Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

The system is infected with Win32.Trojan.WisdomEyes.


  • This topic is locked This topic is locked
17 replies to this topic

#1 tienchien

tienchien

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 30 May 2017 - 05:47 AM

 
The system is infected with Win32.Trojan.WisdomEyes, but I do not know how to fix it.
 
Is my chrome web browser also changed to French?
 
 
Help me, thanks.
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-05-2017
Ran by iSu (administrator) on DESKTOP-EASEBNS (30-05-2017 17:30:15)
Running from C:\Users\iSu\Downloads\Programs
Loaded Profiles: iSu (Available Profiles: iSu)
Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3Svc32.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\x64\SS3Svc64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.0_none_1a733a82001933cc\TiWorker.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-19] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9029088 2016-10-17] (Realtek Semiconductor)
HKLM\...\Run: [Sonic Studio 3] => C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\SS3svc32.exe [1208320 2016-08-27] ()
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM Group Policy restriction on software: %TEMP%\wz*\ <====== ATTENTION
HKLM Group Policy restriction on software: %TEMP%\_tc\ <====== ATTENTION
HKLM Group Policy restriction on software: %TEMP%\7z*\ <====== ATTENTION
HKLM Group Policy restriction on software: %TEMP%\Rar*\ <====== ATTENTION
HKLM Group Policy restriction on software: %TEMP%\*.zip\ <====== ATTENTION
HKLM Group Policy restriction on software: %TEMP%\8z*\ <====== ATTENTION
HKU\S-1-5-21-367381633-881415686-603470208-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4035696 2017-05-25] (Tonec Inc.)
HKU\S-1-5-21-367381633-881415686-603470208-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-20] (Piriform Ltd)
ShellIconOverlayIdentifiers: [   IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
GroupPolicy: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1574d893-57da-4946-8527-50b6ea35d919}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{1574d893-57da-4946-8527-50b6ea35d919}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-11] (Internet Download Manager, Tonec Inc.)
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-11] (Internet Download Manager, Tonec Inc.)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-03-29] (AO Kaspersky Lab)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-03-29]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF HKU\S-1-5-21-367381633-881415686-603470208-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\iSu\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\iSu\AppData\Roaming\IDM\idmmzcc5 [2017-05-30] [not signed]
FF HKU\S-1-5-21-367381633-881415686-603470208-1002\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-01-26]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-18] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-30] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default [2017-05-30]
CHR Extension: (Google Trang trình bày) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-30]
CHR Extension: (Google Tài liệu) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-30]
CHR Extension: (Google Drive) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-30]
CHR Extension: (YouTube) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-30]
CHR Extension: (Ddict Translate: Translator - Dictionary) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpggmmljdiliancllaapiggllnkbjocb [2017-05-30]
CHR Extension: (Adblock Plus) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-05-30]
CHR Extension: (Tampermonkey) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-05-30]
CHR Extension: (Google Bảng tính) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-30]
CHR Extension: (Kaspersky Protection) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-05-30]
CHR Extension: (Google Tài liệu ngoại tuyến) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-30]
CHR Extension: (Thanh toán trên cửa hàng Chrome trực tuyến) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-30]
CHR Extension: (AVIM - Bộ Gõ Tiếng Việt) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\opgbbffpdglhkpglnlkiclakjlpiedoh [2017-05-30]
CHR Extension: (Gmail) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-30]
CHR Extension: (Chrome Media Router) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-30]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2015-05-08] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-24] () [File not signed]
R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-27] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [177440 2016-09-15] (Intel Corporation)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
R2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
S3 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-18] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495040 2017-05-18] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-18] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-18] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-19] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-19] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-19] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R3 e1dexpress; C:\WINDOWS\system32\DRIVERS\e1d65x64.sys [543184 2016-07-26] (Intel Corporation)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [197336 2017-05-30] (AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [520176 2017-05-30] (AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [168736 2017-05-30] (AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1018592 2017-05-30] (AO Kaspersky Lab)
R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [57424 2017-03-29] (AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [229288 2017-05-30] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [87584 2017-05-30] (AO Kaspersky Lab)
S3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [251664 2017-05-30] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [112912 2017-05-30] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [173144 2017-05-30] (AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [136416 2017-03-29] (AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [199392 2017-05-30] (AO Kaspersky Lab)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_7209bde3180ef5f7\nvlddmkm.sys [14458264 2017-05-19] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-05-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-05-18] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-05-18] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-19] ()
R0 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [135680 2017-03-20] (Samsung Electronics Co., Ltd)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-19] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-19] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-19] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-31 03:01 - 2017-05-31 03:01 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-05-31 03:01 - 2017-05-31 03:01 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-05-31 03:01 - 2017-05-31 03:01 - 00000000 ____D C:\Program Files\MSBuild
2017-05-31 03:01 - 2017-05-31 03:01 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-05-31 03:01 - 2017-05-31 03:01 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-05-31 03:01 - 2017-02-11 02:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-05-31 03:01 - 2017-02-11 02:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-05-31 03:01 - 2017-02-11 02:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-05-31 03:01 - 2017-02-11 02:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-05-31 03:01 - 2017-02-11 02:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-05-31 03:01 - 2017-02-11 02:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-05-30 23:51 - 2017-05-30 23:51 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Skype
2017-05-30 23:51 - 2017-05-30 23:51 - 00000000 ____D C:\Users\iSu\AppData\Local\MicrosoftEdge
2017-05-30 23:41 - 2016-09-19 11:21 - 00795640 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iaStorA.sys
2017-05-30 23:41 - 2016-08-16 10:48 - 00002291 _____ C:\WINDOWS\system32\SetupBD.din
2017-05-30 23:37 - 2016-09-02 03:58 - 00426104 ____R (Intel Corporation) C:\WINDOWS\system32\PROUnstl.exe
2017-05-30 23:37 - 2016-08-05 05:17 - 00003130 _____ C:\WINDOWS\system32\e1d65x64.din
2017-05-30 23:37 - 2016-07-26 21:18 - 00543184 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\e1d65x64.sys
2017-05-30 23:37 - 2016-07-22 13:49 - 00091088 _____ (Intel Corporation) C:\WINDOWS\system32\NicInstD.dll
2017-05-30 23:37 - 2016-04-16 02:17 - 00080848 _____ (Intel Corporation) C:\WINDOWS\system32\e1dmsg.dll
2017-05-30 23:37 - 2014-04-19 00:47 - 00125728 _____ (Intel Corporation) C:\WINDOWS\system32\NicCo4.dll
2017-05-30 23:36 - 2017-05-30 23:36 - 00000000 ____D C:\Users\iSu\Intel
2017-05-30 23:36 - 2017-05-30 23:36 - 00000000 ____D C:\ProgramData\Intel
2017-05-30 23:36 - 2017-05-30 23:36 - 00000000 ____D C:\Program Files (x86)\Intel
2017-05-30 23:35 - 2017-05-30 23:35 - 00002330 _____ C:\Users\Public\Desktop\Sonic Studio 3.lnk
2017-05-30 23:35 - 2017-05-30 23:35 - 00002322 _____ C:\Users\Public\Desktop\Sonic Radar 3.lnk
2017-05-30 23:35 - 2017-05-30 23:35 - 00000000 ____D C:\Program Files\ASUSTeKcomputer.Inc
2017-05-30 23:35 - 2017-05-30 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Suite 3
2017-05-30 23:35 - 2017-05-30 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Studio 3
2017-05-30 23:34 - 2017-05-30 12:05 - 00000000 ____D C:\WINDOWS\system32\RTCOM
2017-05-30 23:34 - 2016-10-13 14:33 - 00557536 _____ (Intel Corporation) C:\WINDOWS\system32\tbb_waves.dll
2017-05-30 23:34 - 2016-07-17 08:21 - 00587104 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2017-05-30 23:34 - 2016-07-15 13:51 - 01317192 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2017-05-30 23:34 - 2016-07-04 16:26 - 00944960 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2017-05-30 23:34 - 2016-07-04 16:26 - 00434512 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2017-05-30 23:34 - 2016-05-27 06:00 - 02674440 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2017-05-30 23:34 - 2014-06-17 18:17 - 00856992 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2017-05-30 23:34 - 2014-04-14 16:52 - 00003008 ____R C:\WINDOWS\system32\Drivers\DTSU2P.DAT
