Kako ukloniti Kineski antivirus?

1

Kako ukloniti Kineski antivirus?

offline
  • Pridružio: 23 Mar 2016
  • Poruke: 11

U kompjuter mi se ubacio kineski antivirus, Tencent Tehnology.
Blokirao mi je Windows defender i obrisao Chrome, sam radi sam neke stvari.

Obrisala sam ono sto sam mogla rucno, i uninstlirala ono sto sam videla na listi, takodje sam i odradila scan sa avastom koji je dosta fajlova obrisao, ali u padajucem meniju mi se i dalje pojavljuju odredjene kineske opcije.
Sta sledece da uradim kako bih potpuno ocistila kompjuter? Confused



offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Pozdrav,
Postavi dijagnosticki izvestaj i sacekaj da neko od nas (AMF Tim) pregleda log;

Preuzmi Farbar-ov Farbar Recovery Scan Tool () sa ove adrese na Desktop:
Postoji 32bit. i 64bit.-na verzija. Potrebno je preuzeti verziju koja je kompatibilna sa tvojim sistemom.
Ako nisi siguran koja verzija se odnosi na tvoj sistem, preuzmi ih obe i pokreni. Samo jedan od njih će raditi na tvom sistemu, to će biti prava verzija.


dvoklikom pokreni program, kada se alat pokrene klikni Yes na disclaimer prozor;
pričekati koji trenutak dok alat proverava postoji li novija verzija;
klikni na dugme Scan;
po završetku skeniranja, alat će formirati izveštaj (FRST.txt) u isti direktorijum gde je FRST alat sačuvan;
iskopiraj sadržaj FRST.txt izveštaja u poruku;
po prvom pokretanju, alat bi trebao formirati i dodatni izveštaj (Addition.txt);
okači Addition.txt izveštaj uz poruku koristeći opciju Prikači fajl

offline
  • Pridružio: 23 Mar 2016
  • Poruke: 11

Napisano: 23 Mar 2016 15:53

mycity.rs/must-login.png

mycity.rs/must-login.png

Dopuna: 23 Mar 2016 15:58

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Jovana (administrator) on DESKTOP-MU7BIH8 (23-03-2016 15:48:48)
Running from C:\Users\Jovana\Downloads
Loaded Profiles: Jovana (Available Profiles: Jovana)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Users\Jovana\AppData\Roaming\cpuminer\cpm.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [cpuminer] => C:\Users\Jovana\AppData\Roaming\cpuminer\cpm.exe [1402880 2016-02-29] ()
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25577864 2016-03-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [31744 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMGCShellExt64.dll [2016-03-23] (Tencent)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-23] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
Startup: C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-03-22]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5de0fb33-21b7-4e5b-94a9-f17250dd0225}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6be40341-419b-4fc1-8879-be152113c089}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.2345.com/?34838
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSWebMon64.dat [2016-03-23] (Tencent)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-23] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO-x32: Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-23] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-755135921-1565032832-2796582722-1002 -> hxxp://www.google.com/

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll [2016-03-23] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-22] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-02-26] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-23]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=C88FAF2E2E2E58D2C5E6F1FFABD17F9F&v=20160315&ts=AHEpC3QnAXUmBU.."
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-22]
CHR Extension: (Facebook) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2016-03-22]
CHR Extension: (Soundtrap - Make Music Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\epaknpicfmoglpinnnjckaobafganajf [2016-03-23]
CHR Extension: (Word Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2016-03-22]
CHR Extension: (Avast Online Security) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-03-23]
CHR Extension: (Excel Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljnkagajgfdmfnnidjijobijlfjfgnb [2016-03-22]
CHR Extension: (PDF Viewer) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\jccchjobcggajhnmckffhcahkkbioifn [2016-03-22]
CHR Extension: (PowerPoint Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdafamggmaaaginooondinjgkgcbpnhp [2016-03-22]
CHR Extension: (HUMAN 3.0) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\meefjekipolcgabfgaclcpdkbghhmoah [2016-03-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-22]
CHR Extension: (Gmail) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-22]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-23]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-23] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.)
S2 ggbugreport; C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe [1592888 2016-03-15] ()
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe [313936 2016-03-23] (Tencent)
U2 QQRepair19e7; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair19e7 [136512 2016-03-23] ()
S2 QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC [136512 2016-03-23] ()
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-10-19] (Popcorn Time) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 Winsere; C:\Program Files (x86)\Winsere\Winsere\Winsere.exe [306736 2016-03-15] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [82664 2015-12-16] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-23] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-23] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-23] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4334240 2015-10-02] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUdisk64.sys [184536 2016-03-02] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQSysMonX64.sys [152184 2016-03-23] (电脑管家)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\softaal64.sys [44664 2016-03-23] (Tencent)
R1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [168568 2016-03-23] ()
S3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [101472 2016-03-15] (Tencent)
R2 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernelEx64.sys [141944 2016-03-23] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [97400 2016-03-23] (电脑管家)
S3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TS888x64.sys [38520 2016-03-23] (Tencent)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSDefenseBT64.sys [28984 2016-03-23] (Tencent)
R2 tsnethlpx64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TsNetHlpX64.sys [57976 2016-03-23] ()
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSSysKit64.sys [96888 2016-03-23] (电脑管家)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

