Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with adware, Pop-up sites in google chrome


  • This topic is locked This topic is locked
4 replies to this topic

#1 --Felix--

--Felix--

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:13 AM

Posted 22 December 2016 - 09:47 AM

So, I don't use any kind of anti-malware, anti-virus program and only untrusted programs I run are game cheat engines. I usually run them in VM extract DLL file or just use them from there. I was using cheat which install adware which install mail.run and stuff I was successfully able to remove it everytime from VM. For some reason it's updated version didn't work in VM so I decided to run it on my machine (dumb me). Now I removed all stuff using adware cleaner, registry cleanup. But still something in my machine keeps opening web pages. There are no suspicious processes, services running. No net usage, no detection of any kind of malware, adware by - adware cleaner, quickheal, hitman pro, malwarebytes, rfkill. No luck with anything I usually remove stuff myself, I don't like interruptions of antiviruses. 

 

So, about cheat- it's injection method is to replace d3dref9.dll. I removed this dll and reinstalled directx with no luck. sfc /scannow didn't show any results either. There are no extension or plugins enabled in chrome. This adware really got on my nerve I checked every damm thing. I uploaded and check every suspicious file on virustotal with no luck either. Bought quickheal but it didn't find any suspicious files.

 

If you need any logs or info just ask I will respond as quickly as possible.

 

Just need to add I did boot time scan with quickheal, running security software in safe mode etc. I was gonna reinstall windows but I know what that bleep is.

 
 
FRST LOG:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by win7 (administrator) on WIN7-PC (22-12-2016 20:57:22)
Running from C:\Users\win7\Downloads
Loaded Profiles: win7 (Available Profiles: win7)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-06-15] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [112200 2016-10-21] (VMware, Inc.)
HKU\S-1-5-21-264572023-2887433556-1976621555-1000\...\MountPoints2: {7ec0bbcb-bd12-11e6-b442-806e6f6e6963} - F:\setup.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{749C914A-8505-487B-BD96-21F5BAC0AD4C}: [DhcpNameServer] 192.168.138.1
Tcpip\..\Interfaces\{CBE1B60D-8387-41FE-A918-AC27F1F7A0D3}: [DhcpNameServer] 192.168.174.2
Tcpip\..\Interfaces\{F0C1F6CA-8A30-484E-932B-7EFDAD6492A7}: [DhcpNameServer] 10.0.0.1

Internet Explorer:
==================
HKU\S-1-5-21-264572023-2887433556-1976621555-1000\Software\Microsoft\Internet Explorer\Main,Start Page = 
SearchScopes: HKU\S-1-5-21-264572023-2887433556-1976621555-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 

FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-22] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)