2017-05-30 23:34 - 2012-01-10 09:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2017-05-30 23:34 - 2011-03-17 11:17 - 01361336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2017-05-30 23:34 - 2011-03-07 16:11 - 00148416 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2017-05-30 23:33 - 2016-10-18 11:40 - 05365728 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2017-05-30 23:33 - 2016-10-18 11:13 - 07310217 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2017-05-30 23:33 - 2016-10-18 08:41 - 03153888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2017-05-30 23:33 - 2016-10-18 08:41 - 02786272 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2017-05-30 23:33 - 2016-10-13 17:05 - 02192352 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2017-05-30 23:33 - 2016-10-12 13:49 - 03005408 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2017-05-30 23:33 - 2016-09-30 17:39 - 01921016 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat
2017-05-30 23:33 - 2016-09-20 06:49 - 00985744 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2017-05-30 23:33 - 2016-09-20 06:49 - 00842896 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2017-05-30 23:33 - 2016-09-20 06:49 - 00834192 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2017-05-30 23:33 - 2016-09-20 06:49 - 00486032 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2017-05-30 23:33 - 2016-09-20 06:48 - 00849552 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2017-05-30 23:33 - 2016-09-20 06:48 - 00706704 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2017-05-30 23:33 - 2016-07-22 13:13 - 03194848 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2017-05-30 23:33 - 2016-07-12 13:32 - 01339872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2017-05-30 23:33 - 2016-07-06 13:24 - 00000736 _____ C:\WINDOWS\system32\cxapo.prop
2017-05-30 23:33 - 2016-05-27 06:00 - 02175752 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2017-05-30 23:33 - 2016-05-27 06:00 - 01023752 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2017-05-30 23:33 - 2016-05-27 06:00 - 00250120 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2017-05-30 23:33 - 2016-05-10 17:13 - 00005604 _____ C:\WINDOWS\system32\cxapo.lncs
2017-05-30 23:33 - 2016-05-09 13:42 - 00675032 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2017-05-30 23:33 - 2016-04-06 08:50 - 15060696 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE3.dll
2017-05-30 23:33 - 2016-03-08 13:55 - 72512000 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2017-05-30 23:33 - 2015-12-28 15:18 - 03245784 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2017-05-30 23:33 - 2015-11-10 16:25 - 00182488 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2017-05-30 23:33 - 2015-04-13 15:25 - 03262184 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2017-05-30 23:33 - 2015-02-03 23:38 - 01413776 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2017-05-30 23:33 - 2015-02-03 23:38 - 00454288 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2017-05-30 23:33 - 2015-02-03 23:38 - 00369296 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2017-05-30 23:33 - 2015-02-03 23:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2017-05-30 23:33 - 2015-02-03 23:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2017-05-30 23:33 - 2014-08-14 18:16 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
2017-05-30 23:33 - 2014-05-22 15:24 - 00096568 _____ C:\WINDOWS\system32\audioLibVc.dll
2017-05-30 23:33 - 2014-04-10 11:19 - 02101848 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
2017-05-30 23:33 - 2014-02-27 19:02 - 02162992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2017-05-30 23:33 - 2013-10-11 10:31 - 00947760 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2017-05-30 23:33 - 2011-12-20 14:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2017-05-30 23:33 - 2011-11-22 15:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2017-05-30 23:33 - 2011-09-02 13:21 - 00221024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2017-05-30 23:33 - 2011-09-02 13:21 - 00081248 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2017-05-30 23:33 - 2011-09-02 13:21 - 00078688 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2017-05-30 23:33 - 2010-11-08 06:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2017-05-30 23:33 - 2010-07-22 15:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2017-05-30 23:33 - 2009-11-24 08:55 - 00518896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2017-05-30 23:33 - 2009-11-24 08:55 - 00211184 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2017-05-30 23:33 - 2009-11-24 08:55 - 00198896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2017-05-30 23:33 - 2009-11-24 08:55 - 00155888 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2017-05-30 23:32 - 2016-10-13 14:33 - 23333344 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRenderAVX64.dll
2017-05-30 23:32 - 2016-10-13 14:33 - 23234016 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRender64.dll
2017-05-30 23:32 - 2016-10-13 14:33 - 17237984 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioCapture64.dll
2017-05-30 23:32 - 2016-09-23 09:40 - 06309344 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV3apo.dll
2017-05-30 23:32 - 2016-06-17 09:31 - 05734104 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
2017-05-30 23:32 - 2016-06-17 09:31 - 05535960 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 12999384 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 12866264 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 02791640 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 01401560 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 01194200 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 01147096 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
2017-05-30 23:32 - 2016-03-08 10:28 - 00982232 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
2017-05-30 23:32 - 2014-10-24 09:12 - 00995120 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
2017-05-30 23:32 - 2014-04-10 11:19 - 02041432 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
2017-05-30 23:32 - 2014-01-31 16:27 - 01313904 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
2017-05-30 23:32 - 2013-08-14 14:36 - 00662784 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2017-05-30 23:32 - 2013-07-23 14:39 - 14048512 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll
2017-05-30 23:32 - 2013-07-23 14:39 - 00922880 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
2017-05-30 23:32 - 2012-08-31 18:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2017-05-30 23:32 - 2012-08-31 18:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2017-05-30 23:32 - 2012-08-31 18:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2017-05-30 23:32 - 2012-08-31 18:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2017-05-30 23:32 - 2012-08-31 18:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2017-05-30 23:31 - 2016-10-04 11:48 - 01595200 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
2017-05-30 23:31 - 2016-09-19 10:53 - 10431456 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll
2017-05-30 23:31 - 2016-09-19 10:53 - 01178080 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll
2017-05-30 23:31 - 2016-08-09 23:57 - 03253784 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2017-05-30 23:31 - 2016-08-01 22:07 - 00426072 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\CAF64APO2.dll
2017-05-30 23:31 - 2016-07-13 09:22 - 05285856 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2017-05-30 23:31 - 2016-07-13 09:22 - 02408928 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2017-05-30 23:31 - 2016-07-13 09:22 - 01106400 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2017-05-30 23:31 - 2016-07-13 09:22 - 00364000 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2017-05-30 23:31 - 2016-06-08 16:38 - 00102720 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\Caf64api.dll
2017-05-30 23:31 - 2016-03-17 08:57 - 00459328 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2017-05-30 23:31 - 2016-02-25 18:14 - 00145624 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00407768 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00354008 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00348376 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00193240 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00180440 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00180440 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2017-05-30 23:31 - 2016-02-02 17:33 - 00169176 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2017-05-30 23:31 - 2015-11-23 10:18 - 01506904 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64Proxy.dll
2017-05-30 23:31 - 2014-12-09 06:42 - 06255888 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2017-05-30 23:31 - 2014-12-09 06:42 - 01933584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2017-05-30 23:31 - 2014-12-09 06:42 - 00349968 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2017-05-30 23:31 - 2014-12-09 06:42 - 00298768 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2017-05-30 23:31 - 2014-09-24 10:31 - 07087448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2017-05-30 23:31 - 2014-09-24 10:31 - 01939800 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2017-05-30 23:31 - 2014-09-24 10:31 - 00315736 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2017-05-30 23:31 - 2014-09-24 10:31 - 00261464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2017-05-30 23:31 - 2013-10-11 11:47 - 00113576 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2017-05-30 23:31 - 2013-10-06 23:26 - 00501184 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
2017-05-30 23:31 - 2013-10-06 23:26 - 00487360 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
2017-05-30 23:31 - 2013-10-06 23:26 - 00415680 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
2017-05-30 23:31 - 2013-08-14 14:35 - 00663296 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
2017-05-30 23:31 - 2013-04-03 13:13 - 00906800 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