========================== Drivers MD5 =======================

C:\Windows\System32\drivers\1394ohci.sys DF1C3D7E6C7929AD83BE22852B5B08CB
C:\Windows\System32\drivers\3ware.sys 2C5B3035B86770ADD2FE9BFBAF5B35A4
C:\Windows\System32\drivers\ACPI.sys 469441BAE3FF8A16826FC62C51EF5E18
C:\Windows\System32\Drivers\acpiex.sys 7EADED8087C392876521F7EBCE846EF4
C:\Windows\System32\drivers\acpipagr.sys C498887123327CDFD73A05E7A2780920
C:\Windows\System32\drivers\acpipmi.sys C8DBE6EFFCF014CAA010B9BDDAC833EC
C:\Windows\System32\drivers\acpitime.sys 17039DBEB3B7B9ADCDB4B4533AA9771F
C:\Windows\System32\drivers\AcpiVpc.sys E13DE7CD2B62254DD4FF658B7798A37D
C:\Windows\System32\drivers\ADP80XX.SYS F7D0CD345D2DA42E7042ABCD73662403
C:\Windows\system32\drivers\afd.sys 70148EFA9A562E7185B75BBE7D376BF7
C:\Windows\System32\drivers\agp440.sys 870F1A2C936F92B5D053DF7EC75B352F
C:\Windows\System32\DRIVERS\ahcache.sys 3DF7751D5DC6525E7DC6617FBB45054F
C:\Windows\System32\drivers\amdk8.sys B70F0F2F54B4A4DB6E9C830454752F5A
C:\Windows\system32\DRIVERS\atikmdag.sys F992CE57F4D2A2F988135A1F87337EBC
C:\Windows\system32\DRIVERS\atikmpag.sys 17BA5C907E14947574CBB788F4CEB85F
C:\Windows\System32\drivers\amdkmpfd.sys 82D7250133CF669A294AF189910C8744
C:\Windows\System32\drivers\amdppm.sys 35E890482C9728DD5C552B85DA8A5AB2
C:\Windows\System32\drivers\amdsata.sys 5B30BCFE6E02E45D3EE268FF001BC5E0
C:\Windows\System32\drivers\amdsbs.sys F20B30F35A5C7888441B4DCA001ECF8E
C:\Windows\System32\drivers\amdxata.sys AFE838D7576C581D6483529621AB10CC
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys C3D487827E48CC5EC17994FEC5BDFF87
C:\Windows\System32\drivers\appid.sys EDDB0D726DBECDFC1DBCC6DB464E5A13
C:\Windows\System32\drivers\arcsas.sys E3FE8F610B1CC12BC3B2E6BC43DC97E2
C:\Windows\system32\drivers\aswHwid.sys 7E66DFE6B62C6C34FD6B09DB6169E9F6
C:\Windows\system32\drivers\aswMonFlt.sys 1459AAD5C6A66A458C2D57EE6E080FA5
C:\Windows\system32\drivers\aswRdr2.sys 0866D5FE02D614501B7B4AD5E1BC7B53
C:\Windows\System32\Drivers\aswRvrt.sys 0AA12ADF5F87B4A70BDBAED77F54B978
C:\Windows\system32\drivers\aswSnx.sys 719B704109B933D819093CDDB156A7F1
C:\Windows\system32\drivers\aswSP.sys 43F46E7D103F46EC345B1056BDD2A60B
C:\Windows\system32\drivers\aswStm.sys 219D0E2348629FAE4E6E3478C21B23D6
C:\Windows\System32\Drivers\aswVmm.sys 9949BBD5BB70C4D317B7549896132579
C:\Windows\System32\drivers\asyncmac.sys 5E00748A1AD246CAECBBB7553BED36CC
C:\Windows\System32\drivers\atapi.sys 492B99D2E3D5D7BFD5F0AE1BE7BD37DD
C:\Windows\System32\drivers\athw10x.sys 34F7CAD6F43431B58459F16CD7D8E914
C:\Windows\system32\drivers\AtihdWT6.sys FD9A5BCC3AFB02E87668B749546B6229
C:\Windows\System32\drivers\bxvbda.sys 6447BA6FA709514B6C803D159B4C7D1E
C:\Windows\System32\drivers\BasicDisplay.sys B4AC08B1D04D0CE085435E5CD0E663C5
C:\Windows\System32\drivers\BasicRender.sys 25B5BB369DEE2BAE4BF459C978FF9035
C:\Windows\System32\drivers\bcmfn.sys 3F5523DCEFE42B385659C5CB46A6B810
C:\Windows\System32\drivers\bcmfn2.sys 0B750A6A6D847E73CA48ADD7A0F5A393
C:\Windows\System32\Drivers\Beep.sys 5A88834AEE15D97695FAE0837B73B3E4
C:\Windows\System32\DRIVERS\bowser.sys DA2C6F7ACE392193C424FEA975C5BFFB
C:\Windows\system32\DRIVERS\btfilter.sys 7037B585F7D4AB58F1CFB1E7841E6FEF
C:\Windows\System32\drivers\BthAvrcpTg.sys CAEC7BC11AF69A181AF7932E636E09E4
C:\Windows\system32\DRIVERS\BthEnum.sys 36417FC4F11C31C880CB428037DEDF3F
C:\Windows\System32\drivers\bthhfenum.sys 5F2B4B32E986C058525D3BA2A475A16C
C:\Windows\System32\drivers\BthHFHid.sys 5406289E8AE2CB52FC408154E0A64BA7
C:\Windows\system32\DRIVERS\BthLEEnum.sys CC6C1393B423EBFF9F6696CB9CC4CBCB
C:\Windows\System32\drivers\bthmodem.sys A76F20CCCA31895A1DA78A875E50F946
C:\Windows\System32\drivers\bthpan.sys 09C3DB1B137B269A822F941D867A6BB6
C:\Windows\system32\DRIVERS\BTHport.sys CEFF59649E90987D263D96078724A54A
C:\Windows\system32\DRIVERS\BTHUSB.sys 0D279373091AA1BBEEE958AAF02B5EDF
C:\Windows\System32\drivers\buttonconverter.sys BF89BDBA5D3A0B4256D3F6FC8D31880D
C:\Windows\System32\drivers\capimg.sys C24C27FDF93B85A4EFCF25F830253AA2
C:\Windows\System32\DRIVERS\cdfs.sys 7F9C7226D743B232907ED2537B8A574F
C:\Windows\System32\drivers\cdrom.sys 82D97776BF982AA143BDC7DFB5054EA8
C:\Windows\System32\drivers\circlass.sys 0505C1D991D0F9D47F3353BB98597C7E
C:\Windows\System32\drivers\CLFS.sys 8B4B39C507ABA09AAFE8E3932D1B392C
C:\Windows\System32\drivers\CmBatt.sys 95832B049E2833B9F5189823CDF946C7
C:\Windows\System32\Drivers\cng.sys A1105260EEEE3DBD8D38FD054B22BD00
C:\Windows\System32\DRIVERS\cnghwassist.sys 58D640BC2294C71BDE0953F12D4B432F
C:\Windows\system32\drivers\CHDRT64.sys 8D62E811B121573D7AB93D9E9538812B
C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_912dfdedc3d2f520\CompositeBus.sys 14F9883588398A1BDE49C75098C75DE6
C:\Windows\System32\drivers\condrv.sys 02B8E49148DE5E0A2F6FDF28CE94A6AC
C:\Windows\System32\drivers\csc.sys 5D578EAAFB6FD4F59523E5878B541296
C:\Windows\System32\drivers\dam.sys 2619DC483579DB9FE804044C1ADFFD1A
C:\Windows\System32\Drivers\dfsc.sys C9478D7DB7BE5D7ACE65CB1167F07320
C:\Windows\System32\drivers\disk.sys 4904B152E4942BF700F2D73228B4D477
C:\Windows\System32\drivers\dmvsc.sys 0197AE4B9790A4E73751CACFAA480126
C:\Windows\system32\DRIVERS\drmkaud.sys 25FA06D3B49D6ADF8E874FFCDCD76B50
C:\Windows\System32\drivers\dxgkrnl.sys F45665E77D11F3C1552EDBEAD1559DC8
C:\Windows\System32\drivers\E1G6032E.sys CCED99682127E8582E5F716ECE775EF8
C:\Windows\System32\drivers\evbda.sys 491275B864B704B54EC08168344E0F38
C:\Windows\System32\drivers\EhStorClass.sys CEF108FCE06892CFA5F1B49527D4BF49
C:\Windows\System32\drivers\EhStorTcgDrv.sys 5B1EAAE3001A7A320C106FC3859F4111
C:\Windows\System32\drivers\errdev.sys 7A2705148A4BB3CA255F81624338B461
C:\Windows\System32\Drivers\exfat.sys DFE8A33FBCF6F38182631A4D6097B92D
C:\Windows\System32\Drivers\fastfat.sys 03DE0EC072C5EBD5B018CAD83F1E522A
C:\Windows\System32\drivers\fdc.sys 9D299AE86D671488926126A84DF77BFD
C:\Windows\System32\drivers\filecrypt.sys 8F12AB59336143B680F71B217B495AD2
C:\Windows\System32\drivers\fileinfo.sys 92ECCFA58C8195B8EA33ED942469D4E6
C:\Windows\System32\drivers\filetrace.sys 87C51FDD50C17882BA93E28BBABB9847
C:\Windows\System32\drivers\flpydisk.sys E99261DD76D1C9E05AF575939CAE5AC5
C:\Windows\System32\drivers\fltmgr.sys 25D7A58625E1453E40D36825DE74E4F1
C:\Windows\System32\drivers\FsDepends.sys B4175E8BE60B099686FF55CA7D692316
C:\Windows\System32\Drivers\Fs_Rec.sys CC71372CEB811A72F1DC99089C5CBF53
C:\Windows\System32\DRIVERS\fvevol.sys 421497634C86EF4B8F86D0EBC076728F
C:\Windows\System32\drivers\gagp30kx.sys B9981A4CB9F728B3312A3885BFAA7204
C:\Windows\System32\drivers\vmgencounter.sys 77555B11B264991DDC26872FFCF1AB97
C:\Windows\System32\drivers\genericusbfn.sys F3AC9652D88BF87BA6596CBEA28CE10F
C:\Windows\System32\Drivers\msgpioclx.sys F802FBABF0C4DF1BAA733187B2E476F5
C:\Windows\System32\drivers\gpuenergydrv.sys D011B0ADB15F4815310CE1BF4780B33E
C:\Windows\system32\DRIVERS\HdAudio.sys 0F93EBE9071A6BB1548BF0F816EEA24B
C:\Windows\System32\drivers\HDAudBus.sys 84BC034B6BB763733C1949B7B9BAF976
C:\Windows\System32\drivers\HidBatt.sys 6B8CB114B8E64C0636EB49F7B914D1FC
C:\Windows\System32\drivers\hidbth.sys D1AD197CCDAAC0CB4819DA1D6EB17BAE
C:\Windows\System32\drivers\hidi2c.sys 64909DECCFCC6FB5D9A5BAFDCCB31FEE
C:\Windows\System32\drivers\hidinterrupt.sys F510F7B7BF61DEAAC04E65C3B65E8D59
C:\Windows\System32\drivers\hidir.sys 90F3ED42D423C942BA5EA54E2FFE7AC7
C:\Windows\System32\drivers\hidusb.sys 128DEDDD61915DBA4D451D91D21F0513
C:\Windows\System32\drivers\HpSAMD.sys FF442DCDCE1F6E9FAA9C8AD0CD1D199B
C:\Windows\System32\drivers\HTTP.sys 318E816717431D3C23DC82779900C744
C:\Windows\System32\drivers\hwpolicy.sys CBA5E88A0F0475B7F49653BB72150BEF
C:\Windows\System32\drivers\hyperkbd.sys D668FAB4B0397B426EE3D41683B9A1C0
C:\Windows\system32\DRIVERS\HyperVideo.sys 40115A0F8E7FF9E786EBBD1D33D39AD7
C:\Windows\System32\drivers\i8042prt.sys 53FDD9E69189E546DE4740F8C4D8AB2F
C:\Windows\System32\drivers\iai2c.sys 9A2A2F3C69B9A30B6E78536F6D258BAD
C:\Windows\System32\drivers\iaLPSS2i_I2C.sys 59A20F5AD9F4AE54098154359519408E
C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 16A10CCEDCF5AC4CAAE43DC9FC40392F
C:\Windows\System32\drivers\iaLPSSi_I2C.sys EB82A11613326691508D9ED9A4FE29E7
C:\Windows\System32\drivers\iaStorAV.sys 6B0029A0253098CCE28EACCFDB9E7208
C:\Windows\System32\drivers\iaStorV.sys 9652E1E35A92D8C75710C17A63B15796
C:\Windows\System32\drivers\ibbus.sys FFADF691F7BF727AF5C863454A372723
C:\Windows\System32\drivers\intelide.sys ECDB27420D3A98424666904525A8562A
C:\Windows\System32\drivers\intelpep.sys 8FF1978643EFD219C5BA49690191D701
C:\Windows\System32\drivers\intelppm.sys B61B60F36E1C8022FA8166ABF0F66B07
C:\Windows\System32\drivers\ioqos.sys CA0D42029AFFC4514D295E1EF823D02D
C:\Windows\System32\DRIVERS\ipfltdrv.sys 6E3F9D95235DFC9417384080A216F310
C:\Windows\System32\drivers\IPMIDrv.sys 4F527ECB5EAB47D8EAF34A469666C469
C:\Windows\System32\drivers\ipnat.sys 9E5E8F2A1996F23B7E9687846AA81B01
C:\Windows\System32\drivers\irenum.sys C317EB660138BC9CBFE37CCDE56351AE
C:\Windows\System32\drivers\isapnp.sys 531994A6D9399D9B74BE12B5BB58A81E
C:\Windows\System32\drivers\msiscsi.sys 68D5354A4A9692EEC24664C60F47D4A2
C:\Windows\System32\drivers\kbdclass.sys 701D7DB13B0815E7076EF4CB4CE981F8
C:\Windows\System32\drivers\kbdhid.sys 884EBBDDBF5968003B40185BD96FF0E6
C:\Windows\System32\drivers\kdnic.sys 6B3A0C7902811E6372643447E41F7048
C:\Windows\System32\Drivers\ksecdd.sys 982C795DE20CED7AEDD2E7899B5D9BC1
C:\Windows\System32\Drivers\ksecpkg.sys 7D8B9214692C4D0F1646215D9984E19A
C:\Windows\system32\drivers\ksthunk.sys E9BB0023D730701BB5D9839B44F5E6B5
C:\Windows\System32\drivers\lltdio.sys EC34EED89C34B27C292166B725AC7A7B
C:\Windows\System32\drivers\lsi_sas.sys 961F28D879D345BFA50AF51285C90F2E
C:\Windows\System32\drivers\lsi_sas2i.sys 6BFB8D1B3407518BE06B6F81F92FA0F5
C:\Windows\System32\drivers\lsi_sas3i.sys BE0E47988D78F731DEC2C0CB03E765CB
C:\Windows\System32\drivers\lsi_sss.sys F99BF02BE9219986817BF094981EEB18
C:\Windows\system32\drivers\luafv.sys 2FCF837196082864F66CFD9CAB256275
C:\Windows\System32\drivers\megasas.sys 2ED29B635F35E31A1C0D3DDB7DD2AD03
C:\Windows\System32\drivers\megasr.sys 22E3CB85870879CBAE13C5095A8B12E3
C:\Windows\System32\drivers\mlx4_bus.sys D41920FBFFF2BBCBBC69A5B383AD022E
C:\Windows\system32\drivers\mmcss.sys 64BD0C87064EA20C2D3DC4199F9C239C
C:\Windows\System32\drivers\modem.sys 8D4B46FA84A3A3702EDADD37FAC6EDBA
C:\Windows\System32\drivers\monitor.sys 78FEC1BDB168370F131BFBFEA0A04E9D
C:\Windows\System32\drivers\mouclass.sys D1CC0833CFBC4222A95CAA5D0C8C78FF
C:\Windows\System32\drivers\mouhid.sys C2E05EC6B80BCF5AE362DA873E1BCE64
C:\Windows\System32\drivers\mountmgr.sys D5B7668A8F6C67C51FA5C6C513396D6C
C:\Windows\System32\drivers\mpsdrv.sys 5FBCB85D127BE21E3A9DAF11A13C00EA
C:\Windows\system32\drivers\mrxdav.sys BF6CA7EA5ECD6CF72D3D76652A9B8280
C:\Windows\System32\DRIVERS\mrxsmb.sys 0B3B0C1D86050355676640488FA897D3
C:\Windows\System32\DRIVERS\mrxsmb10.sys 1A490555FD330CA2764D89191177C867
C:\Windows\System32\DRIVERS\mrxsmb20.sys 0F47A6C09F0A7FB5513D322A2B9BE4EC
C:\Windows\System32\drivers\bridge.sys A4411C522D41707D5BCA817A5BB9E30B
C:\Windows\System32\Drivers\Msfs.sys D123343DDB02E372B02BF2C4293F835F
C:\Windows\System32\drivers\msgpiowin32.sys B3358F380BA3F29F56BE0F7734C24D5F
C:\Windows\System32\drivers\mshidkmdf.sys B2044D5D125F249680508EC0B2AAEFAC
C:\Windows\System32\drivers\mshidumdf.sys 36ABE7FC80BED4FE44754AE5CFB51432
C:\Windows\System32\drivers\msisadrv.sys 59307FEAFC9E72EEEC56B7FD7D294F4C
C:\Windows\system32\DRIVERS\MSKSSRV.sys E9457EDFEBC774199F907395C6D09CA2
C:\Windows\System32\drivers\mslldp.sys C85D79735641D27C5821C35ECDDC2334
C:\Windows\system32\DRIVERS\MSPCLOCK.sys EF75184B64356850D0F04D049C253526
C:\Windows\system32\DRIVERS\MSPQM.sys 543933D166C618E7588EA77707EC1683
C:\Windows\System32\Drivers\MsRPC.sys 182711E9DDF70121A20EBB61B2DFB9E8
C:\Windows\System32\drivers\mssmbios.sys E887FFDD6734C496407E9219225CB6FF
C:\Windows\system32\DRIVERS\MSTEE.sys 83A2AB75951000D681FABDB80C07AEFC
C:\Windows\System32\drivers\MTConfig.sys 4FA0483896FC16583851EFB733FCB083
C:\Windows\System32\Drivers\mup.sys 60F88248608315E13391C2F1C3B4473F
C:\Windows\System32\drivers\mvumis.sys 218705233D02776AE4D19CC37D985C1B
C:\Windows\System32\DRIVERS\nwifi.sys 536A0806CE2061A2157E65D4D8ABF30C
C:\Windows\System32\drivers\ndfltr.sys B57CE307DA101C739885B7CC0678077F
C:\Windows\System32\drivers\ndis.sys AFAECF904F1C343EBD50F91BC8D0DBE8
