.0258 0x19b0  Ndu - ok
05:00:01.0289 0x19b0  NetAdapterCx - ok
05:00:01.0289 0x19b0  NetBIOS - ok
05:00:01.0289 0x19b0  NetBT - ok
05:00:01.0305 0x19b0  Netlogon - ok
05:00:01.0336 0x19b0  Netman - ok
05:00:01.0367 0x19b0  netprofm - ok
05:00:01.0414 0x19b0  NetSetupSvc - ok
05:00:01.0477 0x19b0  NetTcpPortSharing - ok
05:00:01.0508 0x19b0  NgcCtnrSvc - ok
05:00:01.0539 0x19b0  NgcSvc - ok
05:00:01.0555 0x19b0  NlaSvc - ok
05:00:01.0586 0x19b0  Npfs - ok
05:00:01.0648 0x19b0  npsvctrig - ok
05:00:01.0680 0x19b0  nsi - ok
05:00:01.0695 0x19b0  nsiproxy - ok
05:00:01.0726 0x19b0  NTFS - ok
05:00:01.0742 0x19b0  Null - ok
05:00:01.0773 0x19b0  nvraid - ok
05:00:01.0805 0x19b0  nvstor - ok
05:00:01.0852 0x19b0  OneSyncSvc - ok
05:00:01.0883 0x19b0  p2pimsvc - ok
05:00:01.0914 0x19b0  p2psvc - ok
05:00:01.0930 0x19b0  Parport - ok
05:00:01.0945 0x19b0  partmgr - ok
05:00:01.0961 0x19b0  PcaSvc - ok
05:00:01.0976 0x19b0  pci - ok
05:00:02.0008 0x19b0  pciide - ok
05:00:02.0023 0x19b0  pcmcia - ok
05:00:02.0023 0x19b0  pcw - ok
05:00:02.0055 0x19b0  pdc - ok
05:00:02.0086 0x19b0  PEAUTH - ok
05:00:02.0101 0x19b0  PeerDistSvc - ok
05:00:02.0117 0x19b0  percsas2i - ok
05:00:02.0117 0x19b0  percsas3i - ok
05:00:02.0430 0x19b0  PerfHost - ok
05:00:02.0476 0x19b0  PhoneSvc - ok
05:00:02.0508 0x19b0  PimIndexMaintenanceSvc - ok
05:00:02.0539 0x19b0  pla - ok
05:00:02.0555 0x19b0  PlugPlay - ok
05:00:02.0602 0x19b0  PNRPAutoReg - ok
05:00:02.0602 0x19b0  PNRPsvc - ok
05:00:02.0617 0x19b0  PolicyAgent - ok
05:00:02.0805 0x19b0  Power - ok
05:00:02.0820 0x19b0  PptpMiniport - ok
05:00:03.0992 0x19b0  [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
05:00:04.0773 0x19b0  PrintNotify - ok
05:00:04.0836 0x19b0  Processor - ok
05:00:04.0867 0x19b0  ProfSvc - ok
05:00:04.0867 0x19b0  Psched - ok
05:00:04.0899 0x19b0  QWAVE - ok
05:00:04.0930 0x19b0  QWAVEdrv - ok
05:00:04.0945 0x19b0  RasAcd - ok
05:00:04.0961 0x19b0  RasAgileVpn - ok
05:00:05.0008 0x19b0  RasAuto - ok
05:00:05.0024 0x19b0  Rasl2tp - ok
05:00:05.0055 0x19b0  RasMan - ok
05:00:05.0070 0x19b0  RasPppoe - ok
05:00:05.0102 0x19b0  RasSstp - ok
05:00:05.0102 0x19b0  rdbss - ok
05:00:05.0133 0x19b0  rdpbus - ok
05:00:05.0133 0x19b0  RDPDR - ok
05:00:05.0227 0x19b0  RdpVideoMiniport - ok
05:00:05.0227 0x19b0  rdyboost - ok
05:00:05.0242 0x19b0  ReFSv1 - ok
05:00:05.0274 0x19b0  RemoteAccess - ok
05:00:05.0289 0x19b0  RemoteRegistry - ok
05:00:05.0367 0x19b0  RetailDemo - ok
05:00:05.0430 0x19b0  RFCOMM - ok
05:00:05.0461 0x19b0  [ 46F03C73DC3ABC0C2FD4A2000CA5AE04, ABF5B1046A958F5F67A0173F0926441EBAC3731008145E683C6E49E93B539B9E ] rimspci         C:\WINDOWS\System32\drivers\rimspe64.sys
05:00:05.0477 0x19b0  rimspci - ok
05:00:05.0492 0x19b0  [ C4581F04AA130892555B821F1FBAA151, 8D517EE442A331AFE768A23067AAFE1491F94F66A58C5184823DF1CEB8DC53A0 ] risdpcie        C:\WINDOWS\System32\drivers\risdpe64.sys