2017-05-30 23:31 - 2011-08-23 16:00 - 00603984 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 01756264 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 01568360 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 01486952 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00728680 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00712296 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00693352 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00491112 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00432744 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00428648 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2017-05-30 23:31 - 2011-05-31 08:42 - 00241768 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2017-05-30 23:31 - 2010-09-27 08:34 - 00318808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
2017-05-30 23:30 - 2017-05-30 23:35 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-05-30 23:30 - 2017-05-30 23:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-05-30 23:30 - 2017-05-30 23:30 - 00000000 ____D C:\Program Files (x86)\Realtek
2017-05-30 23:30 - 2017-05-30 14:43 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-30 23:30 - 2017-05-30 10:15 - 00000000 ____D C:\Program Files\Intel
2017-05-30 23:30 - 2016-09-22 13:55 - 02839520 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
2017-05-30 23:30 - 2015-07-23 23:29 - 00560840 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
2017-05-30 23:30 - 2013-06-21 10:01 - 00109848 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2017-05-30 23:30 - 2012-03-08 10:47 - 00108640 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
2017-05-30 23:29 - 2017-05-30 23:50 - 00000763 _____ C:\WINDOWS\Ascd_ProcessLog.ini
2017-05-30 23:29 - 2017-05-30 23:48 - 00041689 _____ C:\WINDOWS\Ascd_tmp.ini
2017-05-30 23:29 - 2017-05-30 23:30 - 00000000 ____D C:\Program Files (x86)\ASUS
2017-05-30 23:29 - 2014-09-09 09:14 - 00028672 ____R (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\AsIO.dll
2017-05-30 23:29 - 2014-09-09 09:14 - 00015232 ____R C:\WINDOWS\SysWOW64\Drivers\AsIO.sys
2017-05-30 23:28 - 2017-05-30 17:28 - 00995978 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-30 23:26 - 2017-05-30 12:10 - 00002353 _____ C:\Users\iSu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-05-30 23:26 - 2017-05-30 12:10 - 00000000 ___RD C:\Users\iSu\OneDrive
2017-05-30 23:25 - 2017-05-30 23:25 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-EASEBNS_defaultuser0_HistoryPrediction.bin
2017-05-30 23:25 - 2017-05-30 23:25 - 00000000 ____D C:\WINDOWS\CSC
2017-05-30 23:25 - 2017-05-30 23:25 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Adobe
2017-05-30 23:25 - 2017-05-30 23:25 - 00000000 ____D C:\Users\iSu\AppData\Local\VirtualStore
2017-05-30 23:25 - 2017-05-30 23:25 - 00000000 ____D C:\Users\iSu\AppData\Local\TileDataLayer
2017-05-30 23:25 - 2017-05-30 23:25 - 00000000 ____D C:\Users\iSu\AppData\Local\Publishers
2017-05-30 23:25 - 2017-05-30 12:45 - 00000000 ____D C:\Users\iSu\AppData\Local\Packages
2017-05-30 17:30 - 2017-05-30 17:30 - 00000000 ____D C:\FRST
2017-05-30 17:22 - 2017-05-30 17:22 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2017-05-30 17:17 - 2017-05-30 17:17 - 00034212 _____ C:\Users\iSu\Downloads\Addition (1).txt
2017-05-30 17:15 - 2017-05-30 17:15 - 00034212 _____ C:\Users\iSu\Downloads\Addition.txt
2017-05-30 17:12 - 2017-05-30 17:12 - 03298568 _____ (FixSecurity) C:\Users\iSu\Downloads\FixRun.exe
2017-05-30 17:12 - 2017-05-30 17:12 - 00000000 ____D C:\Users\iSu\AppData\Roaming\FixSecurity
2017-05-30 16:55 - 2017-04-28 08:38 - 01411128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-05-30 16:55 - 2017-04-28 08:19 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-05-30 16:55 - 2017-04-28 08:19 - 00605936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-30 16:55 - 2017-04-28 08:16 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-05-30 16:55 - 2017-04-28 08:12 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-05-30 16:55 - 2017-04-28 08:11 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-30 16:55 - 2017-04-28 08:09 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-30 16:55 - 2017-04-28 08:08 - 08320920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-05-30 16:55 - 2017-04-28 08:08 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-05-30 16:55 - 2017-04-28 08:08 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-30 16:55 - 2017-04-28 08:08 - 00775824 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-30 16:55 - 2017-04-28 08:07 - 06759512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-30 16:55 - 2017-04-28 08:07 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-30 16:55 - 2017-04-28 08:06 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-05-30 16:55 - 2017-04-28 08:03 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-05-30 16:55 - 2017-04-28 08:00 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-05-30 16:55 - 2017-04-28 07:59 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-05-30 16:55 - 2017-04-28 07:59 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-30 16:55 - 2017-04-28 07:59 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-05-30 16:55 - 2017-04-28 07:59 - 00207264 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-30 16:55 - 2017-04-28 07:58 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-30 16:55 - 2017-04-28 07:58 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-05-30 16:55 - 2017-04-28 07:57 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-30 16:55 - 2017-04-28 07:56 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-05-30 16:55 - 2017-04-28 07:55 - 21353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-05-30 16:55 - 2017-04-28 07:55 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-30 16:55 - 2017-04-28 07:52 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-05-30 16:55 - 2017-04-28 07:51 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-05-30 16:55 - 2017-04-28 07:46 - 19335168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-05-30 16:55 - 2017-04-28 07:42 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-05-30 16:55 - 2017-04-28 07:40 - 11870208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-05-30 16:55 - 2017-04-28 07:40 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-05-30 16:55 - 2017-04-28 07:40 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-05-30 16:55 - 2017-04-28 07:39 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-05-30 16:55 - 2017-04-28 07:39 - 03655680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-05-30 16:55 - 2017-04-28 07:37 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-30 16:55 - 2017-04-28 07:26 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-05-30 16:55 - 2017-04-28 07:15 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-05-30 16:55 - 2017-04-28 07:05 - 01075712 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-05-30 16:55 - 2017-04-28 07:04 - 23681024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-05-30 16:55 - 2017-04-28 07:03 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-30 16:55 - 2017-04-28 07:03 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-05-30 16:55 - 2017-04-28 07:01 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-05-30 16:55 - 2017-04-28 07:00 - 08244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-05-30 16:55 - 2017-04-28 06:59 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-30 16:55 - 2017-04-28 06:59 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-30 16:55 - 2017-04-28 06:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-05-30 16:55 - 2017-04-28 06:58 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-05-30 16:55 - 2017-04-28 06:58 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-05-30 16:55 - 2017-04-28 06:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-05-30 16:55 - 2017-04-28 06:57 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-05-30 16:55 - 2017-04-28 06:57 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-05-30 16:55 - 2017-04-28 06:57 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-30 16:55 - 2017-04-28 06:54 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-05-30 16:55 - 2017-04-28 06:54 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-30 16:55 - 2017-04-19 14:06 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-30 16:55 - 2017-04-19 14:02 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2017-05-30 16:55 - 2017-04-19 13:15 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-05-30 16:55 - 2017-04-19 13:14 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2017-05-30 16:55 - 2017-04-19 13:13 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-30 16:55 - 2017-04-19 13:12 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-05-30 16:55 - 2017-04-19 13:11 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-30 16:55 - 2017-04-19 13:11 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-05-30 16:55 - 2017-04-19 13:10 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-05-30 16:55 - 2017-04-19 13:10 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-05-30 16:55 - 2017-04-19 13:10 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-05-30 16:55 - 2017-04-19 13:08 - 01103872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-05-30 16:55 - 2017-04-19 13:07 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-05-30 16:55 - 2017-04-19 13:07 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-30 16:55 - 2017-04-19 13:06 - 02651648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-05-30 16:55 - 2017-04-19 13:04 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-30 16:55 - 2017-04-19 13:04 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-30 16:55 - 2017-04-19 13:02 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-30 16:55 - 2017-04-19 12:59 - 02435584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-30 16:55 - 2017-04-19 12:58 - 20374424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-05-30 16:55 - 2017-04-19 12:32 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2017-05-30 16:55 - 2017-04-19 12:30 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-05-30 16:55 - 2017-04-19 12:29 - 02298880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-05-30 16:55 - 2017-04-14 07:35 - 04848440 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-05-30 16:55 - 2017-04-14 07:35 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-05-30 16:55 - 2017-04-14 07:33 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-05-30 16:55 - 2017-04-14 07:32 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-05-30 16:55 - 2017-04-14 07:25 - 01854880 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-05-30 16:55 - 2017-04-14 07:25 - 01452960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-05-30 16:55 - 2017-04-14 06:43 