Chrome: 
=======
CHR Profile: C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default [2016-12-22]
CHR Extension: (Google Slides) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-21]
CHR Extension: (Google Docs) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-21]
CHR Extension: (Google Sheets) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-21]
CHR Extension: (Google Docs Offline) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-21]
CHR Extension: (Chrome Media Router) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-07] ()
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [395024 2016-12-07] (EasyAntiCheat Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-10-22] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-06-15] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-06-15] (NVIDIA Corporation)
S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12472904 2016-10-21] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-09-18] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
S3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [496400 2013-02-27] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-06-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R1 vmkbd3; C:\Windows\System32\DRIVERS\vmkbd.sys [52288 2016-10-21] (VMware, Inc.)
R0 vsock; C:\Windows\System32\DRIVERS\vsock.sys [93248 2016-09-30] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [34520 2015-07-09] (VMware, Inc.)
S4 EasyAntiCheatSys; \??\C:\Windows\system32\drivers\EasyAntiCheat.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-12-22 20:56 - 2016-12-22 20:57 - 02420736 _____ (Farbar) C:\Users\win7\Downloads\FRST64.exe
2016-12-22 05:02 - 2016-12-22 05:02 - 00001401 _____ C:\Users\win7\Desktop\GeForce Experience.lnk
2016-12-21 20:18 - 2016-12-21 20:37 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-21 20:18 - 2016-12-21 20:37 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-21 20:17 - 2016-12-21 20:23 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-21 20:17 - 2016-12-21 20:23 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-21 19:58 - 2016-12-21 19:59 - 00000000 ___SD C:\ComboFix
2016-12-21 19:18 - 2011-06-26 12:15 - 00256000 _____ C:\Windows\PEV.exe
2016-12-21 19:18 - 2010-11-07 22:50 - 00208896 _____ C:\Windows\MBR.exe
2016-12-21 19:18 - 2009-04-20 10:26 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-12-21 19:18 - 2000-08-31 05:30 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-12-21 19:18 - 2000-08-31 05:30 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-12-21 19:18 - 2000-08-31 05:30 - 00098816 _____ C:\Windows\sed.exe
2016-12-21 19:18 - 2000-08-31 05:30 - 00080412 _____ C:\Windows\grep.exe
2016-12-21 19:18 - 2000-08-31 05:30 - 00068096 _____ C:\Windows\zip.exe
2016-12-21 19:17 - 2016-12-21 19:18 - 00000000 ____D C:\Qoobox
2016-12-21 19:16 - 2016-12-21 19:16 - 05659917 ____R (Swearware) C:\Users\win7\Downloads\ComboFix.exe
2016-12-21 19:16 - 2016-12-21 19:16 - 00000000 ____D C:\Windows\erdnt
2016-12-21 19:13 - 2016-12-21 19:13 - 00000000 ____D C:\cfrbackup-XXSNBWEH
2016-12-21 18:01 - 2016-12-21 18:01 - 00571288 _____ (Quick Heal Technologies Pvt. Ltd.) C:\Users\win7\Downloads\PCT.EXE
2016-12-21 17:33 - 2016-12-21 17:34 - 00498184 _____ (Quick Heal Technologies Pvt. Ltd.) C:\Users\win7\Downloads\QHTSFT.EXE
2016-12-19 19:17 - 2016-12-22 20:57 - 00009050 _____ C:\Users\win7\Downloads\FRST.txt
2016-12-19 19:17 - 2016-12-19 19:18 - 00022472 _____ C:\Users\win7\Downloads\Addition.txt
2016-12-19 19:16 - 2016-12-19 19:17 - 00000000 ____D C:\FRST
2016-12-19 19:14 - 2016-12-19 19:15 - 02420224 _____ (Farbar) C:\Users\win7\Desktop\FRST64.exe
2016-12-19 11:16 - 2016-12-19 11:16 - 00039180 _____ C:\Users\win7\Downloads\Hot Chicks Big Fangs 2 - Digital Playground 2015 WEB-DL SPLIT SCENES MP4-RARBG-[rarbg.to].torrent
2016-12-19 09:21 - 2016-12-19 09:21 - 00003288 ____N C:\bootsqm.dat
2016-12-17 20:09 - 2016-12-17 20:09 - 00001521 _____ C:\Users\win7\Downloads\MicRooCerAut2011_2011_03_22.crt
2016-12-16 21:15 - 2016-12-16 21:29 - 00000000 ____D C:\ProgramData\HitmanPro
2016-12-16 21:11 - 2016-12-16 21:14 - 11581544 _____ (SurfRight B.V.) C:\Users\win7\Downloads\HitmanPro_x64.exe
2016-12-16 17:50 - 2016-12-17 23:42 - 00000000 ____D C:\Users\win7\AppData\Roaming\VMware
2016-12-16 17:50 - 2016-12-17 23:42 - 00000000 ____D C:\Users\win7\AppData\Local\VMware
2016-12-16 17:49 - 2016-10-21 07:47 - 00366664 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2016-12-16 17:49 - 2016-10-21 07:46 - 00400968 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2016-12-16 17:49 - 2016-10-21 07:39 - 00088128 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2016-12-16 17:49 - 2016-10-21 07:39 - 00052288 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmkbd.sys
2016-12-16 17:49 - 2016-10-21 07:22 - 00066624 _____ (VMware, Inc.) C:\Windows\system32\vnetinst.dll
2016-12-16 17:49 - 2016-10-21 07:22 - 00045632 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnet.sys
2016-12-16 17:49 - 2016-10-21 07:22 - 00044096 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