05:00:05.0508 0x19b0  risdpcie - ok
05:00:05.0508 0x19b0  RmSvc - ok
05:00:05.0539 0x19b0  RpcEptMapper - ok
05:00:05.0570 0x19b0  RpcLocator - ok
05:00:05.0602 0x19b0  RpcSs - ok
05:00:05.0617 0x19b0  rspndr - ok
05:00:05.0664 0x19b0  s3cap - ok
05:00:05.0664 0x19b0  SamSs - ok
05:00:05.0727 0x19b0  sbp2port - ok
05:00:05.0758 0x19b0  SCardSvr - ok
05:00:05.0805 0x19b0  ScDeviceEnum - ok
05:00:05.0820 0x19b0  scfilter - ok
05:00:05.0836 0x19b0  Schedule - ok
05:00:05.0852 0x19b0  scmbus - ok
05:00:05.0852 0x19b0  scmdisk0101 - ok
05:00:05.0867 0x19b0  SCPolicySvc - ok
05:00:05.0930 0x19b0  sdbus - ok
05:00:05.0945 0x19b0  SDRSVC - ok
05:00:05.0992 0x19b0  sdstor - ok
05:00:05.0992 0x19b0  seclogon - ok
05:00:06.0086 0x19b0  SENS - ok
05:00:06.0149 0x19b0  Sense - ok
05:00:06.0180 0x19b0  SensorDataService - ok
05:00:06.0195 0x19b0  SensorService - ok
05:00:06.0227 0x19b0  SensrSvc - ok
05:00:06.0242 0x19b0  SerCx - ok
05:00:06.0258 0x19b0  SerCx2 - ok
05:00:06.0289 0x19b0  Serenum - ok
05:00:06.0305 0x19b0  Serial - ok
05:00:06.0320 0x19b0  sermouse - ok
05:00:06.0383 0x19b0  SessionEnv - ok
05:00:06.0399 0x19b0  sfloppy - ok
05:00:06.0477 0x19b0  SharedAccess - ok
05:00:06.0570 0x19b0  ShellHWDetection - ok
05:00:06.0602 0x19b0  shpamsvc - ok
05:00:06.0617 0x19b0  SiSRaid2 - ok
05:00:06.0633 0x19b0  SiSRaid4 - ok
05:00:06.0695 0x19b0  smphost - ok
05:00:06.0758 0x19b0  SmsRouter - ok
05:00:06.0789 0x19b0  SNMPTRAP - ok
05:00:06.0883 0x19b0  spaceport - ok
05:00:06.0914 0x19b0  SpbCx - ok
05:00:06.0945 0x19b0  Spooler - ok
05:00:06.0961 0x19b0  sppsvc - ok
05:00:06.0992 0x19b0  srv - ok
05:00:07.0055 0x19b0  srv2 - ok
05:00:07.0055 0x19b0  srvnet - ok
05:00:07.0071 0x19b0  SSDPSRV - ok
05:00:07.0086 0x19b0  SstpSvc - ok
05:00:07.0164 0x19b0  [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm         C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
05:00:07.0195 0x19b0  ssudmdm - ok
05:00:07.0227 0x19b0  StateRepository - ok
05:00:07.0274 0x19b0  stexstor - ok
05:00:07.0289 0x19b0  stisvc - ok
05:00:07.0321 0x19b0  storahci - ok
05:00:07.0336 0x19b0  storflt - ok
05:00:07.0336 0x19b0  stornvme - ok
05:00:07.0352 0x19b0  storqosflt - ok
05:00:07.0352 0x19b0  StorSvc - ok
05:00:07.0367 0x19b0  storufs - ok
05:00:07.0446 0x19b0  storvsc - ok
05:00:07.0477 0x19b0  svsvc - ok
05:00:07.0508 0x19b0  swenum - ok
05:00:07.0508 0x19b0  swprv - ok
05:00:07.0555 0x19b0  Synth3dVsc - ok
05:00:07.0586 0x19b0  SysMain - ok
05:00:07.0617 0x19b0  SystemEventsBroker - ok
05:00:07.0633 0x19b0  TabletInputService - ok
05:00:07.0633 0x19b0  TapiSrv - ok
05:00:07.0649 0x19b0  Tcpip - ok
05:00:07.0664 0x19b0  Tcpip6 - ok
05:00:07.0696 0x19b0  tcpipreg - ok
05:00:07.0727 0x19b0  tdx - ok
05:00:07.0727 0x19b0  terminpt - ok
05:00:07.0774 0x19b0  TermService - ok
05:00:07.0805 0x19b0  Themes - ok