C:\Windows\System32\drivers\ndiscap.sys 202260E7CDD731A32AF62ABD1ABEE008
C:\Windows\System32\drivers\NdisImPlatform.sys A1D473D0CF10561F29B58EA7C5412A92
C:\Windows\System32\DRIVERS\ndistapi.sys 1A0AE283B8DE6BB76412A0F8213D45AC
C:\Windows\System32\drivers\ndisuio.sys A74EE2D2C0BFF5EC3A6185791868C4CA
C:\Windows\System32\drivers\NdisVirtualBus.sys 32A9BD1342640D48AD85C8B3E812B984
C:\Windows\System32\drivers\ndiswan.sys 6A6A8CF5EE61801375A38EBB871D4057
C:\Windows\System32\DRIVERS\ndiswan.sys 6A6A8CF5EE61801375A38EBB871D4057
C:\Windows\System32\DRIVERS\NDProxy.sys 50AEF8EF0064A91ABB08D858D039C9DE
C:\Windows\System32\drivers\Ndu.sys D358DF634F52247CB43F0781218F4D6E
C:\Windows\System32\drivers\netbios.sys 026618ECF6C4BEBDCB7885D42EC0DBE4
C:\Windows\System32\DRIVERS\netbt.sys F51C02D992A8D6BC5EC4D990F227D4C7
C:\Windows\System32\drivers\netvsc.sys 2BB62723C835F75F0C7C9E6A736881FB
C:\Windows\System32\Drivers\Npfs.sys 465DC580170CD844206D7E3EF1DBF2A1
C:\Windows\System32\drivers\npsvctrig.sys 29395C214D2CD4C81F73166AB988A797
C:\Windows\System32\drivers\nsiproxy.sys 2871225495F832A8C8A7DD1A17EDB3DC
C:\Windows\System32\Drivers\NTFS.sys 58BFFEF692A47FCE3FAAEDBC8F3DCBBB
C:\Windows\System32\Drivers\Null.sys 6DBD703320484C37CEA9E4E2D266A8CE
C:\Windows\System32\drivers\nvraid.sys 604D27CC38CC23493F218D0BB834B3FF
C:\Windows\System32\drivers\nvstor.sys 8B50D897657AB4A15FD9E251BBF7D107
C:\Windows\System32\drivers\nv_agp.sys 31F990B2B6B91E9D7A667405CE12FCB1
C:\Windows\System32\drivers\parport.sys 7D0FC96264C0F8F2C1321E33E8EB646C
C:\Windows\System32\drivers\partmgr.sys 24AC0FD10325FBC2303B29A5F237AEB0
C:\Windows\System32\drivers\pci.sys 1D4E995955BDAE781C46CB97AE1CFB58
C:\Windows\System32\drivers\pciide.sys 2B4D98DF0CA57FB9536DBC80D2449D1F
C:\Windows\System32\drivers\pcmcia.sys F4D5793BF2E58AF15C6CF2FEEF9E73EB
C:\Windows\System32\drivers\pcw.sys 22A53744CEEADFFFD33BA010FAD95229
C:\Windows\System32\drivers\pdc.sys 48F3A3222CF340FE31535CB6D49C6D6F
C:\Windows\System32\drivers\peauth.sys E2F8376F9731D12A009C522036C6073A
C:\Windows\System32\drivers\percsas2i.sys 1398A85E59698067CBBE1D66A9C13ADF
C:\Windows\System32\drivers\percsas3i.sys 35F7C7AD709D909D618D9EDF987FC3ED
C:\Windows\System32\drivers\raspptp.sys 5BA6B9AD03B81546BA64E488C4EF9D17
C:\Windows\System32\drivers\processr.sys 21AECFF3EB5748CBE12538A2500EFDE5
C:\Windows\System32\drivers\pacer.sys 596FB6C5A72F34B7566930985E543806
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUdisk64.sys 4730BC23CB7A412BDDEB4A54B8D8AE36
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQSysMonX64.sys 41DCFDA02BD886B5F4225AEA7142A1D4
C:\Windows\system32\drivers\qwavedrv.sys CFBA9C976CBF6796E5DC39EF59984021
C:\Windows\System32\DRIVERS\rasacd.sys 7B2AD8C55217B514C14281AB97B4E21D
C:\Windows\System32\drivers\AgileVpn.sys E15A9CE1E2E7D1C8DF97A4FC1FFE6289
C:\Windows\System32\drivers\rasl2tp.sys E3C82823B22463BC38AA4F8ADA852624
C:\Windows\System32\drivers\raspppoe.sys 3369023EB5790A75BA7DABA14B75D922
C:\Windows\System32\drivers\rassstp.sys 1E32A8CD65C4AD0A827CFEB13034DA29
C:\Windows\System32\DRIVERS\rdbss.sys 2B648363E4C5E34B469C58596F377DD9
C:\Windows\System32\drivers\rdpbus.sys D0221C13960E274CC539D72D5A842ED0
C:\Windows\System32\drivers\rdpdr.sys 1DC2CC74B51E4DC4CD5A20C1021E4010
C:\Windows\System32\drivers\rdpvideominiport.sys 177DF954D0DEC0465A380C75F6E7F65F
C:\Windows\System32\drivers\rdyboost.sys 5D1680871054D2B0B8A971BC8AB3B837
C:\Windows\System32\Drivers\ReFSv1.sys 341E6830DA70F65730300DAB4CB0B490
C:\Windows\System32\drivers\rfcomm.sys 74727B8BF0227820660A79450F2D94EF
C:\Windows\System32\drivers\rspndr.sys 0AC5FCDC29ED97ECDEF1276425EE2059
C:\Windows\System32\drivers\rt640x64.sys CF0F908B50CD8FB12B7B69DA56A44681
C:\Windows\system32\Drivers\RtsUer.sys 87CCF37EC2858FCF7689F8FC0B72F39A
C:\Windows\system32\DRIVERS\rtsuvc.sys 14F73F34745B8EEF780181910B3BF41F
C:\Windows\System32\drivers\vms3cap.sys 044890BB0D6CF1E23C1087234D320509
C:\Windows\System32\drivers\sbp2port.sys 530F797129776AA7E81994783A97E2AD
C:\Windows\System32\DRIVERS\scfilter.sys 9B6B1D4DB35A3D9BEAF023BC95E1F49D
C:\Windows\System32\drivers\sdbus.sys 70165A0A2653FB8AFDE3D85000727F29
C:\Windows\System32\drivers\sdstor.sys DE6D7DC78D956928F59F7415A0F41E13
C:\Windows\System32\drivers\SerCx.sys 67585C295FF2D221679E376B68893B35
C:\Windows\System32\drivers\SerCx2.sys B8C4852CBCAAC1374C08EC7445443824
C:\Windows\System32\drivers\serenum.sys D3A103944A8FCD78FD48B2B19092790C
C:\Windows\System32\drivers\serial.sys 88D58E1DAA6C5062DD3A26273106961F
C:\Windows\System32\drivers\sermouse.sys 0F5B43074AE731D2C6F061241C9D84A6
C:\Windows\System32\drivers\sfloppy.sys D9FE59276BD56A9643C32D5FACE2F251
C:\Windows\System32\drivers\SiSRaid2.sys ABBE803FE0BDAE0E5BE74DDEFBE62F23
C:\Windows\System32\drivers\sisraid4.sys 6043DF55CFE3C7ACF477645FA64DEA98
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\softaal64.sys AF1E457B01C2CAAFDCAC118738ACC066
C:\Windows\System32\drivers\spaceport.sys 1A6CB30F0EFC1632E6F1B852CA892583
C:\Windows\System32\drivers\SpbCx.sys E1C158F6C00359278727A2CEE5D2ED71
\??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv 32503C6C5902F7A5E3F824FE04083B1C
C:\Windows\System32\DRIVERS\srv.sys ACC1709EC7FE6EB8999DBC91C50C2B34
C:\Windows\System32\DRIVERS\srv2.sys AFBCFC946FAE7483E27BD316D03F94A5
C:\Windows\System32\DRIVERS\srvnet.sys 107C1EBE79710E4A759449BD6604245A
C:\Windows\System32\drivers\stexstor.sys CCDA497C880AD16D87EDFAEFCFB2EDF5
C:\Windows\System32\drivers\storahci.sys BF8EA6FC3358C2F69678E3E94F764F84
C:\Windows\System32\drivers\vmstorfl.sys 32FF460DA8C1F370F5C08B7654899B73
C:\Windows\System32\drivers\stornvme.sys CC21DB3EF619B9480FE31A4EFE92CBEB
C:\Windows\System32\drivers\storqosflt.sys 390B8A75768E2689586539C224520895
C:\Windows\System32\drivers\storufs.sys 770A92D9D3A0BF61C97C3AFCB36847D9
C:\Windows\System32\drivers\storvsc.sys 736A2418E3E7F3DB3CF6EB0A55D1D581
C:\Windows\System32\drivers\swenum.sys BD98B0225BCD49E8A62F4F8EE1D1F613
C:\Windows\System32\drivers\Synth3dVsc.sys CAE4B27B469C583131EA5AAE622F5D76
C:\Windows\system32\Drivers\TAOAccelerator64.sys 165894C340DC4C812CD130DD8D2BCFC0
C:\Windows\system32\Drivers\TAOKernelEx64.sys F131940D7D0B0778FDFD0D4F327928CD
C:\Windows\System32\drivers\tcpip.sys 892F30506DCCF230C5A57019C1D8D31B
C:\Windows\System32\drivers\tcpip.sys 892F30506DCCF230C5A57019C1D8D31B
C:\Windows\System32\drivers\tcpipreg.sys 17F37EC9042D84561C550620643D9A85
C:\Windows\system32\DRIVERS\tdx.sys 91D3F2A6253EF83EFBD7903028F58C4D
C:\Windows\System32\drivers\terminpt.sys E730D0EB1B84EBC98423FC8D285EDBC0
C:\Windows\System32\Drivers\TFsFltX64.sys 948E667025736C9B4C39F3C8C48057F2
C:\Windows\System32\drivers\tpm.sys 169B0A246067457FEF8A18EED7EED9D5
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TS888x64.sys FACDA017ECEC8F53FE6DDBEE81E04F5B
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSDefenseBT64.sys 9D7C94C16A83F8F4574EECD590969266
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TsNetHlpX64.sys 394508690E345D69E80EEB2E9CCCBC9B
C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSSysKit64.sys 7FB54EBFD8C226BB1984E682918158E5
C:\Windows\System32\drivers\TsUsbFlt.sys 48E828C66AB016E48F2CB4DD585315FD
C:\Windows\System32\drivers\TsUsbGD.sys 267C76EE60736EA5A1811A53FA02AABE
C:\Windows\System32\drivers\tunnel.sys 8CE72F094B822AD5EE9C3A3AFC0C16B6
C:\Windows\System32\drivers\uagp35.sys 42C546414F80BD6C0137FC3A106F8A69
C:\Windows\System32\drivers\uaspstor.sys 1686DBC81748B096232B15F16C302985
C:\Windows\System32\Drivers\UcmCx.sys 3995CC3DEDED258768B8EBC2F4C0DC73
C:\Windows\System32\drivers\UcmUcsi.sys 1C95F7CE37D9EFB90EBE987A9712356C
C:\Windows\System32\drivers\ucx01000.sys AED081772091C98173905E2DF28C223B
C:\Windows\System32\drivers\udecx.sys DCA34A111C29E4578DF2B8CEA3C7CDBD
C:\Windows\System32\DRIVERS\udfs.sys 718A956AE00CE086F381044AB66CC29C
C:\Windows\System32\drivers\UEFI.sys BA760F8E66428BA9FF1E8BFBC6248136
C:\Windows\System32\drivers\ufx01000.sys 5F0D997E6FC5A418D7673148CEF72887
C:\Windows\System32\drivers\UfxChipidea.sys 2B1DABA97DDF5365FC66EE7DEDD86A13
C:\Windows\System32\drivers\ufxsynopsys.sys DB630FC660443D63EBAB2C830C298EFE
C:\Windows\System32\drivers\uliagpkx.sys 6DE78C04BF32ECA7AF3064F53687C9A5
C:\Windows\System32\drivers\umbus.sys 67D1E0E6E4D5D33AF0AEF0E33B4DA0F4
C:\Windows\System32\drivers\umpass.sys 11680607944A719EF20E0E740785712A
C:\Windows\System32\drivers\urschipidea.sys 2410A0C20D21A25E6C01979FA886BE90
C:\Windows\System32\drivers\urscx01000.sys 6E59CE43B6BA5AA1ADCF36A4DBBB92BB
C:\Windows\System32\drivers\urssynopsys.sys E8A59FA109A22FC07E44BDFCC9727DBD
C:\Windows\System32\drivers\usbccgp.sys D8A44550ECE102B6443F5D54DCE7DAB3
C:\Windows\System32\drivers\usbcir.sys 66B3D22DAB5312FF238ABF5C6D9F8FAB
C:\Windows\System32\drivers\usbehci.sys 3E4F20DB902D2E2914F3FF3DB9772200
C:\Windows\System32\drivers\usbhub.sys 41F7F00D76904416EF1F9EFA1A4C37A2
C:\Windows\System32\drivers\UsbHub3.sys B7E1CAA9429E4C3E7E01CB35B97E1536
C:\Windows\System32\drivers\usbohci.sys DAB35CCA86F5FBE77D870A40089BC4A1
C:\Windows\System32\drivers\usbprint.sys 21162F65C7756AAECAEBED9E67D0A5FE
C:\Windows\System32\drivers\usbser.sys F259A45D6B555B14CC8365AA6BC8DC20
C:\Windows\System32\drivers\USBSTOR.SYS 8949F77132A4F8F3BA17C6727099F002
C:\Windows\System32\drivers\usbuhci.sys 8B3E458A8851F9A3B2109B1680EE1159
C:\Windows\System32\Drivers\usbvideo.sys 4B13B61CBB9CC3CB373C60B930D648F5
C:\Windows\System32\drivers\USBXHCI.SYS 325727F01F03C504CF788618A13DC266
C:\Windows\System32\drivers\vdrvroot.sys E1BE37312785A71862516F66B3FD24CE
C:\Windows\System32\drivers\VerifierExt.sys E42C0F2850735FF9D908B9DB581E6314
C:\Windows\System32\drivers\vhdmp.sys EC15FD6A28757793E2DA394CD94ABD52
C:\Windows\System32\drivers\vhf.sys D0C9632C350F46786643A069251BC249
C:\Windows\System32\drivers\vmbus.sys E886CB75DA2B6EB35469EF10135624C7
C:\Windows\System32\drivers\VMBusHID.sys 46D2EC27820EC0F798F85821E53C2942
C:\Windows\System32\drivers\volmgr.sys B9265F47E7A354BAAA0AF5CBA3F8F7CE
C:\Windows\System32\drivers\volmgrx.sys BEE9C8B72AB752B794F69C2B9B3678AA
C:\Windows\System32\drivers\volsnap.sys E1F91A727A04C9F8199D04FF3BBBF63C
C:\Windows\System32\drivers\vpci.sys F7B1B1101271E31F43CC76E890704F51
C:\Windows\System32\drivers\vsmraid.sys D48ED0A08BD2FD25A833E6AC99623091
C:\Windows\System32\drivers\vstxraid.sys 6990D4AFDF545669D4E6C232F26DE1FB
C:\Windows\System32\drivers\vwifibus.sys 1EE11F0508C58EF081F4176E66D6970B
C:\Windows\System32\drivers\vwififlt.sys 938E4EF58E42D252B742B0E243011B90
C:\Windows\System32\drivers\vwifimp.sys 3BE5AAC930447FD18D4A8255A2FEC95C
C:\Windows\System32\drivers\wacompen.sys 00C27B64C758C111E5D78A70DE6CA2B6
C:\Windows\System32\DRIVERS\wanarp.sys 8CB53620B2C2F0641DD7563EA0FDF491
C:\Windows\System32\DRIVERS\wanarp.sys 8CB53620B2C2F0641DD7563EA0FDF491
C:\Windows\system32\drivers\WdBoot.sys 069D3D6E20AD753B34FCE856F0436869
C:\Windows\System32\drivers\Wdf01000.sys 6CC727E94CD84E9720FDCDA8089CABCC
C:\Windows\system32\drivers\WdFilter.sys E3E97151A1D1E87BB2D5371F66C5F169
C:\Windows\System32\DRIVERS\wdiwifi.sys E70DDD8E2245CC67547B0861983912D8
C:\Windows\System32\Drivers\WdNisDrv.sys 07B043160399AF4009054E2EA3464BF4
C:\Windows\System32\drivers\wfplwfs.sys C11272713719922DE5711094333BD166
C:\Windows\System32\drivers\wimmount.sys EF536C54AB9281FDC4E83B07279FCFC4
C:\Windows\System32\drivers\WindowsTrustedRT.sys D8966A76408107224C6013993135DD78
C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys 8B102A7B6CE326FD4208CC7C2D183343
C:\Windows\System32\drivers\winmad.sys 4A53441C1C4D2878BEF27E381138BB2D
C:\Windows\System32\drivers\WinUSB.SYS 260907CE034FE327AC99BDA4153AB22F
C:\Windows\System32\drivers\winverbs.sys 40A3E8D729F458B2C9A8BD9380FF83D5
C:\Windows\System32\drivers\wmiacpi.sys 8F010BF65238F3F822D22BA12831796E
C:\Windows\System32\Drivers\Wof.sys 2A9650FCC696DB28E45EA8B33B99B8E6
C:\Windows\System32\DRIVERS\wpcfltr.sys 22C52D7EE7C7D0E02C8EFD8CAE8E3A71
C:\Windows\System32\drivers\WpdUpFltr.sys 1C08E424CBDD5065BB7266F8C048C1B1
C:\Windows\system32\drivers\ws2ifsl.sys 638B43D39A3D0B47024555CF1095E6F1
C:\Windows\System32\drivers\WudfPf.sys A928F25CB62232F413EE655352856E10
C:\Windows\System32\drivers\WUDFRd.sys A932391623D5CEC4EF4A2A17D3CEBFCD
C:\Windows\system32\DRIVERS\WUDFRd.sys A932391623D5CEC4EF4A2A17D3CEBFCD
C:\Windows\System32\drivers\xboxgip.sys F279536122B83FD0D8E158AA753E1B7C
C:\Windows\System32\drivers\xinputhid.sys DBACD4E4FE191D0CE7C624ACA389535E