2016-12-16 17:49 - 2016-09-30 01:11 - 00093248 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2016-12-16 17:49 - 2016-09-30 01:11 - 00069104 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2016-12-16 17:49 - 2016-09-30 01:11 - 00065008 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2016-12-16 17:48 - 2016-12-22 04:52 - 00000000 ____D C:\ProgramData\VMware
2016-12-16 17:48 - 2016-12-16 17:48 - 00001203 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
2016-12-16 17:48 - 2016-12-16 17:48 - 00001024 _____ C:\Windows\SysWOW64\%TMP%
2016-12-16 17:48 - 2016-12-16 17:48 - 00000000 ____D C:\Users\Public\Documents\Shared Virtual Machines
2016-12-16 17:48 - 2016-12-16 17:48 - 00000000 ____D C:\Program Files\Common Files\VMware
2016-12-16 17:48 - 2016-12-16 17:48 - 00000000 ____D C:\Program Files (x86)\VMware
2016-12-16 17:48 - 2016-10-21 07:47 - 01148488 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2016-12-16 17:48 - 2016-09-06 18:48 - 00083008 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
2016-12-15 23:36 - 2016-04-14 11:08 - 00102976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-12-15 23:36 - 2016-04-14 11:08 - 00056384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-12-15 21:03 - 2016-12-15 21:03 - 00001377 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2016-12-15 20:59 - 2016-12-15 21:03 - 00000000 ____D C:\Users\win7\AppData\Local\NVIDIA
2016-12-15 20:59 - 2016-04-14 11:08 - 00113216 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-12-15 20:59 - 2016-02-17 12:10 - 01903344 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2016-12-15 20:59 - 2016-02-17 12:10 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-12-15 20:59 - 2016-02-17 12:10 - 01571624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-12-15 20:59 - 2016-02-17 12:10 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-12-15 20:59 - 2016-02-17 12:10 - 00112216 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-15 20:49 - 2016-12-15 20:56 - 43115896 _____ (NVIDIA Corporation) C:\Users\win7\Downloads\GeForce_Experience_v2.10.2.40.exe
2016-12-13 19:15 - 2016-12-13 19:27 - 00003624 _____ C:\Windows\System32\Tasks\InternetDB
2016-12-11 19:29 - 2016-12-11 19:29 - 00015028 _____ C:\Users\win7\Downloads\[otorrents.com]Dishonored-2012.torrent
2016-12-11 19:23 - 2016-12-11 19:23 - 00161929 _____ C:\Users\win7\Downloads\Call.of.Duty.Infinite.Warfare-RELOADED-[rarbg.com].torrent
2016-12-11 19:20 - 2016-12-11 19:20 - 00151709 _____ C:\Users\win7\Downloads\[otorrents.com]Battlefield-Hardline-2015.torrent
2016-12-11 19:18 - 2016-12-11 19:18 - 00023017 _____ C:\Users\win7\Downloads\[otorrents.com]The-Raid-2-2014-720p.torrent
2016-12-11 19:16 - 2016-12-11 19:16 - 00035729 _____ C:\Users\win7\Downloads\[otorrents.com]Captain-Fantastic-2016-720p.torrent
2016-12-11 19:16 - 2016-12-11 19:16 - 00000000 ____D C:\Users\win7\Downloads\Captain Fantastic (2016) [YTS.AG]
2016-12-11 19:14 - 2016-12-11 19:14 - 00028959 _____ C:\Users\win7\Downloads\[otorrents.com]Finding-Dory-2016-720p.torrent
2016-12-11 19:14 - 2016-12-11 19:14 - 00000000 ____D C:\Users\win7\Downloads\Finding Dory (2016) [YTS.AG]
2016-12-11 19:13 - 2016-12-11 19:13 - 00038019 _____ C:\Users\win7\Downloads\Jason Bourne (2016) [720p] [YTS.AG].torrent
2016-12-11 19:13 - 2016-12-11 19:13 - 00000000 ____D C:\Users\win7\Downloads\Jason Bourne (2016) [YTS.AG]
2016-12-11 16:59 - 2016-12-11 16:59 - 00039642 _____ C:\Users\win7\Downloads\themagnificentseven2016720pblurayx264-ytsag-english-100466.zip
2016-12-11 16:51 - 2016-12-11 16:59 - 00000000 ____D C:\Users\win7\Downloads\The Magnificent Seven (2016) [YTS.AG]
2016-12-11 16:51 - 2016-12-11 16:51 - 00040098 _____ C:\Users\win7\Downloads\The Magnificent Seven (2016) [720p] [YTS.AG].torrent
2016-12-11 13:46 - 2016-12-14 19:03 - 00001017 _____ C:\Users\win7\Desktop\PotPlayer 64 bit.lnk
2016-12-11 13:46 - 2016-12-11 13:46 - 00000000 ____D C:\Users\win7\AppData\Roaming\PotPlayerMini64
2016-12-11 13:46 - 2016-12-11 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2016-12-11 13:46 - 2016-12-11 13:46 - 00000000 ____D C:\Program Files\DAUM
2016-12-11 13:44 - 2016-12-11 13:44 - 00000000 ____D C:\Users\win7\Downloads\Independence Day Resurgence (2016) [YTS.AG]
2016-12-11 13:43 - 2016-12-11 13:43 - 00035889 _____ C:\Users\win7\Downloads\Independence Day- Resurgence (2016) [720p] [YTS.AG].torrent
2016-12-11 13:39 - 2016-12-11 13:42 - 21598808 _____ (Kakao) C:\Users\win7\Downloads\PotPlayerSetup64.exe
2016-12-11 13:29 - 2016-12-11 13:30 - 00000000 ____D C:\Users\win7\Downloads\The Shawshank Redemption (1994)
2016-12-11 13:27 - 2016-12-11 13:27 - 00018043 _____ C:\Users\win7\Downloads\The Shawshank Redemption (1994) [720p] [YTS.AG] (3).torrent
2016-12-11 13:27 - 2016-12-11 13:27 - 00018043 _____ C:\Users\win7\Downloads\The Shawshank Redemption (1994) [720p] [YTS.AG] (2).torrent
2016-12-11 13:23 - 2016-12-11 13:23 - 00000812 _____ C:\Users\win7\Desktop\µTorrent.lnk
2016-12-11 13:23 - 2016-12-11 13:23 - 00000792 _____ C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-12-11 13:20 - 2016-12-21 22:49 - 00000000 ____D C:\Users\win7\AppData\Roaming\uTorrent