05:00:07.0852 0x19b0  TieringEngineService - ok
05:00:07.0883 0x19b0  tiledatamodelsvc - ok
05:00:07.0899 0x19b0  TimeBrokerSvc - ok
05:00:07.0930 0x19b0  TPM - ok
05:00:07.0946 0x19b0  TrkWks - ok
05:00:07.0992 0x19b0  TrustedInstaller - ok
05:00:08.0024 0x19b0  tsusbflt - ok
05:00:08.0055 0x19b0  TsUsbGD - ok
05:00:08.0055 0x19b0  tsusbhub - ok
05:00:08.0086 0x19b0  tunnel - ok
05:00:08.0102 0x19b0  tzautoupdate - ok
05:00:08.0117 0x19b0  UASPStor - ok
05:00:08.0133 0x19b0  UcmCx0101 - ok
05:00:08.0149 0x19b0  UcmTcpciCx0101 - ok
05:00:08.0164 0x19b0  UcmUcsi - ok
05:00:08.0196 0x19b0  Ucx01000 - ok
05:00:08.0196 0x19b0  UdeCx - ok
05:00:08.0211 0x19b0  udfs - ok
05:00:08.0227 0x19b0  UEFI - ok
05:00:08.0227 0x19b0  UevAgentDriver - ok
05:00:08.0258 0x19b0  UevAgentService - ok
05:00:08.0274 0x19b0  Ufx01000 - ok
05:00:08.0289 0x19b0  UfxChipidea - ok
05:00:08.0289 0x19b0  ufxsynopsys - ok
05:00:08.0367 0x19b0  UI0Detect - ok
05:00:08.0399 0x19b0  umbus - ok
05:00:08.0414 0x19b0  UmPass - ok
05:00:08.0446 0x19b0  UmRdpService - ok
05:00:08.0446 0x19b0  UnistoreSvc - ok
05:00:08.0477 0x19b0  upnphost - ok
05:00:08.0508 0x19b0  UrsChipidea - ok
05:00:08.0508 0x19b0  UrsCx01000 - ok
05:00:08.0524 0x19b0  UrsSynopsys - ok
05:00:08.0539 0x19b0  usbccgp - ok
05:00:08.0586 0x19b0  usbcir - ok
05:00:08.0617 0x19b0  usbehci - ok
05:00:08.0617 0x19b0  usbhub - ok
05:00:08.0633 0x19b0  USBHUB3 - ok
05:00:08.0649 0x19b0  usbohci - ok
05:00:08.0680 0x19b0  usbprint - ok
05:00:08.0696 0x19b0  usbser - ok
05:00:08.0727 0x19b0  USBSTOR - ok
05:00:08.0727 0x19b0  usbuhci - ok
05:00:08.0758 0x19b0  usbvideo - ok
05:00:08.0774 0x19b0  USBXHCI - ok
05:00:08.0821 0x19b0  UserDataSvc - ok
05:00:08.0899 0x19b0  UserManager - ok
05:00:08.0930 0x19b0  UsoSvc - ok
05:00:08.0930 0x19b0  VaultSvc - ok
05:00:08.0992 0x19b0  [ 29ECC8E4F4B9281C7880B6DD83048202, 8CBE530D197D5A169168178A82967A916004BD5D53FDB902478F92C11EA269CE ] VBoxUSBMon      C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
05:00:09.0024 0x19b0  VBoxUSBMon - ok
05:00:09.0039 0x19b0  vdrvroot - ok
05:00:09.0055 0x19b0  vds - ok
05:00:09.0055 0x19b0  VerifierExt - ok
05:00:09.0086 0x19b0  vhdmp - ok
05:00:09.0086 0x19b0  vhf - ok
05:00:09.0133 0x19b0  vmbus - ok
05:00:09.0133 0x19b0  VMBusHID - ok
05:00:09.0164 0x19b0  vmgid - ok
05:00:09.0196 0x19b0  vmicguestinterface - ok
05:00:09.0196 0x19b0  vmicheartbeat - ok
05:00:09.0196 0x19b0  vmickvpexchange - ok
05:00:09.0211 0x19b0  vmicrdv - ok
05:00:09.0211 0x19b0  vmicshutdown - ok
05:00:09.0211 0x19b0  vmictimesync - ok
05:00:09.0227 0x19b0  vmicvmsession - ok
05:00:09.0227 0x19b0  vmicvss - ok
05:00:09.0258 0x19b0  volmgr - ok
05:00:09.0258 0x19b0  volmgrx - ok
05:00:09.0289 0x19b0  volsnap - ok
05:00:09.0321 0x19b0  volume - ok
05:00:09.0352 0x19b0  vpci - ok
05:00:09.0352 0x19b0  vsmraid - ok
05:00:09.0383 0x19b0  VSS - ok