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-05-30 16:55 - 2017-04-14 06:39 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-05-30 16:55 - 2017-04-14 06:39 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-05-30 16:55 - 2017-04-14 06:39 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-05-30 16:55 - 2017-04-14 06:39 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-05-30 16:55 - 2017-04-14 06:39 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-05-30 16:55 - 2017-04-14 06:37 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-05-30 16:55 - 2017-04-14 06:37 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-05-30 16:55 - 2017-04-14 06:37 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-05-30 16:55 - 2017-04-14 06:35 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-30 16:55 - 2017-04-14 06:35 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2017-05-30 16:55 - 2017-04-14 06:34 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-05-30 16:55 - 2017-04-14 06:33 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-05-30 16:55 - 2017-04-14 06:31 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-05-30 16:55 - 2017-04-14 06:29 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-05-30 16:55 - 2017-04-14 06:29 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-30 16:55 - 2017-04-14 06:29 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-05-30 16:55 - 2017-04-14 06:29 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-05-30 16:55 - 2017-04-14 06:29 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-05-30 16:55 - 2017-04-14 06:28 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-05-30 16:55 - 2017-04-14 06:26 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-05-30 16:55 - 2017-04-14 06:24 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-05-30 16:55 - 2017-04-14 06:21 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-05-30 16:55 - 2017-04-14 06:21 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-05-30 16:55 - 2017-04-14 06:18 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-05-30 16:55 - 2017-04-14 06:18 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-05-30 16:55 - 2017-04-14 06:08 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-30 16:55 - 2017-04-14 06:04 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-05-30 16:55 - 2017-04-14 06:01 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-05-30 16:55 - 2017-04-01 08:05 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-05-30 16:55 - 2017-04-01 08:04 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-05-30 16:55 - 2017-04-01 08:04 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-05-30 16:55 - 2017-04-01 07:57 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-05-30 16:55 - 2017-04-01 07:57 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-05-30 16:55 - 2017-04-01 07:52 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-05-30 16:55 - 2017-04-01 07:51 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-30 16:55 - 2017-04-01 07:29 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-05-30 16:55 - 2017-04-01 07:04 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-05-30 16:55 - 2017-04-01 06:58 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-05-30 16:55 - 2017-04-01 06:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-05-30 16:55 - 2017-04-01 06:50 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-05-30 16:54 - 2017-04-28 08:18 - 02259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-05-30 16:54 - 2017-04-28 08:12 - 00543640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-05-30 16:54 - 2017-04-28 08:06 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-30 16:54 - 2017-04-28 08:05 - 00923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-05-30 16:54 - 2017-04-28 08:04 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-05-30 16:54 - 2017-04-28 07:59 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-30 16:54 - 2017-04-28 07:53 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-05-30 16:54 - 2017-04-28 07:52 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-05-30 16:54 - 2017-04-28 07:52 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-30 16:54 - 2017-04-28 07:49 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-30 16:54 - 2017-04-28 07:49 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-30 16:54 - 2017-04-28 07:46 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2017-05-30 16:54 - 2017-04-28 07:46 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-30 16:54 - 2017-04-28 07:45 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-30 16:54 - 2017-04-28 07:44 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-30 16:54 - 2017-04-28 07:44 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-30 16:54 - 2017-04-28 07:42 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-30 16:54 - 2017-04-28 07:42 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-30 16:54 - 2017-04-28 07:42 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-05-30 16:54 - 2017-04-28 07:41 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-30 16:54 - 2017-04-28 07:40 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-30 16:54 - 2017-04-28 07:40 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-05-30 16:54 - 2017-04-28 07:40 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-05-30 16:54 - 2017-04-28 07:39 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-30 16:54 - 2017-04-28 07:38 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-30 16:54 - 2017-04-28 07:38 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-05-30 16:54 - 2017-04-28 07:37 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-05-30 16:54 - 2017-04-28 07:34 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-05-30 16:54 - 2017-04-28 07:33 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-30 16:54 - 2017-04-28 07:15 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-05-30 16:54 - 2017-04-28 07:14 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-30 16:54 - 2017-04-28 07:11 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-30 16:54 - 2017-04-28 07:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-05-30 16:54 - 2017-04-28 07:11 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-30 16:54 - 2017-04-28 07:09 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2017-05-30 16:54 - 2017-04-28 07:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-30 16:54 - 2017-04-28 07:08 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2017-05-30 16:54 - 2017-04-28 07:08 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-05-30 16:54 - 2017-04-28 07:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-30 16:54 - 2017-04-28 07:07 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-30 16:54 - 2017-04-28 07:06 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-05-30 16:54 - 2017-04-28 07:06 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-05-30 16:54 - 2017-04-28 07:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-30 16:54 - 2017-04-28 07:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-30 16:54 - 2017-04-28 07:05 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-30 16:54 - 2017-04-28 07:04 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-30 16:54 - 2017-04-28 07:04 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-05-30 16:54 - 2017-04-28 07:04 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-05-30 16:54 - 2017-04-28 07:03 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-30 16:54 - 2017-04-28 07:03 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-30 16:54 - 2017-04-28 07:03 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-05-30 16:54 - 2017-04-28 07:02 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-30 16:54 - 2017-04-28 07:01 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-30 16:54 - 2017-04-28 06:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-05-30 16:54 - 2017-04-28 06:59 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-05-30 16:54 - 2017-04-28 06:54 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-05-30 16:54 - 2017-04-28 06:54 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-30 16:54 - 2017-04-28 06:52 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-05-30 16:54 - 2017-04-19 14:07 - 00712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-05-30 16:54 - 2017-04-19 14:04 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-05-30 16:54 - 2017-04-19 13:19 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-05-30 16:54 - 2017-04-19 13:18 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-05-30 16:54 - 2017-04-19 13:16 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-05-30 16:54 - 2017-04-19 13:13 - 00980992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-05-30 16:54 - 2017-04-19 13:13 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-05-30 16:54 - 2017-04-19 13:12 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-30 16:54 - 2017-04-19 13:12 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-05-30 16:54 - 2017-04-19 13:08 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-30 16:54 - 2017-04-19 13:01 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-05-30 16:54 - 2017-04-19 12:59 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-05-30 16:54 - 2017-04-19 12:37 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2017-05-30 16:54 - 2017-04-19 12:36 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-05-30 16:54 - 2017-04-19 12:35 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-05-30 16:54 - 2017-04-19 12:34 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-30 16:54 - 2017-04-19 12:34 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-05-30 16:54 - 2017-04-19 12:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2017-05-30 16:54 - 2017-04-14 07:35 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2017-05-30 16:54 - 2017-04-14 07:30 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-05-30 16:54 - 2017-04-14 06:43 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-05-30 16:54 - 2017-04-14 06:41 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-05-30 16:54 - 2017-04-14 06:41 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-05-30 16:54 - 2017-04-14 06:40 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-05-30 16:54 - 2017-04-14 06:38 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-05-30 16:54 - 2017-04-14 06:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-30 16:54 - 2017-04-14 06:37 