2016-12-11 13:14 - 2016-12-11 13:15 - 02422464 _____ (BitTorrent Inc.) C:\Users\win7\Downloads\uTorrent.exe
2016-12-11 13:13 - 2016-12-11 13:13 - 00018043 _____ C:\Users\win7\Downloads\The Shawshank Redemption (1994) [720p] [YTS.AG] (1).torrent
2016-12-11 13:12 - 2016-12-11 13:12 - 00018043 _____ C:\Users\win7\Downloads\The Shawshank Redemption (1994) [720p] [YTS.AG].torrent
2016-12-10 13:13 - 2016-12-10 13:13 - 00000951 _____ C:\Users\win7\Desktop\gflauncher - Shortcut.lnk
2016-12-09 14:41 - 2016-12-13 19:14 - 00000000 ____D C:\Users\win7\Desktop\GoogleChrome
2016-12-09 14:21 - 2016-12-13 16:05 - 00000060 _____ C:\Users\win7\Desktop\Uplay games.txt
2016-12-09 14:12 - 2016-12-09 14:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-12-09 14:09 - 2016-12-09 14:42 - 00003626 _____ C:\Windows\System32\Tasks\InternetCD
2016-12-08 23:11 - 2016-12-08 23:13 - 14572000 _____ (Microsoft Corporation) C:\Users\win7\Downloads\vc_redist.x64.exe
2016-12-08 23:11 - 2016-12-08 23:13 - 13767776 _____ (Microsoft Corporation) C:\Users\win7\Downloads\vc_redist.x86.exe
2016-12-08 23:09 - 2016-12-21 20:16 - 00000000 ____D C:\Users\win7\AppData\LocalLow\Unity
2016-12-08 23:09 - 2016-12-21 20:16 - 00000000 ____D C:\Users\win7\AppData\Local\Unity
2016-12-08 23:04 - 2016-12-08 23:04 - 00003584 _____ C:\Windows\System32\Tasks\InternetCC
2016-12-08 16:30 - 2016-12-14 17:58 - 00002558 _____ C:\Users\win7\Desktop\Rkill.txt
2016-12-08 12:20 - 2016-12-08 12:20 - 00000000 ____D C:\Windows\CSC
2016-12-08 05:50 - 2016-12-21 22:52 - 00007623 _____ C:\Users\win7\AppData\Local\Resmon.ResmonCfg
2016-12-08 04:24 - 2016-12-08 04:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2016-12-08 00:36 - 2016-12-08 00:36 - 00000232 _____ C:\Users\win7\Desktop\Assassin's Creed III.url
2016-12-08 00:34 - 2016-12-08 00:37 - 34990434 _____ C:\Users\win7\Downloads\AC3_THEME.ZIP
2016-12-08 00:24 - 2016-12-16 23:14 - 00000000 ____D C:\Users\win7\AppData\Local\Ubisoft Game Launcher
2016-12-08 00:24 - 2016-12-08 00:45 - 00000000 ____D C:\Users\win7\AppData\Roaming\NVIDIA
2016-12-08 00:24 - 2016-12-08 00:24 - 00001201 _____ C:\Users\win7\Desktop\Uplay.lnk
2016-12-08 00:24 - 2016-12-08 00:24 - 00000000 ____D C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-12-08 00:24 - 2016-12-08 00:24 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2016-12-08 00:20 - 2016-12-08 00:21 - 07194312 _____ (Microsoft Corporation) C:\Users\win7\Downloads\vcredist_x64.exe
2016-12-08 00:20 - 2016-12-08 00:21 - 06503984 _____ (Microsoft Corporation) C:\Users\win7\Downloads\vcredist_x86.exe
2016-12-08 00:14 - 2016-12-15 21:04 - 00000000 ____D C:\Users\win7\AppData\Local\NVIDIA Corporation
2016-12-08 00:14 - 2016-12-08 00:14 - 00000000 ____D C:\Users\win7\AppData\Local\CEF
2016-12-08 00:12 - 2016-12-15 20:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-12-08 00:10 - 2016-12-22 04:52 - 00000000 ____D C:\ProgramData\NVIDIA
2016-12-08 00:10 - 2016-10-22 12:50 - 00215608 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2016-12-08 00:10 - 2016-10-22 12:50 - 00201664 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 06386232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 02475968 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 00548408 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-12-08 00:10 - 2016-10-22 11:34 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2016-12-08 00:10 - 2016-10-22 10:52 - 00133056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-12-08 00:10 - 2016-10-21 12:47 - 07500035 _____ C:\Windows\system32\nvcoproc.bin
2016-12-08 00:09 - 2016-12-15 21:03 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-12-08 00:09 - 2016-12-15 20:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-12-08 00:07 - 2016-10-22 14:10 - 01595456 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2016-12-08 00:07 - 2016-10-22 14:10 - 00212936 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-12-08 00:07 - 2016-10-22 14:10 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 35224120 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 34701368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 28136504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 19917400 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 17426520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 17338976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 14394528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 14017984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-12-08 00:07 - 2016-10-22 12:50 - 10910184 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 10772640 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 10324072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 09112272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 08912488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 08715728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 03930688 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 03627968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 03469408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 03193400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437563.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 01585088 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437563.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 01037368 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00683824 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00573072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00492560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00439864 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-12-08 00:07 - 2016-10-22 12:50 - 00041344 _____ C:\Windows\system32\nvinfo.pb