05:00:09.0383 0x19b0  VSTXRAID - ok
05:00:09.0414 0x19b0  vwifibus - ok
05:00:09.0414 0x19b0  vwififlt - ok
05:00:09.0446 0x19b0  vwifimp - ok
05:00:09.0477 0x19b0  W32Time - ok
05:00:09.0492 0x19b0  WacomPen - ok
05:00:09.0555 0x19b0  WalletService - ok
05:00:09.0571 0x19b0  wanarp - ok
05:00:09.0571 0x19b0  wanarpv6 - ok
05:00:09.0602 0x19b0  wbengine - ok
05:00:09.0617 0x19b0  WbioSrvc - ok
05:00:09.0633 0x19b0  wcifs - ok
05:00:09.0649 0x19b0  Wcmsvc - ok
05:00:09.0649 0x19b0  wcncsvc - ok
05:00:09.0680 0x19b0  wcnfs - ok
05:00:09.0680 0x19b0  WdBoot - ok
05:00:09.0696 0x19b0  Wdf01000 - ok
05:00:09.0711 0x19b0  WdFilter - ok
05:00:09.0727 0x19b0  WdiServiceHost - ok
05:00:09.0742 0x19b0  WdiSystemHost - ok
05:00:09.0774 0x19b0  wdiwifi - ok
05:00:09.0774 0x19b0  WdNisDrv - ok
05:00:09.0836 0x19b0  WdNisSvc - ok
05:00:09.0852 0x19b0  WebClient - ok
05:00:09.0852 0x19b0  Wecsvc - ok
05:00:09.0883 0x19b0  WEPHOSTSVC - ok
05:00:09.0899 0x19b0  wercplsupport - ok
05:00:09.0914 0x19b0  WerSvc - ok
05:00:09.0930 0x19b0  WFPLWFS - ok
05:00:09.0946 0x19b0  WiaRpc - ok
05:00:09.0977 0x19b0  WIMMount - ok
05:00:09.0977 0x19b0  WinDefend - ok
05:00:10.0008 0x19b0  WindowsTrustedRT - ok
05:00:10.0008 0x19b0  WindowsTrustedRTProxy - ok
05:00:10.0055 0x19b0  WinHttpAutoProxySvc - ok
05:00:10.0086 0x19b0  WinMad - ok
05:00:10.0289 0x19b0  Winmgmt - ok
05:00:10.0321 0x19b0  WinRM - ok
05:00:10.0383 0x19b0  WINUSB - ok
05:00:10.0383 0x19b0  WinVerbs - ok
05:00:10.0414 0x19b0  wisvc - ok
05:00:10.0446 0x19b0  WlanSvc - ok
05:00:10.0477 0x19b0  wlidsvc - ok
05:00:10.0477 0x19b0  WmiAcpi - ok
05:00:10.0508 0x19b0  wmiApSrv - ok
05:00:10.0571 0x19b0  WMPNetworkSvc - ok
05:00:10.0602 0x19b0  Wof - ok
05:00:10.0617 0x19b0  WPDBusEnum - ok
05:00:10.0649 0x19b0  WpdUpFltr - ok
05:00:10.0664 0x19b0  WpnService - ok
05:00:10.0696 0x19b0  WpnUserService - ok
05:00:10.0727 0x19b0  ws2ifsl - ok
05:00:10.0727 0x19b0  wscsvc - ok
05:00:10.0742 0x19b0  WSearch - ok
05:00:10.0774 0x19b0  wuauserv - ok
05:00:10.0961 0x19b0  WudfPf - ok
05:00:10.0961 0x19b0  WUDFRd - ok
05:00:11.0008 0x19b0  wudfsvc - ok
05:00:11.0039 0x19b0  WUDFWpdMtp - ok
05:00:11.0055 0x19b0  WwanSvc - ok
05:00:11.0086 0x19b0  XblAuthManager - ok
05:00:11.0149 0x19b0  XblGameSave - ok
05:00:11.0180 0x19b0  xboxgip - ok
05:00:11.0227 0x19b0  XboxNetApiSvc - ok
05:00:11.0258 0x19b0  xinputhid - ok
05:00:11.0367 0x19b0  [ 0A19F25D89670A271752308C28F45A96, CB5455814440BC95166DB51974076B0D4F28875DC41DD5E4B4E2FB92D8F627FA ] XQHDrv          C:\WINDOWS\system32\DRIVERS\XQHDrv.sys
05:00:11.0399 0x19b0  XQHDrv - ok
05:00:11.0446 0x19b0  ykinw8 - ok
05:00:11.0446 0x19b0  ================ Scan global ===============================
05:00:11.0586 0x19b0  [ Global ] - ok
05:00:11.0586 0x19b0  ================ Scan MBR ==================================
05:00:11.0618 0x19b0  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