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-05-30 16:54 - 2017-04-14 06:36 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-05-30 16:54 - 2017-04-14 06:36 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-05-30 16:54 - 2017-04-14 06:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-30 16:54 - 2017-04-14 06:34 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2017-05-30 16:54 - 2017-04-14 06:33 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-05-30 16:54 - 2017-04-14 06:31 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-05-30 16:54 - 2017-04-14 06:25 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-05-30 16:54 - 2017-04-14 06:15 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-05-30 16:54 - 2017-04-14 06:15 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-05-30 16:54 - 2017-04-14 06:13 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2017-05-30 16:54 - 2017-04-14 06:13 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-30 16:54 - 2017-04-14 06:06 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-05-30 16:54 - 2017-04-01 08:04 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-05-30 16:54 - 2017-04-01 07:28 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-05-30 16:54 - 2017-04-01 07:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-05-30 16:54 - 2017-04-01 07:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-05-30 16:54 - 2017-04-01 07:05 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-05-30 16:54 - 2017-04-01 07:04 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-05-30 16:54 - 2017-04-01 07:02 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-05-30 16:54 - 2017-04-01 07:01 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-05-30 16:54 - 2017-04-01 06:56 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-05-30 16:54 - 2017-04-01 06:55 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-05-30 16:54 - 2017-04-01 06:55 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-05-30 16:54 - 2017-04-01 06:52 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-05-30 16:54 - 2017-04-01 06:52 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-05-30 16:54 - 2017-04-01 06:50 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-05-30 16:54 - 2017-04-01 06:45 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-05-30 16:54 - 2017-04-01 06:44 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-05-30 16:54 - 2017-04-01 04:00 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2017-05-30 16:47 - 2017-05-30 16:48 - 02587824 _____ (Kaspersky Lab) C:\Users\iSu\Downloads\startup.exe
2017-05-30 14:58 - 2017-05-30 14:58 - 00000000 ____D C:\Users\iSu\Documents\Battlefield 1
2017-05-30 14:44 - 2017-05-30 14:44 - 00004110 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{93B62D34-4896-4F36-ACC0-C41C90417C25}
2017-05-30 14:43 - 2017-05-30 14:43 - 00000000 ____D C:\Program Files\Samsung
2017-05-30 14:42 - 2017-05-30 14:42 - 00000000 ____D C:\ProgramData\Electronic Arts
2017-05-30 14:32 - 2017-05-30 17:02 - 00000000 ____D C:\Users\iSu\Desktop\avz4
2017-05-30 14:21 - 2017-05-30 14:21 - 00000000 ____D C:\ProgramData\s2v4
2017-05-30 14:21 - 2017-05-30 14:21 - 00000000 ____D C:\ProgramData\s2ug
2017-05-30 14:18 - 2017-05-30 14:55 - 00001239 _____ C:\Users\Public\Desktop\Battlefield 1.lnk
2017-05-30 14:18 - 2017-05-30 14:18 - 00000000 ___HD C:\Program Files\Common FilesEAInstaller
2017-05-30 14:18 - 2017-05-30 14:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 1
2017-05-30 14:15 - 2017-05-30 14:15 - 00000000 ____D C:\WINDOWS\Panther
2017-05-30 13:56 - 2017-05-30 13:56 - 00251664 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2017-05-30 13:56 - 2017-05-30 13:56 - 00229288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2017-05-30 13:56 - 2017-05-30 13:56 - 00173144 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2017-05-30 13:56 - 2017-05-30 13:56 - 00112912 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2017-05-30 13:55 - 2017-05-30 13:55 - 00000000 ____D C:\ProgramData\s8ao
2017-05-30 13:55 - 2017-05-30 13:55 - 00000000 ____D C:\ProgramData\s7ac
2017-05-30 13:53 - 2017-05-30 13:53 - 00087584 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2017-05-30 13:52 - 2017-05-30 17:30 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-05-30 13:52 - 2017-05-30 17:12 - 00003392 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-05-30 13:52 - 2017-05-30 13:55 - 01018592 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2017-05-30 13:52 - 2017-05-30 13:55 - 00520176 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2017-05-30 13:52 - 2017-05-30 13:55 - 00197336 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2017-05-30 13:52 - 2017-05-30 13:53 - 00000000 ____D C:\Program Files\Common Files\AV
2017-05-30 13:52 - 2017-05-30 13:52 - 00002209 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2017-05-30 13:52 - 2017-05-30 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2017-05-30 13:52 - 2017-05-30 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2017-05-30 13:52 - 2017-05-30 13:52 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2017-05-30 13:52 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2017-05-30 13:46 - 2017-05-30 13:46 - 00000000 ____D C:\Users\iSu\AppData\Roaming\WinRAR
2017-05-30 13:42 - 2017-05-30 16:48 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-05-30 13:42 - 2017-05-30 13:42 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-05-30 13:42 - 2017-05-30 13:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-05-30 13:42 - 2017-05-30 13:42 - 00000000 ____D C:\Program Files\WinRAR
2017-05-30 13:24 - 2017-05-30 13:24 - 00000000 ____D C:\ProgramData\ses
2017-05-30 13:24 - 2017-05-30 13:24 - 00000000 ____D C:\ProgramData\s2hc
2017-05-30 13:19 - 2017-05-30 13:19 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-05-30 13:10 - 2017-05-30 13:10 - 00002866 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-05-30 13:10 - 2017-05-30 13:10 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-05-30 13:10 - 2017-05-30 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-05-30 13:10 - 2017-05-30 13:10 - 00000000 ____D C:\Program Files\CCleaner
2017-05-30 12:50 - 2017-05-30 12:56 - 00000400 __RSH C:\ProgramData\ntuser.pol
2017-05-30 12:50 - 2017-05-30 12:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-05-30 12:38 - 2017-05-30 12:38 - 00000000 ____D C:\Users\iSu\AppData\Local\PeerDistRepub
2017-05-30 12:27 - 2017-05-30 12:27 - 00000000 ____D C:\Users\iSu\AppData\Local\SS3
2017-05-30 12:25 - 2017-05-30 14:17 - 00000000 ____D C:\Users\iSu\AppData\Local\NVIDIA Corporation
2017-05-30 12:25 - 2017-05-30 12:25 - 00000000 ____D C:\Users\iSu\AppData\Local\Comms
2017-05-30 12:16 - 2017-05-30 12:16 - 00000000 ____D C:\ProgramData\USOShared
2017-05-30 12:15 - 2017-05-30 12:15 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-30 12:15 - 2017-05-30 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-05-30 12:15 - 2017-05-18 14:35 - 01893312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-05-30 12:15 - 2017-05-18 14:35 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-05-30 12:15 - 2017-05-18 14:35 - 01477056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-05-30 12:15 - 2017-05-18 14:35 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-05-30 12:15 - 2017-05-18 14:35 - 00121280 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-05-30 12:15 - 2017-05-18 14:35 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-05-30 12:15 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2017-05-30 12:15 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2017-05-30 12:15 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2017-05-30 12:15 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2017-05-30 12:15 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2017-05-30 12:15 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2017-05-30 12:14 - 2017-05-30 12:14 - 00000000 ____D C:\Users\iSu\AppData\Local\DBG
2017-05-30 12:14 - 2017-05-30 12:14 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-05-30 12:14 - 2017-05-18 14:35 - 00513144 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-05-30 12:14 - 2017-05-18 12:21 - 00134592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2017-05-30 12:14 - 2017-03-11 04:17 - 00536864 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-05-30 12:14 - 2017-03-11 04:17 - 00525600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-05-30 12:14 - 2017-03-11 04:17 - 00254240 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-05-30 12:14 - 2017-03-11 04:17 - 00233760 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-05-30 12:13 - 2017-05-18 14:35 - 40201848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 35390072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 35282040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 28624504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 11056456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 11028664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 10551072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 09248144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 09014976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 08808488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 03797112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 03624784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 03256440 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 01988216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438233.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 01606592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438233.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 01278528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 01275944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 01056704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00995736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00993912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00993872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00964032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00914880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00775864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00725112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00688968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00618928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00612272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00609728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00583800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00577728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00499320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00143296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00057792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-05-30 12:13 - 2017-05-18 14:35 - 00048064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-05-30 12:13 - 2017-05-18 14:35 - 00046008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2017-05-30 12:13 - 2017-05-18 14:35 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-05-30 12:13 - 2017-05-18 14:35 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-05-30 12:10 - 2017-05-30 12:10 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-05-30 12:09 - 2017-05-30 12:09 - 00000020 ___SH C:\Users\iSu\ntuser.ini