2016-12-08 00:07 - 2016-10-22 12:50 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-12-08 00:07 - 2016-10-22 12:50 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2016-12-08 00:05 - 2016-12-15 20:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-12-08 00:05 - 2016-12-08 00:05 - 00000000 ____D C:\NVIDIA
2016-12-08 00:04 - 2016-12-08 00:10 - 74516600 _____ (NVIDIA Corporation) C:\Users\win7\Downloads\GeForce_Experience_v3.1.2.31.exe
2016-12-08 00:03 - 2016-12-08 00:03 - 00000000 ____D C:\Users\win7\AppData\Roaming\WinRAR
2016-12-08 00:03 - 2016-12-08 00:03 - 00000000 ____D C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-08 00:03 - 2016-12-08 00:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-08 00:03 - 2016-12-08 00:03 - 00000000 ____D C:\Program Files\WinRAR
2016-12-07 23:46 - 2016-12-14 17:30 - 00000000 ____D C:\AdwCleaner
2016-12-07 23:38 - 2016-12-22 05:13 - 00000000 ____D C:\ProgramData\GFACE
2016-12-07 23:38 - 2016-12-07 23:38 - 00000000 ____D C:\Users\win7\AppData\Local\CrashRpt
2016-12-07 23:38 - 2016-12-07 15:23 - 00395024 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2016-12-07 23:37 - 2016-12-22 20:54 - 00000000 ____D C:\Users\win7\AppData\Local\u-launcher
2016-12-07 23:33 - 2016-12-07 23:43 - 00003616 _____ C:\Windows\System32\Tasks\InternetCB
2016-12-07 23:31 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2016-12-07 23:31 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2016-12-07 23:31 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2016-12-07 23:31 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2016-12-07 23:31 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2016-12-07 23:31 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2016-12-07 23:31 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2016-12-07 23:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2016-12-07 23:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2016-12-07 23:31 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2016-12-07 23:31 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2016-12-07 23:31 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2016-12-07 23:31 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2016-12-07 23:31 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2016-12-07 23:31 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2016-12-07 23:31 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2016-12-07 23:31 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2016-12-07 23:31 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2016-12-07 23:31 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2016-12-07 23:31 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2016-12-07 23:31 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2016-12-07 23:31 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2016-12-07 23:31 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2016-12-07 23:31 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2016-12-07 23:31 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2016-12-07 23:31 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2016-12-07 23:31 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2016-12-07 23:31 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2016-12-07 23:31 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2016-12-07 23:31 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2016-12-07 23:31 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2016-12-07 23:31 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2016-12-07 23:31 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2016-12-07 23:31 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2016-12-07 23:31 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2016-12-07 23:31 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2016-12-07 23:31 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2016-12-07 23:31 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2016-12-07 23:31 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2016-12-07 23:31 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2016-12-07 23:31 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2016-12-07 23:31 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2016-12-07 23:31 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2016-12-07 23:31 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2016-12-07 23:31 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2016-12-07 23:31 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2016-12-07 23:31 