05:00:12.0899 0x19b0  \Device\Harddisk0\DR0 - ok
05:00:12.0899 0x19b0  ================ Scan VBR ==================================
05:00:12.0930 0x19b0  [ 5ECC00D9B17AD06F42B14C84D992D50B ] \Device\Harddisk0\DR0\Partition1
05:00:12.0961 0x19b0  \Device\Harddisk0\DR0\Partition1 - ok
05:00:12.0977 0x19b0  [ D8F6252EC57819372943FA09D7368929 ] \Device\Harddisk0\DR0\Partition2
05:00:12.0993 0x19b0  \Device\Harddisk0\DR0\Partition2 - ok
05:00:13.0024 0x19b0  [ 70796721B0FEA4E65CD1172EB795675F ] \Device\Harddisk0\DR0\Partition3
05:00:13.0039 0x19b0  \Device\Harddisk0\DR0\Partition3 - ok
05:00:13.0039 0x19b0  ================ Scan generic autorun ======================
05:00:13.0055 0x19b0  [ 6A59AE2735639095CD93E58B0893914C, A1BFC257313185BD4BE63275C1B58877151C31DE3173EADE685199E9D28A23D9 ] C:\WINDOWS\system32\igfxtray.exe
05:00:16.0243 0x19b0  IgfxTray - ok
05:00:16.0321 0x19b0  [ 4341A0AE66759EDC080D92DAA0D9B341, A17D7A56627ECBE7D23E634A9E726BA2E3682A7EB75659AE68A426FF2954C717 ] C:\WINDOWS\system32\hkcmd.exe
05:00:16.0352 0x19b0  HotKeysCmds - ok
05:00:16.0399 0x19b0  [ 5451A9DA41DA19CDD467616492D4096F, 54CBA128702FFF112AE8BA4B187D00CC3ABAB68D3EB1B915193E50523D4DA73F ] C:\WINDOWS\system32\igfxpers.exe
05:00:16.0446 0x19b0  Persistence - ok
05:00:16.0446 0x19b0  WindowsDefender - ok
05:00:17.0274 0x19b0  OneDriveSetup - ok
05:00:17.0274 0x19b0  OneDriveSetup - ok
05:00:17.0649 0x19b0  [ 1D7DD340E13DF9585EABB849CFC3E11B, 31CCD9753402DC030C641214B4ECB48A757BCD9F427A143A88745C62EFF87766 ] C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
05:00:17.0680 0x19b0  OneDrive - ok
05:00:19.0008 0x19b0  [ 3D1032DF6328423B497C1A8DE6BF4955, AC1794285FBFC420ED6FE13FB110811AA1C4ABA2837676945281BC654B64E14A ] C:\Users\Admin\Downloads\LienMinhHuyenThoai\GameData\GarenaMessenger.exe
05:00:19.0633 0x19b0  GarenaPlus - ok
05:00:19.0821 0x19b0  [ B365AF317AE730A67C936F21432B9C71, BD2C2CF0631D881ED382817AFCCE2B093F4E412FFB170A719E2762F250ABFEA4 ] C:\Program Files\Process Hacker 2\ProcessHacker.exe
05:00:19.0993 0x19b0  Process Hacker 2 - ok
05:00:20.0087 0x19b0  [ 735439CF5E6FD89BF9C6209D0786884C, 3971821104AA2D5F947373A1D2FB7D7D5AFB2789A2A1CC6A4FF69302EFCDCD49 ] C:\Program Files\UniKey\UniKeyNT.exe
05:00:20.0102 0x19b0  UniKey - ok
05:00:20.0102 0x19b0  OneDriveSetup - ok
05:00:20.0149 0x19b0  WAB Migrate - ok
05:00:20.0149 0x19b0  Waiting for KSN requests completion. In queue: 7
05:00:21.0337 0x19b0  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
05:00:21.0446 0x19b0  Win FW state via NFP2: enabled ( trusted )
05:00:22.0087 0x19b0  ============================================================
05:00:22.0087 0x19b0  Scan finished
05:00:22.0087 0x19b0  ============================================================
05:00:22.0102 0x19a0  Detected object count: 0
05:00:22.0102 0x19a0  Actual detected object count: 0