2017-05-30 12:09 - 2017-05-30 12:09 - 00000000 ____D C:\Users\iSu\AppData\Local\ConnectedDevicesPlatform
2017-05-30 12:08 - 2017-05-30 12:08 - 00000000 _SHDL C:\Users\Default\My Documents
2017-05-30 12:08 - 2017-03-19 03:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-05-30 12:06 - 2017-05-30 17:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-30 12:06 - 2017-05-30 12:26 - 00022009 _____ C:\WINDOWS\diagwrn.xml
2017-05-30 12:06 - 2017-05-30 12:26 - 00011433 _____ C:\WINDOWS\diagerr.xml
2017-05-30 12:06 - 2017-05-30 12:10 - 00003286 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-05-30 12:06 - 2017-05-30 12:06 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-05-30 12:06 - 2017-05-30 12:06 - 00003432 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-30 12:06 - 2017-05-30 12:06 - 00003208 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-05-30 12:06 - 2017-05-30 12:06 - 00003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2017-05-30 12:06 - 2017-05-30 12:06 - 00002406 _____ C:\WINDOWS\System32\Tasks\SS3Svc64Run
2017-05-30 12:06 - 2017-05-30 12:06 - 00002398 _____ C:\WINDOWS\System32\Tasks\SS3Svc32Run
2017-05-30 12:05 - 2017-05-30 12:05 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-05-30 12:05 - 2017-05-30 12:05 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-05-30 12:04 - 2017-05-30 17:22 - 00000000 ____D C:\ProgramData\NVIDIA
2017-05-30 12:04 - 2017-05-30 17:20 - 00000000 ____D C:\Users\iSu
2017-05-30 12:04 - 2017-05-30 12:04 - 00000000 _SHDL C:\Users\iSu\My Documents
2017-05-30 12:04 - 2017-05-30 12:04 - 00000000 _SHDL C:\Users\iSu\Documents\My Videos
2017-05-30 12:04 - 2017-05-30 12:04 - 00000000 _SHDL C:\Users\iSu\Documents\My Pictures
2017-05-30 12:04 - 2017-05-30 12:04 - 00000000 _SHDL C:\Users\iSu\Documents\My Music
2017-05-30 12:04 - 2017-05-18 14:35 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-05-30 12:04 - 2017-05-18 12:48 - 06437824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 02479736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 01762936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 00548984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 00392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-05-30 12:04 - 2017-05-18 12:48 - 00069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-05-30 12:04 - 2017-05-17 01:09 - 07993157 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-05-30 12:03 - 2017-05-30 17:22 - 00217000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-30 12:03 - 2017-05-30 12:15 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-05-30 12:03 - 2017-05-30 12:15 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-05-30 12:03 - 2017-05-30 12:15 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-05-30 12:03 - 2017-05-30 12:05 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-05-30 12:03 - 2017-05-30 12:03 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-05-30 12:03 - 2017-05-30 12:03 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-05-30 12:03 - 2017-05-30 12:03 - 00000000 ____D C:\WINDOWS\system32\DAX2
2017-05-30 12:03 - 2017-05-30 12:03 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-05-30 12:03 - 2017-05-30 12:03 - 00000000 ____D C:\Program Files\Realtek
2017-05-30 11:57 - 2017-05-30 12:05 - 00000000 ____D C:\Program Files\CMAK
2017-05-30 11:57 - 2017-05-30 11:57 - 00000000 ____D C:\Program Files (x86)\CMAK
2017-05-30 11:37 - 2017-05-30 11:48 - 39348224 _____ C:\Users\iSu\Downloads\en_windows_10_multiple_editions_version_1703_updated_march_2017_x64_dvd_10189288.iso
2017-05-30 11:35 - 2017-05-30 11:35 - 00001401 _____ C:\Users\iSu\AppData\Roaming\Microsoft\Windows\Start Menu\1Password 6.lnk
2017-05-30 11:35 - 2017-05-30 11:35 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Macromedia
2017-05-30 11:35 - 2017-05-30 11:35 - 00000000 ____D C:\Users\iSu\AppData\Local\1password
2017-05-30 11:28 - 2017-05-30 17:20 - 00000000 ____D C:\Users\iSu\AppData\Roaming\DMCache
2017-05-30 11:28 - 2017-05-30 17:03 - 00000000 ____D C:\Users\iSu\Downloads\Video
2017-05-30 11:28 - 2017-05-30 14:32 - 00000000 ____D C:\Users\iSu\AppData\Roaming\IDM
2017-05-30 11:28 - 2017-05-30 14:17 - 00000000 ____D C:\Users\iSu\Downloads\Compressed
2017-05-30 11:28 - 2017-05-30 12:05 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-05-30 11:28 - 2017-05-30 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-05-30 11:28 - 2017-05-30 11:28 - 00001074 _____ C:\Users\iSu\Desktop\Internet Download Manager.lnk
2017-05-30 11:28 - 2017-05-30 11:28 - 00000000 ____D C:\ProgramData\IDM
2017-05-30 11:28 - 2017-05-30 11:28 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
2017-05-30 11:23 - 2017-05-30 11:28 - 07167896 _____ (Tonec Inc.) C:\Users\iSu\Downloads\idman628build11.exe
2017-05-30 11:06 - 2017-05-30 11:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-30 11:05 - 2017-05-30 11:05 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-30 11:05 - 2017-04-08 05:06 - 00532136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-30 11:00 - 2017-05-30 11:01 - 00000000 ____D C:\Program Files (x86)\Origin Games
2017-05-30 10:59 - 2017-05-30 14:58 - 00000000 ____D C:\Users\iSu\AppData\Roaming\Origin
2017-05-30 10:54 - 2017-05-30 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-05-30 10:54 - 2017-05-30 10:54 - 00001058 _____ C:\Users\Public\Desktop\Origin.lnk
2017-05-30 10:54 - 2017-05-30 10:54 - 00000000 ____D C:\Program Files (x86)\Origin
2017-05-30 10:52 - 2017-05-30 14:51 - 00000000 ____D C:\ProgramData\Origin
2017-05-30 10:52 - 2017-05-30 11:00 - 00000000 ____D C:\Users\iSu\AppData\Local\Origin
2017-05-30 10:52 - 2017-05-30 10:52 - 00000000 ____D C:\Users\iSu\.QtWebEngineProcess
2017-05-30 10:52 - 2017-05-30 10:52 - 00000000 ____D C:\Users\iSu\.Origin
2017-05-30 10:48 - 2017-05-30 10:48 - 01993784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437878.dll
2017-05-30 10:48 - 2017-05-30 10:48 - 01598392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437878.dll
2017-05-30 10:48 - 2017-05-18 14:35 - 04114248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-05-30 10:48 - 2017-05-18 14:35 - 01600560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2017-05-30 10:48 - 2017-05-18 14:35 - 00218040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2017-05-30 10:48 - 2017-05-18 14:35 - 00045061 _____ C:\WINDOWS\system32\nvinfo.pb
2017-05-30 10:42 - 2017-05-30 10:42 - 00000000 ____D C:\Users\iSu\Desktopk
2017-05-30 10:42 - 2016-09-30 10:28 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2017-05-30 10:41 - 2016-09-07 11:22 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2017-05-30 10:10 - 2017-05-30 12:08 - 00002268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-30 10:10 - 2017-05-30 12:08 - 00002256 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-30 10:10 - 2017-05-30 10:53 - 00000000 ____D C:\Users\iSu\AppData\Local\Google
2017-05-30 10:10 - 2017-05-30 10:10 - 00000000 ____D C:\Program Files (x86)\Google
2017-05-25 22:54 - 2016-10-17 22:35 - 00223464 _____ (Tonec Inc.) C:\WINDOWS\system32\Drivers\idmwfp.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-31 03:03 - 2017-03-19 04:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-05-31 03:02 - 2017-03-19 04:06 - 00000000 ____D C:\WINDOWS\Setup
2017-05-31 03:01 - 2017-03-19 03:56 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\telnet.exe
2017-05-30 17:22 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-30 17:22 - 2015-08-20 10:33 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-30 17:21 - 2017-03-18 18:40 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-30 17:20 - 2017-03-19 04:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-30 17:20 - 2017-03-19 04:01 - 00000000 ____D C:\WINDOWS\INF
2017-05-30 17:20 - 2017-03-18 18:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-05-30 17:04 - 2017-03-19 03:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-30 13:55 - 2016-06-14 17:47 - 00199392 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2017-05-30 13:52 - 2017-03-19 04:03 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-05-30 13:52 - 2017-03-18 18:40 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-05-30 12:50 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-05-30 12:50 - 2015-07-10 18:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-05-30 12:46 - 2017-03-19 04:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-30 12:16 - 2017-03-19 04:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-05-30 12:07 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-05-30 12:07 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\Registration
2017-05-30 12:06 - 2017-03-19 04:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-05-30 12:06 - 2015-07-10 18:04 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-05-30 12:05 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-05-30 12:05 - 2017-03-19 04:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-30 12:05 - 2017-03-19 04:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-05-30 12:04 - 2017-03-19 09:31 - 00000000 ____D C:\WINDOWS\HoloShell
2017-05-30 12:04 - 2017-03-19 04:03 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-05-30 12:04 - 2017-03-19 04:03 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-05-30 12:04 - 2017-03-19 04:03 - 00000000 ____D C:\WINDOWS\Help
2017-05-30 12:04 - 2017-03-18 18:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-05-30 10:16 - 2015-07-10 18:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2017-05-30 10:16 - 2015-07-10 18:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2017-05-18 14:35 - 2017-03-19 09:31 - 00418752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
 