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2016-12-07 23:31 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2016-12-07 23:31 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2016-12-07 23:31 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2016-12-07 23:31 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2016-12-07 23:31 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2016-12-07 23:31 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2016-12-07 23:31 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2016-12-07 23:31 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2016-12-07 23:31 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2016-12-07 23:31 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2016-12-07 23:31 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2016-12-07 23:31 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2016-12-07 23:31 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2016-12-07 23:31 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2016-12-07 23:31 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2016-12-07 23:31 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2016-12-07 23:31 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2016-12-07 23:31 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2016-12-07 23:31 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2016-12-07 23:31 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2016-12-07 23:31 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2016-12-07 23:31 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2016-12-07 23:31 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2016-12-07 23:31 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2016-12-07 23:31 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2016-12-07 23:31 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2016-12-07 23:31 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2016-12-07 23:31 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2016-12-07 23:31 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2016-12-07 23:31 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2016-12-07 23:31 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2016-12-07 23:31 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2016-12-07 23:31 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2016-12-07 23:31 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2016-12-07 23:31 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2016-12-07 23:31 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2016-12-07 23:31 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2016-12-07 23:31 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2016-12-07 23:31 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2016-12-07 23:31 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2016-12-07 23:31 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2016-12-07 23:31 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2016-12-07 23:31 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2016-12-07 23:31 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2016-12-07 23:31 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2016-12-07 23:31 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-12-07 23:31 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-12-07 23:31 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-12-07 23:31 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-12-07 23:31 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2016-12-07 23:31 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-12-07 23:31 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2016-12-07 23:31 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-12-07 23:31 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2016-12-07 23:31 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-12-07 23:31 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2016-12-07 23:31 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-12-07 23:31 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2016-12-07 23:31 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-12-07 23:31 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2016-12-07 23:31 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-12-07 23:31 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2016-12-07 23:31 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-12-07 23:31 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2016-12-07 23:31 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-12-07 23:31 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2016-12-07 23:31 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-12-07 23:31 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-12-07 23:30 - 2015-07-18 18:38 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-12-07 23:29 - 2016-12-08 23:17 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-07 23:28 - 2016-12-21 20:18 - 00000000 ____D C:\Program Files (x86)\Google
2016-12-07 23:28 - 2016-12-16 17:48 - 00798048 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-12-07 23:28 - 2016-12-08 00:48 - 00000000 ____D C:\Users\win7\AppData\Local\Google