#11 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 12 November 2016 - 05:14 PM

the windows appear is :
This computer supports " Virtualization technology" . Would u like to use it for rootkit detection ?
If Yes i got blue screen and restart automaticaly , If no A new window appear :
This application can use the Avast! Free Antivirus for Scanning. It is recommended to download it for better detection results.
Would u like to download latest avast! virus definitions?
I click No and it well done here the log and the MBR.dat
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-11-13 05:04:31
-----------------------------
05:04:31.296    OS Version: Windows x64 6.2.9200
05:04:31.296    Number of processors: 4 586 0x2502
05:04:31.296    ComputerName: QTICKET001  UserName: Admin
05:04:33.889    Initialize success
05:04:33.983    VM: initialized successfully
05:04:33.983    VM: Intel CPU supported
05:04:46.289    VM: not used
05:05:02.755    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
05:05:02.755    Disk 0 Vendor: Hitachi_ PB3O Size: 305245MB BusType: 3
05:05:02.880    Disk 0 MBR read successfully
05:05:02.896    Disk 0 MBR scan
05:05:02.896    Disk 0 Windows 7 default MBR code
05:05:02.927    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
05:05:02.942    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       104694 MB offset 206848
05:05:02.958    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS          450 MB offset 214620160
05:05:02.974    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       199998 MB offset 215541760
05:05:03.192    Disk 0 scanning C:\WINDOWS\system32\drivers
05:05:19.490    Service scanning
05:05:33.631    Modules scanning
05:05:33.647    Disk 0 trace - called modules:
05:05:33.662    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
05:05:33.678    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffff890c1a8c1060]
05:05:33.678    3 CLASSPNP.SYS[fffff80092d35efb] -> nt!IofCallDriver -> [0xffff890c183afbd0]
05:05:33.678    5 ACPI.sys[fffff80091c94571] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xffff890c16c82050]
05:05:33.694    Disk 0 statistics 10790/0/0 @ 0.53 MB/s
05:05:33.694    Scan finished successfully
05:07:04.622    Disk 0 MBR has been saved successfully to "C:\Users\Admin\Desktop\MBR.dat"
05:07:04.653    The log file has been saved successfully to "C:\Users\Admin\Desktop\aswMBR.txt"

Attached Files

  • Attached File  MBR.zip   560bytes   0 downloads


#12 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 13 November 2016 - 09:59 AM

Windows Defender is good but I would like you to Install the Free Avast security software.

Download and install from this site.
https://www.avast.com/index

Run the application when installed.

Let me know if the problem persists.

#13 Evil13TM

Evil13TM
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  

Posted 14 November 2016 - 01:21 PM

i got Blue screen Error and automaticaly restart when it was installing avast . Then the computer staring again slow slow slowly , took me more than 10 mins to finish starting windows . Im pretty sure about what i will do . i will Format my harddrive and remake all partitions , then install the new windows 10 . i thinks i am wasting ur time :( but that way may be faster , any way i need u give me some advice or what should i do . Thanks 4 all u guy , i love bleepingcomputer , and nasdaq is the best supporter i got .


Edited by Evil13TM, 14 November 2016 - 01:21 PM.


#14 nasdaq

nasdaq

  • Malware Response Team
  • 40,246 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:44 PM

Posted 15 November 2016 - 09:43 AM

Good luck. I Hope it's not some hardware problems causing these BSOD.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users