==================== Files in the root of some directories =======
 
2017-05-30 12:03 - 2017-05-30 12:03 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-05-30 12:03
 
==================== End of FRST.txt ============================

Attached Files


Edited by tienchien, 30 May 2017 - 06:35 AM.


BC AdBot (Login to Remove)

 


#2 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 30 May 2017 - 06:41 AM


:welcome: to BleepingComputer.

Hi there,

my name is Jo and I will help you with your computer problems.


Please follow these guidelines:
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • back up all your private data / music / important files on another (external) drive before using our tools.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic ‘til you get the “all clean” post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

***


:step1: Please download Security Analysis by Rocket Grannie from here
  • Save it to your Desktop.
  • Close your security software to avoid potential conflicts.
  • Double click RGSA.exe
  • Click OK on the copyright-disclaimer
  • When finished, a Notepad window will open with the results of the scan.
  • The log named SALog.txt can also be found on the Desktop or in the same folder from where the tool is run if installed elsewhere.
  • Please copy and paste the contents of that log in this topic.
  • Note:
If you get a Warning from Windows about running the program, click on More info and then click Run Anyway to run it even though Windows says it might put your PC at risk.

***


:step2: Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
With some infections, you may see two messages boxes.
  • 'Could not load protection driver'. Click 'OK'.
  • 'Could not load DDA driver'. Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions.
  • If malware is found - do not press the Clean up button, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
  • If there is no malware found, please let me know as well.

***


:step3: Please download AdwCleaner by Xplode and save to your Desktop.
Double-click AdwCleaner.exe
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it.
    If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#3 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 30 May 2017 - 07:10 AM

No infection found. In my C drive there is software, which when I scan it with VirusTotal.com it still detects Win32.Trojan.WisdomEyes.

 

Thanks verry much.

 

 

----------------------------------------------------------------------------------------------------

Result of Security Analysis by Rocket Grannie (x86) Updated: 22nd May, 2017
Running from:C:\Users\iSu\Desktop (18:52:25 - 05/30/2017)
***---------------------------------------------------------***
Microsoft Windows 10 Pro X64
UAC is Enabled
Internet Explorer 11
Default Browser: Google Chrome
***------------Antivirus - Antispyware - Firewall-----------***
Kaspersky Internet Security (Disabled - up to Date)
Windows Defender (Enabled - up to Date)
Kaspersky Internet Security (Disabled - up to Date)
Windows Defender (Enabled - up to Date)
Kaspersky Internet Security (Disabled)
***-------Security Programs - Browsers - Miscellaneous------***
Adobe Flash Player 25 NPAPI is not installed
CCleaner (5.30)
Google Chrome (58.0.3029.110)
 
***----------------Analysis Complete-------------------------***
 
 
-----------------------------------------------------------------------------
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2017.05.30.03
  rootkit: v2017.05.27.01
 
Windows 10 x64 NTFS
Internet Explorer 11.296.15063.0
iSu :: DESKTOP-EASEBNS [administrator]
 
5/30/2017 6:53:44 PM
mbar-log-2017-05-30 (18-53-44).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 254679
Time elapsed: 5 minute(s), 12 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 
 
 
 
--------------------------------------------------
# AdwCleaner v6.047 - Logfile created 30/05/2017 at 18:59:59
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-05-26.6 [Server]
# Operating System : Windows 10 Pro  (X64)
# Username : iSu - DESKTOP-EASEBNS
# Running from : C:\Users\iSu\Desktop\AdwCleaner.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
 
 
***** [ Web browsers ] *****
 
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [746 Bytes] - [30/05/2017 18:59:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [1137 Bytes] - [30/05/2017 18:59:54]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [891 Bytes] ##########
 
 
 

Edited by tienchien, 30 May 2017 - 07:17 AM.


#4 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 30 May 2017 - 07:32 AM

Hello again,

:step1: Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7/8/10 users need to right click and choose Run as Administrator
You only need to get one of them to run, not all of them.Do not reboot your computer after running rkill as the malware programs will start again.