2016-12-07 23:24 - 2016-12-07 23:24 - 00000000 ____D C:\Program Files (x86)\Realtek
2016-12-07 23:24 - 2016-12-07 23:23 - 00977624 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2016-12-07 23:24 - 2016-12-07 23:23 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2016-12-07 23:24 - 2016-12-07 23:23 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2016-12-07 23:10 - 2016-12-21 18:40 - 00000000 ____D C:\Temp
2016-12-07 23:10 - 2016-12-07 23:10 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf
2016-12-07 23:10 - 2016-12-07 23:10 - 00000000 ____D C:\ProgramData\Intel
2016-12-07 23:10 - 2016-12-07 23:10 - 00000000 ____D C:\Program Files\Intel
2016-12-07 23:10 - 2013-09-16 12:17 - 00016344 _____ (Intel Corporation) C:\Windows\system32\Drivers\IntelMEFWVer.dll
2016-12-07 23:10 - 2013-04-26 07:54 - 00786416 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys
2016-12-07 23:10 - 2013-04-26 07:54 - 00368112 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys
2016-12-07 23:10 - 2013-04-26 07:54 - 00020464 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys
2016-12-07 23:09 - 2016-12-07 23:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-12-07 23:09 - 2016-12-07 23:09 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2016-12-07 23:09 - 2013-09-16 12:17 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2016-12-07 23:09 - 2013-09-16 12:17 - 00099288 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2016-12-07 23:08 - 2016-12-07 23:10 - 00000000 ____D C:\Program Files (x86)\Intel
2016-12-07 23:08 - 2013-08-05 09:20 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2016-12-07 23:07 - 2016-12-07 23:07 - 00000000 ____D C:\Intel
2016-12-07 23:06 - 2016-12-07 23:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_ASMBSW_01_11_00.Wdf
2016-12-07 23:06 - 2016-12-07 23:06 - 00000000 ____D C:\Windows\AsusInstAll
2016-12-07 23:06 - 2016-12-07 23:06 - 00000000 ____D C:\Program Files\ASUS
2016-12-07 23:06 - 2016-12-07 23:06 - 00000000 ____D C:\Program Files (x86)\ASUS
2016-12-07 23:06 - 2012-08-22 15:24 - 00015232 _____ C:\Windows\SysWOW64\Drivers\AsIO.sys
2016-12-07 23:06 - 2012-08-17 08:27 - 02356592 _____ (Microsoft Corporation) C:\Windows\system32\WudfUpdate_01011.dll
2016-12-07 23:06 - 2011-02-25 11:55 - 00296320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2016-12-07 23:06 - 2010-06-29 13:11 - 00028672 _____ (ASUSTek Computer Inc.) C:\Windows\SysWOW64\AsIO.dll
2016-12-07 23:05 - 2016-12-07 23:11 - 00058619 _____ C:\Windows\Ascd_log.ini
2016-12-07 23:05 - 2016-12-07 23:05 - 00000000 _____ C:\Windows\scd.ini
2016-12-07 23:05 - 2016-12-07 23:05 - 00000000 _____ C:\Windows\Ascd_err.ini
2016-12-07 23:04 - 2016-12-07 23:04 - 00041432 _____ C:\Windows\Ascd_tmp.ini
2016-12-07 23:04 - 2016-12-07 23:04 - 00001769 _____ C:\Windows\Language_trs.ini
2016-12-07 23:03 - 2016-12-07 23:03 - 00058016 _____ C:\Users\win7\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-07 22:59 - 2016-12-22 02:40 - 00000000 ____D C:\Users\win7
2016-12-07 22:59 - 2016-12-07 22:59 - 00001413 _____ C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-12-07 22:59 - 2016-12-07 22:59 - 00000020 ___SH C:\Users\win7\ntuser.ini
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 _SHDL C:\Users\win7\My Documents
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 _SHDL C:\Users\win7\Documents\My Videos
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 _SHDL C:\Users\win7\Documents\My Pictures
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 _SHDL C:\Users\win7\Documents\My Music
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 ____D C:\Users\win7\AppData\Roaming\Adobe
2016-12-07 22:59 - 2016-12-07 22:59 - 00000000 ____D C:\Users\win7\AppData\Local\VirtualStore
2016-12-07 22:59 - 2011-04-12 13:58 - 00000000 ____D C:\Users\win7\AppData\Roaming\Media Center Programs
2016-12-07 22:58 - 2013-09-01 17:08 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-12-22 05:52 - 2009-07-14 10:43 - 00785446 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-22 05:52 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\inf
2016-12-22 04:59 - 2009-07-14 10:15 - 00031088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-22 04:59 - 2009-07-14 10:15 - 00031088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-22 04:51 - 2009-07-14 10:38 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-13 02:02 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\system32\NDF
2016-12-09 14:48 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\PLA
2016-12-08 12:28 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\rescache
2016-12-08 12:22 - 2009-07-14 10:15 - 00275712 _____ C:\Windows\system32\FNTCACHE.DAT
2016-12-08 12:19 - 2009-07-14 11:02 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-12-08 00:10 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\Help
2016-12-07 23:10 - 2009-07-14 08:50 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-07 22:59 - 2013-09-24 21:04 - 00000000 ____D C:\Windows\Panther
2016-12-07 22:59 - 2009-07-14 10:15 - 00000000 ____D C:\Windows\Setup