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-23 15:48 - 2016-03-23 15:49 - 00046615 _____ C:\Users\Jovana\Downloads\FRST.txt
2016-03-23 15:48 - 2016-03-23 15:48 - 02374144 _____ (Farbar) C:\Users\Jovana\Downloads\FRST64.exe
2016-03-23 15:48 - 2016-03-23 15:48 - 00000000 ____D C:\FRST
2016-03-23 15:47 - 2016-03-23 15:47 - 01725440 _____ (Farbar) C:\Users\Jovana\Downloads\FRST.exe
2016-03-23 15:32 - 2016-03-23 15:32 - 00000000 ____D C:\AdwCleaner
2016-03-23 14:55 - 2016-03-23 14:55 - 00000000 ___HD C:\OneDriveTemp
2016-03-23 13:32 - 2016-03-23 13:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-03-23 13:22 - 2016-03-23 13:22 - 00000000 ____D C:\QMDownload
2016-03-23 13:14 - 2016-03-23 13:14 - 00001250 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-03-23 13:11 - 2016-03-23 13:09 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-23 13:10 - 2016-03-23 13:10 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-23 13:10 - 2016-03-23 13:10 - 00001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-23 13:10 - 2016-03-23 13:10 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\AVAST Software
2016-03-23 13:09 - 2016-03-23 13:12 - 00004006 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-03-23 13:09 - 2016-03-23 13:12 - 00003040 _____ C:\Windows\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-23 13:09 - 2016-03-23 13:09 - 01070904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00463744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00287016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00165344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-23 13:09 - 2016-03-23 13:09 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-23 13:08 - 2016-03-23 13:08 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-23 13:07 - 2016-03-23 13:07 - 05207096 _____ (AVAST Software) C:\Users\Jovana\Downloads\avast_free_antivirus_setup_online.exe
2016-03-23 13:07 - 2016-03-23 13:07 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 12:48 - 2016-03-23 12:48 - 00000000 ____D C:\Users\Jovana\AppData\LocalLow\TENCENT
2016-03-23 12:43 - 2016-03-23 12:43 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Synaptics
2016-03-23 12:41 - 2016-03-23 12:41 - 00038520 _____ (Tencent) C:\Windows\SysWOW64\Drivers\TS888x64.sys
2016-03-23 12:37 - 2016-03-23 12:37 - 00005120 _____ C:\Users\Jovana\AppData\Roaming\GiftBag.db
2016-03-23 12:36 - 2016-03-23 14:55 - 00000000 ____D C:\ProgramData\TXQMPC
2016-03-23 12:36 - 2016-03-23 12:36 - 00141944 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernelEx64.sys
2016-03-23 12:36 - 2016-03-23 12:36 - 00097400 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFltX64.sys
2016-03-23 12:36 - 2016-03-23 12:36 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-03-23 12:36 - 2016-03-23 12:36 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-03-23 12:36 - 2016-03-15 16:28 - 00101472 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator64.sys
2016-03-23 12:35 - 2016-03-23 13:07 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Tencent
2016-03-23 12:35 - 2016-03-23 12:38 - 00000000 ____D C:\ProgramData\Tencent
2016-03-23 12:35 - 2016-03-23 12:35 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-03-23 12:34 - 2016-03-23 13:52 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\cpuminer
2016-03-23 12:34 - 2016-03-23 12:38 - 00000702 __RSH C:\ProgramData\ntuser.pol
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\Users\Public\Thunder Network
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\gplyra
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\ProgramData\Thunder Network
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\Program Files (x86)\Winsere
2016-03-23 12:33 - 2016-03-23 12:40 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-03-23 12:33 - 2016-03-23 12:39 - 00000000 ____D C:\Users\Jovana\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-03-23 12:33 - 2016-03-23 12:33 - 00015126 _____ C:\Windows\System32\Tasks\WinTaske
2016-03-23 12:33 - 2016-03-23 12:33 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-03-23 12:33 - 2016-03-23 12:33 - 00000000 ____D C:\Program Files (x86)\WinTaske
2016-03-23 12:28 - 2016-03-23 12:28 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\WinRAR
2016-03-23 02:32 - 2016-03-23 02:32 - 00000000 ____D C:\Windows\system32\SleepStudy
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\ATI
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Local\ATI
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Local\AMD
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\ProgramData\ATI
2016-03-23 00:39 - 2016-03-23 00:39 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-03-23 00:39 - 2016-03-23 00:39 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-03-23 00:37 - 2016-03-23 00:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-23 00:32 - 2016-03-23 01:44 - 00005250 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-MU7BIH8-Jovana DESKTOP-MU7BIH8
2016-03-23 00:21 - 2016-03-23 12:39 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\qBittorrent
2016-03-23 00:21 - 2016-03-23 00:21 - 00000000 ____D C:\Users\Jovana\AppData\Local\qBittorrent
2016-03-23 00:20 - 2016-03-23 00:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2016-03-23 00:20 - 2016-03-23 00:20 - 00000000 ____D C:\Program Files (x86)\qBittorrent
2016-03-23 00:16 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\LocalLow\Adobe
2016-03-23 00:16 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Local\CEF
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\Program Files\ATI Technologies
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
2016-03-22 23:52 - 2016-03-22 23:54 - 00000000 ____D C:\ProgramData\AMD
2016-03-22 23:51 - 2016-03-23 13:54 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2016-03-22 23:51 - 2016-03-23 00:32 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-22 23:51 - 2016-03-22 23:51 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-03-22 23:51 - 2016-03-22 23:51 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-03-22 23:51 - 2015-12-16 20:07 - 00082664 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmpfd.sys
2016-03-22 23:50 - 2016-03-22 23:53 - 00000000 ____D C:\AMD
2016-03-22 23:49 - 2016-03-22 23:50 - 00000000 ____D C:\Program Files\AMD
2016-03-22 23:49 - 2016-03-22 23:49 - 00000000 ____D C:\Windows\SysWOW64\sda
2016-03-22 23:48 - 2016-03-22 23:48 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-03-22 23:48 - 2016-03-22 23:48 - 00000000 ____D C:\Program Files\Common Files\Atheros
2016-03-22 23:13 - 2016-03-22 23:13 - 00000000 ____D C:\Users\Jovana\Documents\OneNote Notebooks
2016-03-22 22:59 - 2016-03-22 22:59 - 00003972 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-03-22 22:59 - 2016-03-22 22:59 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-22 22:59 - 2016-03-22 22:59 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-03-22 22:58 - 2016-03-22 23:58 - 00000000 ____D C:\ProgramData\Adobe
2016-03-22 22:56 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Local\Adobe
2016-03-22 22:52 - 2016-03-22 22:52 - 00000000 ____D C:\Users\Jovana\AppData\Local\Microsoft Toolkit
2016-03-22 22:36 - 2016-03-23 00:54 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-03-22 22:36 - 2016-03-22 22:36 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Windows\PCHEALTH
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2016-03-22 22:32 - 2016-03-22 22:32 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2016-03-22 22:32 - 2016-03-22 22:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-03-22 22:31 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files\Microsoft Office
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 __RHD C:\MSOCache
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 ____D C:\Users\Jovana\AppData\Local\Microsoft Help
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-03-22 22:29 - 2016-03-23 14:54 - 00000000 ____D C:\Program Files\WinRAR
2016-03-22 22:02 - 2016-03-22 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2016-03-22 21:53 - 2016-03-22 21:53 - 00000000 ____D C:\Users\Jovana\AppData\Local\Conexant
2016-03-22 21:46 - 2016-03-22 21:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\PopcornTimeDesktop
2016-03-22 21:44 - 2016-03-22 22:02 - 00000000 ____D C:\Program Files (x86)\Popcorn Time
2016-03-22 18:45 - 2016-03-22 18:45 - 00000000 ____D C:\Users\Jovana\AppData\LocalLow\Temp
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\GRETECH
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\Program Files (x86)\GRETECH
2016-03-22 18:12 - 2016-03-22 18:12 - 00000000 ___RD C:\Users\Jovana\3D Objects
2016-03-22 18:02 - 2016-03-23 14:56 - 00000000 ___RD C:\Users\Jovana\Dropbox
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Users\Jovana\AppData\Local\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\iTunes
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\iPod
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-03-22 17:46 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-03-22 17:45 - 2016-03-22 17:46 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 14:40 - 2016-03-22 14:40 - 00000000 ____D C:\Users\Jovana\AppData\Local\PeerDistRepub
2016-03-22 14:40 - 2016-03-22 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-22 14:39 - 2016-03-22 14:39 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Dropbox
2016-03-22 14:38 - 2016-03-23 15:43 - 00000940 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-03-22 14:38 - 2016-03-23 14:55 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-03-22 14:38 - 2016-03-22 14:38 - 00004000 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2016-03-22 14:38 - 2016-03-22 14:38 - 00003768 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2016-03-22 14:28 - 2016-03-23 14:56 - 00000000 ____D C:\Users\Jovana\AppData\Local\Dropbox
2016-03-22 14:28 - 2016-03-22 14:40 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-03-22 14:28 - 2016-03-22 14:28 - 00000000 ____D C:\ProgramData\Dropbox
2016-03-22 13:37 - 2016-03-22 13:37 - 00000000 ____D C:\Users\Jovana\AppData\Local\ElevatedDiagnostics
2016-03-22 12:58 - 2016-03-22 12:58 - 00000000 ____D C:\Users\Jovana\Tracing
2016-03-22 12:36 - 2016-03-23 15:06 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ____D C:\ProgramData\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-22 11:26 - 2016-03-22 11:43 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome апликације
2016-03-22 11:21 - 2016-03-23 15:26 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-22 11:21 - 2016-03-23 14:55 - 00000960 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-22 11:21 - 2016-03-22 13:40 - 00000000 ____D C:\Users\Jovana\AppData\Local\Google
2016-03-22 11:21 - 2016-03-22 11:22 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-22 11:21 - 2016-03-22 11:21 - 00004022 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-22 11:21 - 2016-03-22 11:21 - 00003790 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-22 00:11 - 2016-03-22 00:11 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Macromedia
2016-03-21 23:47 - 2016-03-22 00:54 - 00000000 ____D C:\Users\Jovana\AppData\Local\Comms
2016-03-21 21:46 - 2016-03-21 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2016-03-21 21:44 - 2016-03-21 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2016-03-21 21:44 - 2016-03-21 21:44 - 00000000 ____D C:\Program Files\Dolby Digital Plus
2016-03-21 21:44 - 2014-12-09 20:11 - 00423128 _____ (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
2016-03-21 21:44 - 2014-10-20 14:54 - 00207576 _____ (Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
2016-03-21 21:44 - 2013-12-24 15:35 - 00001724 _____ C:\Windows\system32\Drivers\SamSfPa.dat
2016-03-21 21:43 - 2016-03-22 21:53 - 00000000 ____D C:\ProgramData\Conexant
2016-03-21 21:43 - 2016-03-21 21:44 - 00000000 ____D C:\Program Files\CONEXANT
2016-03-21 21:43 - 2016-03-21 21:43 - 00001047 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2016-03-21 21:43 - 2016-03-21 21:43 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-03-21 21:43 - 2015-10-29 19:43 - 07043584 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons081a.dll
2016-03-21 21:43 - 2015-10-29 19:41 - 07043584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsLexicons081a.dll
2016-03-21 21:43 - 2015-10-29 19:38 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\NlsData081a.dll
2016-03-21 21:43 - 2015-10-29 19:36 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData081a.dll
2016-03-21 21:43 - 2015-10-29 19:29 - 01909760 _____ (Microsoft Corporation) C:\Windows\system32\MLS2.dll
2016-03-21 21:43 - 2015-10-29 19:27 - 01870848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MLS2.dll
2016-03-21 21:29 - 2016-03-23 15:41 - 00000000 ___RD C:\Users\Jovana\OneDrive
2016-03-21 21:29 - 2016-03-21 21:42 - 00002366 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-21 21:29 - 2016-03-21 21:29 - 00000000 ____D C:\Users\Jovana\AppData\Local\MicrosoftEdge
2016-03-21 21:28 - 2016-03-21 21:28 - 00000000 ____D C:\Users\Jovana\AppData\Local\ActiveSync
2016-03-21 21:27 - 2016-03-21 21:27 - 00000000 ____D C:\Users\Jovana\AppData\Local\Publishers
2016-03-21 21:26 - 2016-03-23 12:38 - 00000000 ____D C:\Users\Jovana\AppData\Local\VirtualStore
2016-03-21 21:26 - 2016-03-23 11:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\Packages
2016-03-21 21:26 - 2016-03-23 01:26 - 00000000 ____D C:\Users\Jovana
2016-03-21 21:26 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Adobe
2016-03-21 21:26 - 2016-03-21 21:26 - 00000020 ___SH C:\Users\Jovana\ntuser.ini
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\My Documents
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Videos
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Pictures
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Music
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 ____D C:\Users\Jovana\AppData\Local\TileDataLayer
2016-03-21 21:24 - 2016-03-22 21:59 - 00000000 ____D C:\Program Files\KMSpico
2016-03-21 21:24 - 2016-03-21 21:24 - 00004608 _____ C:\Windows\SECOH-QAD.exe
2016-03-21 21:24 - 2016-03-21 21:24 - 00003584 _____ C:\Windows\SECOH-QAD.dll
2016-03-09 10:26 - 2016-03-09 10:26 - 00000000 ____D C:\Windows\CSC
2016-03-09 10:22 - 2016-03-09 10:22 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files\MSBuild
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-03-09 09:49 - 2015-10-24 02:47 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:47 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:47 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2016-03-09 09:49 - 2015-10-24 02:46 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2016-03-09 09:49 - 2015-10-24 02:45 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-09 09:43 - 2015-12-09 04:39 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-03-09 09:41 - 2016-03-09 09:42 - 00000000 ____D C:\Windows\system32\MRT
2016-03-09 09:41 - 2016-03-09 09:41 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-03-09 09:41 - 2016-02-24 10:51 - 07474528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-03-09 09:41 - 2016-02-24 10:48 - 00713568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-03-09 09:41 - 2016-02-24 10:47 - 01173344 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-03-09 09:41 - 2016-02-24 10:40 - 00513888 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-03-09 09:41 - 2016-02-24 10:28 - 03449168 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2016-03-09 09:41 - 2016-02-24 09:46 - 06607080 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2016-03-09 09:41 - 2016-02-24 09:11 - 01997152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-03-09 09:41 - 2016-02-24 09:06 - 05242496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-03-09 09:41 - 2016-02-24 07:11 - 03593216 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-03-09 09:41 - 2016-02-24 07:00 - 02273792 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-03-09 09:41 - 2016-02-24 06:20 - 22376960 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-03-09 09:41 - 2016-02-24 06:18 - 18677760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-03-09 09:41 - 2016-02-24 06:12 - 19339776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-03-09 09:41 - 2016-02-24 06:12 - 05321728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 09:41 - 2016-02-24 06:10 - 24600576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-03-09 09:41 - 2016-02-24 06:09 - 06972416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-03-09 09:41 - 2016-02-24 06:05 - 12586496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-03-09 09:41 - 2016-02-24 06:03 - 14252544 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-03-09 09:41 - 2016-02-24 05:59 - 05661696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-03-09 09:41 - 2016-02-24 05:55 - 07835648 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-03-09 09:41 - 2016-02-23 12:25 - 01818696 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-03-09 09:41 - 2016-02-23 11:34 - 01542816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-03-09 09:41 - 2016-02-23 11:32 - 08705672 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-03-09 09:41 - 2016-02-23 11:32 - 00369912 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-03-09 09:41 - 2016-02-23 11:31 - 00536256 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-03-09 09:41 - 2016-02-23 11:31 - 00408120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-03-09 09:41 - 2016-02-23 11:21 - 22564328 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-03-09 09:41 - 2016-02-23 10:38 - 06952088 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-09 09:41 - 2016-02-23 10:30 - 02919320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-03-09 09:41 - 2016-02-23 10:27 - 21124344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-03-09 09:41 - 2016-02-23 09:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\wininetlui.dll
2016-03-09 09:41 - 2016-02-23 09:58 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-03-09 09:41 - 2016-02-23 09:28 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2016-03-09 09:41 - 2016-02-23 09:09 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-03-09 09:41 - 2016-02-23 09:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininetlui.dll
2016-03-09 09:41 - 2016-02-23 09:06 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-03-09 09:41 - 2016-02-23 09:02 - 01318912 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2016-03-09 09:41 - 2016-02-23 09:00 - 02624512 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2016-03-09 09:41 - 2016-02-23 08:58 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2016-03-09 09:41 - 2016-02-23 08:52 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2016-03-09 09:41 - 2016-02-23 08:30 - 01731584 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-03-09 09:41 - 2016-02-23 08:24 - 02755584 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-03-09 09:41 - 2016-02-23 08:22 - 01944576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-03-09 09:41 - 2016-02-23 08:21 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-03-09 09:41 - 2016-02-23 08:17 - 02635264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-03-09 09:41 - 2016-02-23 07:59 - 01500672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-03-09 09:41 - 2016-02-23 07:55 - 04894208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-03-09 09:41 - 2016-02-23 07:55 - 02229760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-03-09 09:41 - 2016-02-23 07:52 - 11545600 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-03-09 09:41 - 2016-02-23 07:50 - 09919488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-03-09 09:41 - 2016-02-23 07:39 - 13382656 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-03-09 09:41 - 2016-02-23 07:36 - 12125696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-03-09 09:41 - 2016-02-23 07:36 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-03-09 09:41 - 2016-02-23 07:35 - 07533568 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-03-09 09:41 - 2016-02-23 07:28 - 06740992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2016-03-09 09:41 - 2016-02-09 04:24 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2016-03-09 09:41 - 2016-02-09 04:07 - 01626624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2016-03-09 09:41 - 2016-02-09 04:04 - 01946624 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2016-03-09 09:40 - 2016-03-01 06:31 - 00848168 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-03-09 09:40 - 2016-03-01 06:22 - 00709688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-03-09 09:40 - 2016-02-24 10:52 - 01997328 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-03-09 09:40 - 2016-02-24 10:34 - 01613664 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-03-09 09:40 - 2016-02-24 10:15 - 01557768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-03-09 09:40 - 2016-02-24 09:58 - 00794888 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-03-09 09:40 - 2016-02-24 09:54 - 00127840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-03-09 09:40 - 2016-02-24 09:51 - 01322248 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-03-09 09:40 - 2016-02-24 09:50 - 00808800 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-03-09 09:40 - 2016-02-24 09:43 - 00625000 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2016-03-09 09:40 - 2016-02-24 09:39 - 00358752 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-03-09 09:40 - 2016-02-24 09:39 - 00141560 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2016-03-09 09:40 - 2016-02-24 09:19 - 00670928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-03-09 09:40 - 2016-02-24 09:14 - 00216416 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00957608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00703840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-03-09 09:40 - 2016-02-24 09:11 - 00652392 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00394080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-03-09 09:40 - 2016-02-24 09:11 - 00258280 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2016-03-09 09:40 - 2016-02-24 09:10 - 00630632 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2016-03-09 09:40 - 2016-02-24 09:10 - 00576864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-03-09 09:40 - 2016-02-24 09:09 - 00640472 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2016-03-09 09:40 - 2016-02-24 09:09 - 00147808 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2016-03-09 09:40 - 2016-02-24 08:59 - 00294752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-03-09 09:40 - 2016-02-24 08:39 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTypeHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 08:39 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\ExtrasXmlParser.dll
2016-03-09 09:40 - 2016-02-24 08:38 - 00187744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2016-03-09 09:40 - 2016-02-24 08:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2016-03-09 09:40 - 2016-02-24 08:37 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataLanguageUtil.dll
2016-03-09 09:40 - 2016-02-24 08:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenanceClient.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00540752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2016-03-09 09:40 - 2016-02-24 08:35 - 00523752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00220064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-03-09 09:40 - 2016-02-24 08:33 - 00538736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2016-03-09 09:40 - 2016-02-24 08:33 - 00141664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2016-03-09 09:40 - 2016-02-24 08:31 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-03-09 09:40 - 2016-02-24 08:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2016-03-09 09:40 - 2016-02-24 08:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\POSyncServices.dll
2016-03-09 09:40 - 2016-02-24 08:23 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
2016-03-09 09:40 - 2016-02-24 08:23 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-03-09 09:40 - 2016-02-24 08:23 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\UserDataPlatformHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 08:22 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00195072 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2016-03-09 09:40 - 2016-02-24 08:19 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2016-03-09 09:40 - 2016-02-24 08:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2016-03-09 09:40 - 2016-02-24 08:15 - 00365568 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-03-09 09:40 - 2016-02-24 08:14 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll
2016-03-09 09:40 - 2016-02-24 08:13 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
2016-03-09 09:40 - 2016-02-24 08:12 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\cemapi.dll
2016-03-09 09:40 - 2016-02-24 08:12 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\PhoneCallHistoryApis.dll
2016-03-09 09:40 - 2016-02-24 08:10 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
2016-03-09 09:40 - 2016-02-24 08:09 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll
2016-03-09 09:40 - 2016-02-24 08:09 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll
2016-03-09 09:40 - 2016-02-24 08:07 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll
2016-03-09 09:40 - 2016-02-24 08:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2016-03-09 09:40 - 2016-02-24 08:03 - 00088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2016-03-09 09:40 - 2016-02-24 08:02 - 00161280 _____ (Microsoft Corporation) C:\Windows\system32\CallHistoryClient.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\profext.dll
2016-03-09 09:40 - 2016-02-24 08:00 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2016-03-09 09:40 - 2016-02-24 07:58 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\scapi.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00790528 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExtrasXmlParser.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2016-03-09 09:40 - 2016-02-24 07:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 07:53 - 00089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2016-03-09 09:40 - 2016-02-24 07:53 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 09:40 - 2016-02-24 07:52 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2016-03-09 09:40 - 2016-02-24 07:52 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 09:40 - 2016-02-24 07:51 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-03-09 09:40 - 2016-02-24 07:49 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
2016-03-09 09:40 - 2016-02-24 07:47 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-03-09 09:40 - 2016-02-24 07:46 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 01713664 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00915456 _____ (Microsoft Corporation) C:\Windows\system32\configurationclient.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\POSyncServices.dll
2016-03-09 09:40 - 2016-02-24 07:43 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2016-03-09 09:40 - 2016-02-24 07:43 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2016-03-09 09:40 - 2016-02-24 07:42 - 00954368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2016-03-09 09:40 - 2016-02-24 07:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2016-03-09 09:40 - 2016-02-24 07:41 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2016-03-09 09:40 - 2016-02-24 07:41 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 01224704 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 07:39 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-03-09 09:40 - 2016-02-24 07:39 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2016-03-09 09:40 - 2016-02-24 07:38 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2016-03-09 09:40 - 2016-02-24 07:36 - 01847808 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2016-03-09 09:40 - 2016-02-24 07:34 - 00938496 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2016-03-09 09:40 - 2016-02-24 07:34 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-03-09 09:40 - 2016-02-24 07:32 - 00223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
2016-03-09 09:40 - 2016-02-24 07:32 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
2016-03-09 09:40 - 2016-02-24 07:31 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cemapi.dll
2016-03-09 09:40 - 2016-02-24 07:31 - 00169984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll
2016-03-09 09:40 - 2016-02-24 07:25 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2016-03-09 09:40 - 2016-02-24 07:23 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CallHistoryClient.dll
2016-03-09 09:40 - 2016-02-24 07:22 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\profext.dll
2016-03-09 09:40 - 2016-02-24 07:21 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 09:40 - 2016-02-24 07:21 - 00168448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 00184832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll
2016-03-09 09:40 - 2016-02-24 07:17 - 00369664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2016-03-09 09:40 - 2016-02-24 07:16 - 00394752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2016-03-09 09:40 - 2016-02-24 07:13 - 00540160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 01443328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRHInproc.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00949248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00890368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-03-09 09:40 - 2016-02-24 07:04 - 01497088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2016-03-09 09:40 - 2016-02-24 07:03 - 00769536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2016-03-09 09:40 - 2016-02-24 07:01 - 01831936 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2016-03-09 09:40 - 2016-02-24 07:00 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2016-03-09 09:40 - 2016-02-24 06:57 - 02158592 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-03-09 09:40 - 2016-02-24 06:55 - 01996288 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-03-09 09:40 - 2016-02-24 06:43 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
2016-03-09 09:40 - 2016-02-24 06:34 - 01707520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2016-03-09 09:40 - 2016-02-24 06:22 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll
2016-03-09 09:40 - 2016-02-23 12:29 - 01030416 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-03-09 09:40 - 2016-02-23 12:29 - 00874968 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2016-03-09 09:40 - 2016-02-23 12:27 - 02654872 _____ C:\Windows\system32\CoreUIComponents.dll
2016-03-09 09:40 - 2016-02-23 12:27 - 01317640 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-03-09 09:40 - 2016-02-23 12:27 - 01141504 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-03-09 09:40 - 2016-02-23 12:25 - 02152288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-03-09 09:40 - 2016-02-23 12:25 - 00563552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2016-03-09 09:40 - 2016-02-23 12:15 - 00779384 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2016-03-09 09:40 - 2016-02-23 12:08 - 00989536 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2016-03-09 09:40 - 2016-02-23 11:34 - 01859960 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2016-03-09 09:40 - 2016-02-23 11:33 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-03-09 09:40 - 2016-02-23 11:33 - 00389992 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 02544264 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 01152328 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 00498448 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 01017032 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 00819648 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 00476728 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2016-03-09 09:40 - 2016-02-23 11:25 - 03671888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-03-09 09:40 - 2016-02-23 11:22 - 00572272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2016-03-09 09:40 - 2016-02-23 11:17 - 00146272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-03-09 09:40 - 2016-02-23 10:45 - 02773096 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2016-03-09 09:40 - 2016-02-23 10:40 - 00430944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-03-09 09:40 - 2016-02-23 10:39 - 00502112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 02180136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00980352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00895080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00882720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00450912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00420928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2016-03-09 09:40 - 2016-02-23 10:37 - 00713824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:32 - 00791744 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-03-09 09:40 - 2016-02-23 10:27 - 00376536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
2016-03-09 09:40 - 2016-02-23 10:25 - 00534368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2016-03-09 09:40 - 2016-02-23 10:20 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\XblGameSave.dll
2016-03-09 09:40 - 2016-02-23 10:20 - 00238592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
2016-03-09 09:40 - 2016-02-23 10:19 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xinputhid.sys
2016-03-09 09:40 - 2016-02-23 10:17 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2016-03-09 09:40 - 2016-02-23 10:12 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\provpackageapidll.dll
2016-03-09 09:40 - 2016-02-23 10:10 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\WiFiConfigSP.dll
2016-03-09 09:40 - 2016-02-23 10:07 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2016-03-09 09:40 - 2016-02-23 10:07 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2016-03-09 09:40 - 2016-02-23 10:06 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\flvprophandler.dll
2016-03-09 09:40 - 2016-02-23 10:01 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rasl2tp.sys
2016-03-09 09:40 - 2016-02-23 10:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-09 09:40 - 2016-02-23 10:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll
2016-03-09 09:40 - 2016-02-23 09:58 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\irmon.dll
2016-03-09 09:40 - 2016-02-23 09:57 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2016-03-09 09:40 - 2016-02-23 09:56 - 02186864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2016-03-09 09:40 - 2016-02-23 09:55 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2016-03-09 09:40 - 2016-02-23 09:53 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
2016-03-09 09:40 - 2016-02-23 09:53 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\ngckeyenum.dll
2016-03-09 09:40 - 2016-02-23 09:52 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2016-03-09 09:40 - 2016-02-23 09:51 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
2016-03-09 09:40 - 2016-02-23 09:50 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2016-03-09 09:40 - 2016-02-23 09:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\AppCapture.dll
2016-03-09 09:40 - 2016-02-23 09:48 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerClient.dll
2016-03-09 09:40 - 2016-02-23 09:40 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SMSRouter.dll
2016-03-09 09:40 - 2016-02-23 09:39 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2016-03-09 09:40 - 2016-02-23 09:38 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll
2016-03-09 09:40 - 2016-02-23 09:38 - 00287712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-03-09 09:40 - 2016-02-23 09:36 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\QuickActionsDataModel.dll
2016-03-09 09:40 - 2016-02-23 09:34 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\wifiprofilessettinghandler.dll
2016-03-09 09:40 - 2016-02-23 09:34 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2016-03-09 09:40 - 2016-02-23 09:33 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2016-03-09 09:40 - 2016-02-23 09:32 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2016-03-09 09:40 - 2016-02-23 09:31 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2016-03-09 09:40 - 2016-02-23 09:29 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SmsRouterSvc.dll
2016-03-09 09:40 - 2016-02-23 09:27 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll
2016-03-09 09:40 - 2016-02-23 09:26 - 00372224 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2016-03-09 09:40 - 2016-02-23 09:23 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2016-03-09 09:40 - 2016-02-23 09:22 - 00567808 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00847360 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00606720 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00493568 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-09 09:40 - 2016-02-23 09:19 - 00948736 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
2016-03-09 09:40 - 2016-02-23 09:19 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2016-03-09 09:40 - 2016-02-23 09:18 - 00557056 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2016-03-09 09:40 - 2016-02-23 09:14 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2016-03-09 09:40 - 2016-02-23 09:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2016-03-09 09:40 - 2016-02-23 09:12 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2016-03-09 09:40 - 2016-02-23 09:11 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2016-03-09 09:40 - 2016-02-23 09:10 - 00997376 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2016-03-09 09:40 - 2016-02-23 09:10 - 00474624 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2016-03-09 09:40 - 2016-02-23 09:09 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2016-03-09 09:40 - 2016-02-23 09:09 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-03-09 09:40 - 2016-02-23 09:06 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-03-09 09:40 - 2016-02-23 09:05 - 00161280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2016-03-09 09:40 - 2016-02-23 09:04 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2016-03-09 09:40 - 2016-02-23 09:04 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2016-03-09 09:40 - 2016-02-23 09:04 - 00382464 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-03-09 09:40 - 2016-02-23 09:02 - 00755712 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2016-03-09 09:40 - 2016-02-23 09:02 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-03-09 09:40 - 2016-02-23 08:58 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll
2016-03-09 09:40 - 2016-02-23 08:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerServer.dll
2016-03-09 09:40 - 2016-02-23 08:58 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll
2016-03-09 09:40 - 2016-02-23 08:57 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TimeBrokerClient.dll
2016-03-09 09:40 - 2016-02-23 08:50 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll
2016-03-09 09:40 - 2016-02-23 08:49 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2016-03-09 09:40 - 2016-02-23 08:48 - 00838144 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2016-03-09 09:40 - 2016-02-23 08:47 - 00157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WiFiDisplay.dll
2016-03-09 09:40 - 2016-02-23 08:38 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2016-03-09 09:40 - 2016-02-23 08:37 - 01118208 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-03-09 09:40 - 2016-02-23 08:37 - 00613376 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00713728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00379392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-09 09:40 - 2016-02-23 08:35 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2016-03-09 09:40 - 2016-02-23 08:31 - 00585216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2016-03-09 09:40 - 2016-02-23 08:30 - 00646656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-09 09:40 - 2016-02-23 08:29 - 00349696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2016-03-09 09:40 - 2016-02-23 08:28 - 00555520 _____ (Microsoft Corporation) C:\Windows\system32\SyncController.dll
2016-03-09 09:40 - 2016-02-23 08:28 - 00256512 _____ (Microsoft Corporation) C:\Windows\system32\accountaccessor.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 04827136 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 01105920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2016-03-09 09:40 - 2016-02-23 08:21 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-09 09:40 - 2016-02-23 08:20 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll
2016-03-09 09:40 - 2016-02-23 08:14 - 00990720 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2016-03-09 09:40 - 2016-02-23 08:11 - 01390080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2016-03-09 09:40 - 2016-02-23 08:05 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2016-03-09 09:40 - 2016-02-23 08:01 - 02295808 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2016-03-09 09:40 - 2016-02-23 07:58 - 00450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncController.dll
2016-03-09 09:40 - 2016-02-23 07:56 - 04412928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-03-09 09:40 - 2016-02-23 07:53 - 01799168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2016-03-09 09:40 - 2016-02-23 07:51 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2016-03-09 09:40 - 2016-02-23 07:42 - 03425792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-03-09 09:40 - 2016-02-23 07:41 - 02912256 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2016-03-09 09:40 - 2016-02-23 07:39 - 02581504 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-03-09 09:40 - 2016-02-23 07:33 - 02604032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2016-03-09 09:40 - 2016-02-23 07:32 - 02793472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-03-09 09:40 - 2016-02-23 07:30 - 02061312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-03-09 09:40 - 2016-02-09 05:28 - 00277856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2016-03-09 09:40 - 2016-02-09 05:13 - 00185184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2016-03-09 09:40 - 2016-02-09 04:18 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2016-03-09 09:40 - 2016-02-09 04:18 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2016-03-09 09:40 - 2016-02-09 04:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2016-03-09 09:31 - 2016-03-23 15:01 - 00879220 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\My Documents
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Documents and Settings
2016-03-09 09:18 - 2016-03-09 10:24 - 00000000 ____D C:\Windows\Panther
2016-02-13 14:22 - 2016-03-22 00:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-13 14:22 - 2016-02-13 14:22 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-02-13 14:17 - 2016-02-13 14:17 - 00000000 ____D C:\ProgramData\USOShared
2016-02-13 14:16 - 2016-03-23 14:54 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-13 14:16 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2016-02-13 14:12 - 2016-03-23 12:40 - 00342232 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-13 14:11 - 2016-02-13 14:12 - 00000000 ____D C:\Windows\ServiceProfiles
2016-02-13 14:05 - 2015-10-30 08:18 - 00032200 _____ C:\Windows\Professional.xml
2016-02-13 14:04 - 2016-03-22 22:36 - 00000000 ____D C:\Windows\ShellNew
2016-02-13 14:04 - 2016-03-09 09:45 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-13 14:04 - 2016-02-13 14:04 - 00000000 __SHD C:\Windows\BitLockerDiscoveryVolumeContents
2016-02-13 13:55 - 2016-03-21 21:43 - 00000000 ____D C:\Windows\OCR
2016-02-13 13:55 - 2016-02-13 13:55 - 00000000 ____D C:\Windows\SKB
2016-02-13 13:54 - 2016-02-13 13:54 - 16986112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 13018624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 07979008 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 07199232 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 06572032 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 06297088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 05503488 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 05202944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 04759040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 04502352 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 04064320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 03993600 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 03355136 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02843136 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02756096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-02-13 13:54 - 2016-02-13 13:54 - 02756096 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-02-13 13:54 - 2016-02-13 13:54 - 02680320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02606824 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02597888 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02587696 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02444288 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02155008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02127360 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-02-13 13:54 - 2016-02-13 13:54 - 02057216 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02050048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-02-13 13:54 - 2016-02-13 13:54 - 02026736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 02001408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01860096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01824264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01814528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01804664 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01750440 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 01717248 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01674240 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01648640 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01594408 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01582080 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 01542656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01500672 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 01467392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01415200 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01399224 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01387520 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01371792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01337240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01309376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01299504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01281376 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01270072 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01268736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01268736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 01174008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01118208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01092456 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01089880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01070080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 01056256 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01042432 _____ (Microsoft Corporation) C:\Windows\system32\BingOnlineServices.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01035776 _____ (Microsoft Corporation) C:\Windows\system32\XboxNetApiSvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00973664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00970752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00938496 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00931328 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00925064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00911648 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00900608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00884736 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00871936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00858952 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00824320 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00820704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00803840 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00799744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00794112 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00792064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00786696 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00785088 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00784896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingOnlineServices.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00704000 _____ (Microsoft Corporation) C:\Windows\system32\CellularAPI.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00701384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00698208 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00695752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00687616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00683008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00678912 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00675064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00671472 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00652312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00647168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\uReFS.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\PhoneProviders.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00613888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00610816 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00604928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00604672 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00586208 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00586080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00578912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00572928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00569856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00558592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00538632 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00526856 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00523616 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00517632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00516544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00511320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00499432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00475648 _____ (Microsoft Corporation) C:\Windows\system32\DDDS.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00472576 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00470528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00462760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00454056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00440152 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00431240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00421888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00412512 _____ (Microsoft Corporation) C:\Windows\system32\wifitask.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00409088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00405568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00389120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00387072 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00383488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00366224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00350720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00346112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00337840 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00334736 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00334336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-02-13 13:54 - 2016-02-13 13:54 - 00304752 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00299008 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00296488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00289248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00264544 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00264192 _____ (Nokia) C:\Windows\system32\NmaDirect.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00260608 _____ C:\Windows\system32\MTFServer.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00245840 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthLEEnum.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00241664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00235008 _____ C:\Windows\system32\MTF.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-02-13 13:54 - 2016-02-13 13:54 - 00234504 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00208176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00205824 _____ (Nokia) C:\Windows\SysWOW64\NmaDirect.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00203264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassam.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00202472 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\SimCfg.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\mdmmigrator.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\ProximityCommon.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00166912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00162816 _____ C:\Windows\SysWOW64\MTF.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00161632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\SimAuth.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SimCfg.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\FilterDS.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2016-02-13 13:54 - 2016-02-13 13:54 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ETWCoreUIComponentsResources.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00138240 _____ (Microsoft Corporation) C:\Windows\system32\ETWCoreUIComponentsResources.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\wificonnapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\winbio.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SimAuth.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2016-02-13 13:54 - 2016-02-13 13:54 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ProximityCommon.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00119320 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00118624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\capimg.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00116728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00115040 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MapControls.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MapControls.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00110032 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\rasauto.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinelsa.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00100160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-02-13 13:54 - 2016-02-13 13:54 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\winhttpcom.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00095072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winbio.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00092352 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.V2.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\MapsCSP.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00088392 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapsBtSvc.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\tzautoupdate.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00085320 _____ (Microsoft Corporation) C:\Windows\system32\OpenWith.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00084832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00081112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpenWith.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00080600 _____ (Microsoft Corporation) C:\Windows\system32\wwapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttpcom.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\cfgbkend.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\RMSRoamingSecurity.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\EditBufferTestHook.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\mssign32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\wwancfg.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00073360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\MosStorage.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppCapture.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManagerProxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MosHostClient.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\ihvrilproxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00063528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wwapi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgbkend.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssign32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthTokenBrokerExt.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EditBufferTestHook.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00058408 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosStorage.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosResource.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\MosResource.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rilproxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\Wwanpref.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00051680 _____ (Microsoft Corporation) C:\Windows\system32\SensorsUtilsV2.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosHostClient.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\wsplib.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\usermgrcli.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.proxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mapstoasttask.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthManagerProxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\ztrace_maps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\BackgroundTransferHost.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCoreRes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCoreRes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wimmount.sys
2016-02-13 13:54 - 2016-02-13 13:54 - 00035656 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usermgrcli.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BackgroundTransferHost.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00032040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ztrace_maps.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\tetheringconfigsp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WordBreakers.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\mapsupdatetask.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\nativemap.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.proxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00026408 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\rasautou.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasautou.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\rasadhlp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\IcsEntitlementHost.exe
2016-02-13 13:54 - 2016-02-13 13:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\sscoreext.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\rastlsext.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasadhlp.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvcProxy.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastlsext.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosTrace.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MosHost.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosHost.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\readingviewresources.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlStringsRes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\MapControlStringsRes.dll
2016-02-13 13:54 - 2016-02-13 13:54 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\winrm
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\WCN
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\SysWOW64\0409
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\system32\winrm
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\system32\WCN
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\system32\slmgr
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\system32\0409
2016-02-13 13:51 - 2016-02-13 13:51 - 00000000 ____D C:\Windows\DigitalLocker