---


:step2: Malwarebytes' Anti-Malware
If this program is already installed: Skip the installation and run only the scan!
Download and install: Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mb3-setup-1878.1878-3.5.1.2522.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
How to get logs: (Export log to save as txt)
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Attach that saved log to your next reply.
(Copy to clipboard for pasting into forum replies or tickets)
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

---


:step3:
ZN3USrZ.png Emsisoft Emergency Kit
  • Click here to download Emsisoft Emergency Kit. The download will automatically start after a moment.
  • Save EmsisoftEmergencyKit.exe to your Desktop.
  • Double click on EmsisoftEmergencyKit.exe (Windows Vista/7/8 users: Accept UAC warning if it is enabled). A screen like this will appear:
    dQVDkTW.png
  • Leave everything as it is, then click Extract. This will unpack Emsisoft Emergency Kit to the EEK folder located in the root drive (usually C:\).
  • Once the extraction is done, an icon qwL1Upn.png will appear on your Desktop. Double click it to start Emsisoft Emergency Kit.
  • Wait for Emsisoft Emergency Kit to finish loading signatures. A screen like this should appear:
    yEgPemv.png
  • Choose Yes, then wait for EEK to finish updating.
  • Choose Malware Scan under the Scan button. When EEK asks to activate PUP detection, choose Yes.
  • Wait for the scan to finish.
    RUeRoi4.png
  • If EEK detects something, all detected items will be displayed. Place a checkmark before everything, then choose Quarantine Selected.
  • If Emsisoft Emergency Kit asks to reboot, please do so immediately.
  • The scan log is located in Logs -> Scan Logs. Click on the entry of the latest scan, choose Export and save the report on your Desktop.
    P7FSALs.png
  • Please Copy and Paste the contents of the scan log in your next reply.

***


:step4: How the computer is running now?


***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#5 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 30 May 2017 - 10:41 AM

I did all that you told me. But as in previous times, no infection was detected. It seems my system is clean, but sometimes it has very strange behavior that I can not explain.

 

After all, I am very thankful to you.


Edited by tienchien, 30 May 2017 - 10:41 AM.


#6 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 30 May 2017 - 10:54 AM

The system is infected with Win32.Trojan.WisdomEyes, but I do not know how to fix it.


How do you know about Trojan.WisdomEyes?

---

You could Uninstall Chrome

restart the pc

Re-install Chrome but enable only plugins/addons that you really need!

---

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
Save it in the same location as / FSRT / FSRT64 (usually your desktop) as fixlist.txt
 
Start
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction <======= ATTENTION
CHR Extension: (Chrome Media Router) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-30]
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST / FSRT64 again as Administrator like we did before but this time press the Fix button just once and wait.

The tool will make a log (Fixlog.txt) please post it to your reply.


How the computer is running now?

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#7 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 30 May 2017 - 10:17 PM

I use https://www.virustotal.com to scan a file on drive c, and I get an infection. I will do what you told after hours. thank you very much.

#8 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 31 May 2017 - 05:19 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-05-2017
Ran by iSu (31-05-2017 17:08:56) Run:1
Running from C:\Users\iSu\Desktop
Loaded Profiles: iSu (Available Profiles: iSu)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction <======= ATTENTION
CHR Extension: (Chrome Media Router) - C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-30]
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"C:\WINDOWS\system32\GroupPolicy\Machine" => not found.
C:\Users\iSu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
 
 
The system needed a reboot.
 
==== End of Fixlog 17:09:03 ====


#9 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 31 May 2017 - 05:43 AM

I use https://www.virustotal.com to scan a file on drive c, and I get an infection. I will do what you told after hours. thank you very much.

Please go to virustotal to scan the file(s):
Virus Total
click on Browse, and upload that above mentioned file(s) for analysis:

Then click Submit. Allow the file(s) to be scanned, and then please copy and paste the results link (for Virus Total) here for me to see.
If it says already scanned -- click "reanalyze now"
Please post the results in your next reply.

---

ESET Online Scanner
  • Click here to download the installer for ESET Online Scanner and save it to your Desktop.
  • Disable all your antivirus and antimalware software - see how to do that here.
  • Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.
Open the scan log and copy and paste the content to your next reply.
 

***


Edited by Jo*, 31 May 2017 - 05:43 AM.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#10 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 31 May 2017 - 08:27 AM

Wow, what did you do with my browser?

Right now, I no longer receive ads when I use the browser. I tried to get rid of them for 2 years but failed, even when I reinstalled windows many times.

Thank you very much.

 

 

 

Strange, now I can not find the file that Virutotal detected "Win32.Trojan.WisdomEyes". It is located in the path: C:\Program Files\ASUSTeKcomputer.Inc\Sonic Suite 3\Foundation\ Of software called SS3Svc32.exe. It is a legitimate software that I install from my Z270f mobo asus cd driver. Now when I'm on the path above, Fodel \Foundation simply does nothing.

 

PS: esetsmartinstaller_enu.exe Report found nothing.


Edited by tienchien, 31 May 2017 - 08:27 AM.


#11 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 31 May 2017 - 08:41 AM

Can you tell me how your computer is running now and if there are any remaining malware related problems.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#12 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 31 May 2017 - 09:28 AM

I just downloaded the MSI Afterburner software from the MSI home page. Installed on the machine, and immediately I get the message ???

 

 

Looks like my system has something so that malicious code can come back. Hix

 

 

 

Untitled2378e.png

 

IMG_0053.jpg


Edited by tienchien, 31 May 2017 - 09:32 AM.


#13 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 31 May 2017 - 09:54 AM

Please translate what your AV (Kapersky) reports.

What I can see is:

1. You use torrents what is a high risk for getting malware
2. Kapersky detects a file in a temp folder, which could be related to your torrent/download
3. If malware comes along with your download, it is ok that Kapersky detects it
4. if no malware, Kapersky makes a false positive detection, which is an issue for Kapersky Support/Forums

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#14 tienchien

tienchien
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  

Posted 31 May 2017 - 11:03 AM

Yeah, that was a false positive.

My system is working fine. I will note your reminder about the torrent And I know it is illegal. Thank you all for the help, again.


Edited by tienchien, 31 May 2017 - 11:03 AM.


#15 Jo*

Jo*

  • Malware Response Team
  • 3,408 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:07 AM

Posted 31 May 2017 - 11:22 AM

***


It Appears That Your Pc Is Clean!


***


Clean up:


***


Right-click AdwCleaner.exe and select Run As Administrator.
  • Click on the Uninstall button.
  • A window will open, press the Confirm button.
  • AdwCleaner will uninstall now.

***


Clean up with delfix:
  • please download delfix to your desktop.
  • Close all other programms and start delfix.
  • Please check all the boxes and run the tool.
  • delfix will now delete all found traces of our removal process

***


Delete the log files our tools created; they are located at your desktop or at the
"c:\users\{.......}\Downloads" folder.
Highlight them, and press the del or delete key on the keyboard.
You can browse to the location of the file or folder using either My Computer or Windows Explorer.

===================================

Here are some Preventive tips to reduce the potential for spyware infection in the future

:step1: Make sure you keep your Windows OS current.
  • Windows Vista / 7 / 8 users can update via
    Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane).
:step2: Avoid P2P
  • If you think you're using a "safe" P2P program, only the program is safe, not the data.
  • You will share files from unsafe sources, and these may be infected.
  • Some bad guys use P2P filesharing as an important chanel to spread their wares.
:step3: Use only one anti-virus software and keep it up-to-date.

:step4: Firewall
Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

:step5: Backup regularly
You never know when your PC will become unstable or become so infected that you can't recover it.

:step6: Use Strong passwords!

:step7: Email attachments
Do not open any unknown email attachments, which you received without asking for it!


Extra note:
Keep your Browser, Java, pdf Reader and Adobe Flash Up to Date.
And you could install Malwarebytes Anti-Exploit to run alongside your traditional anti-virus or anti-malware products.

Make sure your programs are up to date - because older versions may contain Security Leaks.


***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users