==================== Files in the root of some directories =======

2016-12-08 05:50 - 2016-12-21 22:52 - 0007623 _____ () C:\Users\win7\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\win7\AppData\Local\Temp\_is5BD5.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-12-16 13:19

==================== End of FRST.txt ============================

 

Attached Files



BC AdBot (Login to Remove)

 


#2 mAL_rEm018

mAL_rEm018

  • Malware Response Team
  • 311 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:43 AM

Posted 23 December 2016 - 01:25 AM

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the Malware Removal forum and wait for help.

Failure to post replies within 4 days will result in this thread being closed.


Hello --Felix--,

My name is mAL_rEm018, but feel free to call me mAL.  I will be helping you with your malware related problems. :)

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.


Because of this, I advise you to backup any personal files and folders before you start.


Cobian Backup
DriveImage XML


To make sure everything goes smoothly, I would like you to observe the following rules:

  • You must have Administrator rights, permissions for this computer.
  • Please reply to this thread.  Do not start another topic.
  • Perform all actions in the order given.
  • If you don't know, stop and ask!
  • DO NOT run any other fix or removal tools unless instructed to do so!
  • Don't attempt to install any new software (other than those I ask you to) until your computer is clean.
  • DO NOT post for help at any other forum.  Applying fixes from multiple help sites can cause problems.
  • I advise you to print the instructions if possible, since your internet connection might not be available during some of the fixes.
  • Absence of symptoms does not mean that everything is clear, therefore stick with this topic until I give you the "all clear".

I am currently reviewing you logs and will return as soon as possible, with additional instructions.


Teacher at the Malware Removal University.

Member of UNITE

 

Failure to post replies within 4 days will result in this thread being closed


#3 --Felix--

--Felix--
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:13 AM

Posted 23 December 2016 - 12:06 PM

Hi, we should just get a deeper look.
Please follow this Preparation Guide and post in a new topic.
Let me know if all went well.

 
I followed that Preparation Guide. I have backups on external drives and performed a scan on them from other computer.  And this is the only thread I would be following to solve the issue

Edited by --Felix--, 23 December 2016 - 12:07 PM.


#4 mAL_rEm018

mAL_rEm018

  • Malware Response Team
  • 311 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:43 AM

Posted 23 December 2016 - 06:19 PM

Hello --Felix--,
 

(Swearware) C:\Users\win7\Downloads\ComboFix.exe

A word of caution: Combofix is a very powerful tool that could cause substantial damage to your computer if used incorrectly.  Please do not use it in the future, unless you are being asked by a trained helper. That being said, please navigate to the following location and post the "ComboFix.txt" log in your next reply:



C:\ComboFix.txt


Now let's get to work. :)

Backup your registry using TCRB


  • Please download TCRB to your Desktop.
  • Open Tweaking.com Registry Backup.
  • Click on the Backup Registry tab and ensure that all options are checked.
  • Press on Backup Now.
  • Wait until the backup is complete and exit the program.

No anti-virus

Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently.  Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors.



  • avast! - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
  • Microsoft Security Essentials -  Free and provides real-time protection for your home PC.

Note: You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.


-----------------------------------------
In your next reply, I would like to see..


  • Did you have trouble performing any of the steps?
  • C:\ComboFix.txt

 


Teacher at the Malware Removal University.

Member of UNITE

 

Failure to post replies within 4 days will result in this thread being closed


#5 mAL_rEm018

mAL_rEm018

  • Malware Response Team
  • 311 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:43 AM

Posted 27 December 2016 - 06:33 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.


Teacher at the Malware Removal University.

Member of UNITE

 

Failure to post replies within 4 days will result in this thread being closed





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users