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-23 15:01 - 2015-10-30 08:21 - 00000000 ____D C:\Windows\INF
2016-03-23 13:54 - 2015-10-30 07:28 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-03-23 12:34 - 2015-10-30 08:24 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-03-23 12:34 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2016-03-23 11:55 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\AppReadiness
2016-03-23 11:46 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-23 00:53 - 2015-10-30 08:11 - 00000000 ____D C:\Windows\CbsTemp
2016-03-23 00:52 - 2015-10-30 08:24 - 00000167 _____ C:\Windows\win.ini
2016-03-23 00:52 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System
2016-03-23 00:51 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-22 22:35 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-03-22 21:20 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\NDF
2016-03-22 11:14 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\appcompat
2016-03-21 21:26 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2016-03-21 21:23 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\rescache
2016-03-09 10:20 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\Sysprep
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 __RSD C:\Windows\Media
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ___RD C:\Windows\PurchaseDialog
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\bcastdvr
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-09 09:45 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-03-09 09:45 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\Dism
2016-03-08 08:12 - 2015-10-30 08:26 - 00829944 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:12 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2016-03-23 12:37 - 2016-03-23 12:37 - 0005120 _____ () C:\Users\Jovana\AppData\Roaming\GiftBag.db
2016-03-21 21:43 - 2016-03-21 21:43 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Jovana\AppData\Local\Temp\qqpcmgr_v11.4.17347.218_45285_Silence.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== BCD ================================

Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {current}
resumeobject {a22a39f3-7eae-11e5-b8d6-9d6d256076f2}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30

Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \Windows\system32\winload.exe
description Windows 10
locale en-US
inherit {bootloadersettings}
recoverysequence {a22a39f5-7eae-11e5-b8d6-9d6d256076f2}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \Windows
resumeobject {a22a39f3-7eae-11e5-b8d6-9d6d256076f2}
nx OptIn
bootmenupolicy Standard

Windows Boot Loader
-------------------
identifier {a22a39f5-7eae-11e5-b8d6-9d6d256076f2}
device ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{a22a39f6-7eae-11e5-b8d6-9d6d256076f2}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[C:]\Recovery\WindowsRE\Winre.wim,{a22a39f6-7eae-11e5-b8d6-9d6d256076f2}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Resume from Hibernate
---------------------
identifier {a22a39f3-7eae-11e5-b8d6-9d6d256076f2}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {a22a39f5-7eae-11e5-b8d6-9d6d256076f2}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No

Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes

EMS Settings
------------
identifier {emssettings}
bootems No

Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200

RAM Defects
-----------
identifier {badmemory}

Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}

Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}

Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200


Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}

Device options
--------------
identifier {a22a39f6-7eae-11e5-b8d6-9d6d256076f2}
description Windows Recovery
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\WindowsRE\boot.sdi



LastRegBack: 2016-03-09 09:18

==================== End of FRST.txt ============================

mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Napisano: 23 Mar 2016 16:51

Ubuduce, jako je bitno da pratis uputstva bas onako kako pise. Nije bilo naglazeno da oznacis Drivers MD5 i BCD.

Idemo dalje ...


Preuzmi skript pod nazivom 117539_1314794845_FixList.txt sa ovog linka i sacuvaj ga na Desktop;
https://www.mycity.rs/must-login.png

Promeni naziv (rename) sa 117539_1314794845_FixList.txt na samo FixList.txt
(znaci bitno je da se notepad zove samo fixlist.txt, bez brojeva)

[helper side note: fixlist je unicode format]




Arrow Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Arrow Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

Dopuna: 23 Mar 2016 16:53

Da, zaboravih ...

FRST je pokrenut iz download foldera. FRST treba da se nalazi na Desktop. Prebaci (cut) FRST na radnu povrsinu.

offline
  • Pridružio: 23 Mar 2016
  • Poruke: 11

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Jovana (2016-03-23 16:55:51) Run:1
Running from C:\Users\Jovana\Desktop
Loaded Profiles: Jovana (Available Profiles: Jovana)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
Unlock: C:\Program Files (x86)\Tencent
Unlock: C:\Program Files (x86)\Common Files\Tencent
Unlock: C:\Program Files (x86)\SearchesToYesbnd
Unlock: C:\Program Files (x86)\Winsere
Unlock: C:\Windows\system32\Drivers\TAOAccelerator64.sys
Unlock: C:\Windows\system32\Drivers\TAOKernelEx64.sys
Unlock: C:\Windows\System32\Drivers\TFsFltX64.sys

CreateRestorePoint:
AV: 电脑管家系统防护 (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5}
AS: 电脑管家系统防护 (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48}
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"

CloseProcesses:
HKLM\...\Run: [cpuminer] => C:\Users\Jovana\AppData\Roaming\cpuminer\cpm.exe [1402880 2016-02-29] ()
Task: {CBD5CF96-61AA-43CB-A3BA-25D5C2344439} - System32\Tasks\WinTaske => C:\Program Files (x86)\WinTaske\WinTaske\WinTaske.exe [2016-03-15] ()
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMGCShellExt64.dll [2016-03-23] (Tencent)
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSWebMon64.dat [2016-03-23] (Tencent)
BHO-x32: Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll [2016-03-23] (Tencent Technology (Shenzhen) Company Limited)
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=C88FAF2E2E2E58D2C5E6F1FFABD17F9F&v=20160315&ts=AHEpC3QnAXUmBU.."
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default
S2 ggbugreport; C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe [1592888 2016-03-15] ()
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe [313936 2016-03-23] (Tencent)
U2 QQRepair19e7; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair19e7 [136512 2016-03-23] ()
S2 QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC [136512 2016-03-23] ()
S2 Winsere; C:\Program Files (x86)\Winsere\Winsere\Winsere.exe [306736 2016-03-15] ()
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUdisk64.sys [184536 2016-03-02] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQSysMonX64.sys [152184 2016-03-23] (电脑管家)
R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\softaal64.sys [44664 2016-03-23] (Tencent)
R1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [168568 2016-03-23] ()
S3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [101472 2016-03-15] (Tencent)
R2 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernelEx64.sys [141944 2016-03-23] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [97400 2016-03-23] (电脑管家)
S3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TS888x64.sys [38520 2016-03-23] (Tencent)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSDefenseBT64.sys [28984 2016-03-23] (Tencent)
R2 tsnethlpx64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TsNetHlpX64.sys [57976 2016-03-23] ()
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSSysKit64.sys [96888 2016-03-23] (电脑管家)

RemoveProxy:
FirewallRules: [{74E592A2-4B5D-4F10-B73C-85B3DD4520EB}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCmgrInstallGuide.exe
FirewallRules: [{FBC1B302-EB2A-4690-A11B-85AAFCF4E66E}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCTray.exe
FirewallRules: [{DF7FBCDC-BEE2-4E67-AF10-77C241F699B8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCMgr.exe
FirewallRules: [{2CF58E49-DAB3-4081-B98B-35C3A73E8B0B}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe
FirewallRules: [{6944578A-6FBB-453B-889C-F658DF699172}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMDL.exe
FirewallRules: [{A7296E56-11EF-4EC5-BBB1-48196F249C3E}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\bugreport.exe
FirewallRules: [{DAFBAB84-7D01-48F1-AB47-E8336522A262}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCFileOpen.exe
FirewallRules: [{BCA7BDF5-85A3-4A26-B835-8A279CD57129}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCLeakScan.exe
FirewallRules: [{A6DEBD30-B1B2-4A00-A1BC-3D062D3A9179}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPConfig.exe
FirewallRules: [{E4F5450F-B116-4533-853F-7CCCD074AE5C}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{8C415960-3079-4F90-91E0-826E68E0157C}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSoftMgr.exe
FirewallRules: [{F76DAA61-3109-403D-9579-A0B6D1FCA0C1}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
FirewallRules: [{4BE630BF-D741-4500-86BC-55D55F32FCD1}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\plugins\QMNetMon\QQPCNetFlow.exe
FirewallRules: [{E26B07F4-6495-4BBA-814D-347FC74B60EE}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCBTU.exe
FirewallRules: [{E195FDF8-E009-4569-B8D8-21348013629C}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCClinic.exe
FirewallRules: [{874E44DF-5D8B-436A-81E1-DBE9B004733A}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCLaunch.exe
FirewallRules: [{D8B142D2-80D0-4643-A4AD-787B413400A3}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUpdate\QQPCMgrUpdate.exe
FirewallRules: [{54BF8624-0745-4B02-B1F5-FE291221A78F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSoftGame.exe
FirewallRules: [{E02C6E8A-6075-46A5-B67D-3C32EFD3D299}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSysOptimize.exe
FirewallRules: [{A935C58E-6BE4-4B4C-BCB0-75278D9D8090}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCUpdateAVLib.exe
FirewallRules: [{9217BE09-40A6-4DE1-B4F4-3370D5DB4E98}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQRepair.exe
FirewallRules: [{F6DD2F42-EE9B-429B-8CB6-D0435219DEC6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\Uninst.exe
FirewallRules: [{4A122323-EBDF-4DFB-AC63-21502E8BD507}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCPatch.exe
FirewallRules: [{8A998E63-6A8D-4534-AB59-C373AE283328}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TpkUpdate.exe
FirewallRules: [{9CAFC011-6501-42C2-96D5-FC4470ED38E6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMRouterMgr.exe
FirewallRules: [{48118DFF-3640-416E-B0B9-867B4616A656}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMAccountProtection.exe
FirewallRules: [{110F6641-D936-4E4D-8578-70DCDECEDD15}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMAdBlock.exe

Hosts:
S3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys
R2 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernelEx64.sys
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys
C:\Program Files (x86)\Tencent
C:\Program Files (x86)\Common Files\Tencent
C:\ProgramData\TXQMPC
C:\Users\Jovana\AppData\LocalLow\TENCENT
C:\Program Files (x86)\SearchesToYesbnd
C:\Users\Jovana\AppData\Roaming\cpuminer
C:\Program Files (x86)\WinTaske
C:\Program Files (x86)\Winsere
C:\ProgramData\Tencent
C:\Users\Jovana\AppData\Roaming\Tencent
C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件

EmptyTemp:
End

*****************

"C:\Program Files (x86)\Tencent" => was unlocked
"C:\Program Files (x86)\Common Files\Tencent" => was unlocked
"C:\Program Files (x86)\SearchesToYesbnd" => was unlocked
"C:\Program Files (x86)\Winsere" => was unlocked
"C:\Windows\system32\Drivers\TAOAccelerator64.sys" => was unlocked
"C:\Windows\system32\Drivers\TAOKernelEx64.sys" => was unlocked
"C:\Windows\System32\Drivers\TFsFltX64.sys" => could not be unlocked
Restore point was successfully created.
AV: 电脑管家系统防护 (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5} => removed successfully
AS: 电脑管家系统防护 (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48} => removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\cpuminer => value removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CBD5CF96-61AA-43CB-A3BA-25D5C2344439}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CBD5CF96-61AA-43CB-A3BA-25D5C2344439}" => key removed successfully
C:\Windows\System32\Tasks\WinTaske => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinTaske" => key removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon" => key removed successfully
"HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => key removed successfully
"HKCR\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{50F4150A-48B2-417A-BE4C-C83F580FB904}" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant" => key removed successfully
C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr" => key removed successfully
Could not move "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll" => Scheduled to move on reboot.
Chrome StartupUrls => removed successfully
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default => Error: No automatic fix found for this entry.
ggbugreport => service removed successfully
QQPCRTP => Unable to stop service.
QQPCRTP => service could not remove
QQRepair19e7 => service removed successfully
QQRepairFixSVC => service removed successfully
Winsere => service removed successfully
QMUdisk => Unable to stop service.
QMUdisk => service removed successfully
QQSysMonX64 => Unable to stop service.
QQSysMonX64 => service could not remove
softaal => Unable to stop service.
softaal => service removed successfully
SRepairDrv => Unable to stop service.
SRepairDrv => service removed successfully
TAOAccelerator => service removed successfully
TAOKernelDriver => Unable to stop service.
TAOKernelDriver => service removed successfully
TFsFlt => Unable to stop service.
TFsFlt => service could not remove
TS888x64 => service removed successfully
TSDefenseBt => service could not remove
tsnethlpx64 => Unable to stop service.
tsnethlpx64 => service could not remove
TSSysKit => Unable to stop service.
TSSysKit => service removed successfully

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{74E592A2-4B5D-4F10-B73C-85B3DD4520EB} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FBC1B302-EB2A-4690-A11B-85AAFCF4E66E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF7FBCDC-BEE2-4E67-AF10-77C241F699B8} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2CF58E49-DAB3-4081-B98B-35C3A73E8B0B} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6944578A-6FBB-453B-889C-F658DF699172} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A7296E56-11EF-4EC5-BBB1-48196F249C3E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DAFBAB84-7D01-48F1-AB47-E8336522A262} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BCA7BDF5-85A3-4A26-B835-8A279CD57129} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A6DEBD30-B1B2-4A00-A1BC-3D062D3A9179} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E4F5450F-B116-4533-853F-7CCCD074AE5C} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C415960-3079-4F90-91E0-826E68E0157C} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F76DAA61-3109-403D-9579-A0B6D1FCA0C1} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4BE630BF-D741-4500-86BC-55D55F32FCD1} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E26B07F4-6495-4BBA-814D-347FC74B60EE} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E195FDF8-E009-4569-B8D8-21348013629C} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{874E44DF-5D8B-436A-81E1-DBE9B004733A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D8B142D2-80D0-4643-A4AD-787B413400A3} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{54BF8624-0745-4B02-B1F5-FE291221A78F} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E02C6E8A-6075-46A5-B67D-3C32EFD3D299} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A935C58E-6BE4-4B4C-BCB0-75278D9D8090} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9217BE09-40A6-4DE1-B4F4-3370D5DB4E98} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6DD2F42-EE9B-429B-8CB6-D0435219DEC6} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A122323-EBDF-4DFB-AC63-21502E8BD507} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8A998E63-6A8D-4534-AB59-C373AE283328} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9CAFC011-6501-42C2-96D5-FC4470ED38E6} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{48118DFF-3640-416E-B0B9-867B4616A656} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{110F6641-D936-4E4D-8578-70DCDECEDD15} => value removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
TAOAccelerator => service not found.
TAOKernelDriver => service not found.
TFsFlt => Unable to stop service.
TFsFlt => service could not remove

"C:\Program Files (x86)\Tencent" folder move:

Could not move "C:\Program Files (x86)\Tencent" => Scheduled to move on reboot.

C:\Program Files (x86)\Common Files\Tencent => moved successfully
C:\ProgramData\TXQMPC => moved successfully
C:\Users\Jovana\AppData\LocalLow\TENCENT => moved successfully
C:\Program Files (x86)\SearchesToYesbnd => moved successfully
C:\Users\Jovana\AppData\Roaming\cpuminer => moved successfully
C:\Program Files (x86)\WinTaske => moved successfully
C:\Program Files (x86)\Winsere => moved successfully

"C:\ProgramData\Tencent" folder move:

Could not move "C:\ProgramData\Tencent" => Scheduled to move on reboot.

C:\Users\Jovana\AppData\Roaming\Tencent => moved successfully
C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件 => moved successfully
EmptyTemp: => 1.5 GB temporary data Removed.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-03-23 17:01:02)

"C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll" => Could not move
"C:\Program Files (x86)\Tencent" => Could not move
"C:\ProgramData\Tencent" => Could not move

==== End of Fixlog 17:01:08 ====

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

offline
  • Pridružio: 23 Mar 2016
  • Poruke: 11

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by SYSTEM (2016-03-23 18:34:21) Run:2
Running from d:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
Start
Unlock: C:\Program Files (x86)\Tencent
Unlock: C:\Program Files (x86)\Common Files\Tencent
Unlock: C:\Program Files (x86)\SearchesToYesbnd
Unlock: C:\Program Files (x86)\Winsere
Unlock: C:\Windows\system32\Drivers\TAOAccelerator64.sys
Unlock: C:\Windows\system32\Drivers\TAOKernelEx64.sys
Unlock: C:\Windows\System32\Drivers\TFsFltX64.sys

CreateRestorePoint:
AV: 电脑管家系统防护 (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5}
AS: 电脑管家系统防护 (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48}
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"

CloseProcesses:
HKLM\...\Run: [cpuminer] => C:\Users\Jovana\AppData\Roaming\cpuminer\cpm.exe [1402880 2016-02-29] ()
Task: {CBD5CF96-61AA-43CB-A3BA-25D5C2344439} - System32\Tasks\WinTaske => C:\Program Files (x86)\WinTaske\WinTaske\WinTaske.exe [2016-03-15] ()
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMGCShellExt64.dll [2016-03-23] (Tencent)
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSWebMon64.dat [2016-03-23] (Tencent)
BHO-x32: Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll [2016-03-23] (Tencent Technology (Shenzhen) Company Limited)
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=C88FAF2E2E2E58D2C5E6F1FFABD17F9F&v=20160315&ts=AHEpC3QnAXUmBU.."
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default
S2 ggbugreport; C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe [1592888 2016-03-15] ()
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe [313936 2016-03-23] (Tencent)
U2 QQRepair19e7; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair19e7 [136512 2016-03-23] ()
S2 QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC [136512 2016-03-23] ()
S2 Winsere; C:\Program Files (x86)\Winsere\Winsere\Winsere.exe [306736 2016-03-15] ()
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUdisk64.sys [184536 2016-03-02] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQSysMonX64.sys [152184 2016-03-23] (电脑管家)
R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\softaal64.sys [44664 2016-03-23] (Tencent)
R1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [168568 2016-03-23] ()
S3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [101472 2016-03-15] (Tencent)
R2 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernelEx64.sys [141944 2016-03-23] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [97400 2016-03-23] (电脑管家)
S3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TS888x64.sys [38520 2016-03-23] (Tencent)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSDefenseBT64.sys [28984 2016-03-23] (Tencent)
R2 tsnethlpx64; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TsNetHlpX64.sys [57976 2016-03-23] ()
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSSysKit64.sys [96888 2016-03-23] (电脑管家)

RemoveProxy:
FirewallRules: [{74E592A2-4B5D-4F10-B73C-85B3DD4520EB}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCmgrInstallGuide.exe
FirewallRules: [{FBC1B302-EB2A-4690-A11B-85AAFCF4E66E}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCTray.exe
FirewallRules: [{DF7FBCDC-BEE2-4E67-AF10-77C241F699B8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCMgr.exe
FirewallRules: [{2CF58E49-DAB3-4081-B98B-35C3A73E8B0B}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe
FirewallRules: [{6944578A-6FBB-453B-889C-F658DF699172}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMDL.exe
FirewallRules: [{A7296E56-11EF-4EC5-BBB1-48196F249C3E}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\bugreport.exe
FirewallRules: [{DAFBAB84-7D01-48F1-AB47-E8336522A262}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCFileOpen.exe
FirewallRules: [{BCA7BDF5-85A3-4A26-B835-8A279CD57129}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCLeakScan.exe
FirewallRules: [{A6DEBD30-B1B2-4A00-A1BC-3D062D3A9179}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPConfig.exe
FirewallRules: [{E4F5450F-B116-4533-853F-7CCCD074AE5C}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{8C415960-3079-4F90-91E0-826E68E0157C}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSoftMgr.exe
FirewallRules: [{F76DAA61-3109-403D-9579-A0B6D1FCA0C1}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
FirewallRules: [{4BE630BF-D741-4500-86BC-55D55F32FCD1}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\plugins\QMNetMon\QQPCNetFlow.exe
FirewallRules: [{E26B07F4-6495-4BBA-814D-347FC74B60EE}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCBTU.exe
FirewallRules: [{E195FDF8-E009-4569-B8D8-21348013629C}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCClinic.exe
FirewallRules: [{874E44DF-5D8B-436A-81E1-DBE9B004733A}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCLaunch.exe
FirewallRules: [{D8B142D2-80D0-4643-A4AD-787B413400A3}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUpdate\QQPCMgrUpdate.exe
FirewallRules: [{54BF8624-0745-4B02-B1F5-FE291221A78F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSoftGame.exe
FirewallRules: [{E02C6E8A-6075-46A5-B67D-3C32EFD3D299}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCSysOptimize.exe
FirewallRules: [{A935C58E-6BE4-4B4C-BCB0-75278D9D8090}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCUpdateAVLib.exe
FirewallRules: [{9217BE09-40A6-4DE1-B4F4-3370D5DB4E98}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQRepair.exe
FirewallRules: [{F6DD2F42-EE9B-429B-8CB6-D0435219DEC6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\Uninst.exe
FirewallRules: [{4A122323-EBDF-4DFB-AC63-21502E8BD507}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCPatch.exe
FirewallRules: [{8A998E63-6A8D-4534-AB59-C373AE283328}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TpkUpdate.exe
FirewallRules: [{9CAFC011-6501-42C2-96D5-FC4470ED38E6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMRouterMgr.exe
FirewallRules: [{48118DFF-3640-416E-B0B9-867B4616A656}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMAccountProtection.exe
FirewallRules: [{110F6641-D936-4E4D-8578-70DCDECEDD15}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMAdBlock.exe

Hosts:
S3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys
R2 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernelEx64.sys
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys
C:\Program Files (x86)\Tencent
C:\Program Files (x86)\Common Files\Tencent
C:\ProgramData\TXQMPC
C:\Users\Jovana\AppData\LocalLow\TENCENT
C:\Program Files (x86)\SearchesToYesbnd
C:\Users\Jovana\AppData\Roaming\cpuminer
C:\Program Files (x86)\WinTaske
C:\Program Files (x86)\Winsere
C:\ProgramData\Tencent
C:\Users\Jovana\AppData\Roaming\Tencent
C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件

EmptyTemp:
End

*****************

"C:\Program Files (x86)\Tencent" => was unlocked
"C:\Program Files (x86)\Common Files\Tencent" => not found.
"C:\Program Files (x86)\SearchesToYesbnd" => not found.
"C:\Program Files (x86)\Winsere" => not found.
"C:\Windows\system32\Drivers\TAOAccelerator64.sys" => was unlocked
"C:\Windows\system32\Drivers\TAOKernelEx64.sys" => was unlocked
"C:\Windows\System32\Drivers\TFsFltX64.sys" => was unlocked
Error: Restore point can only be created in normal mode.
AV: 电脑管家系统防护 (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5} => Error: The entry should be fixed outside recovery mode.
AS: 电脑管家系统防护 (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48} => Error: The entry should be fixed outside recovery mode.
HKLM\System\ControlSet001\Control\SafeBoot\Minimal\QQPCRTP => key not found.
HKLM\System\ControlSet001\Control\SafeBoot\Network\QQPCRTP => key not found.
CloseProcesses: => Error: This directive works only outside recovery mode.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\cpuminer => value not found.
Task: {CBD5CF96-61AA-43CB-A3BA-25D5C2344439} - System32\Tasks\WinTaske => C:\Program Files (x86)\WinTaske\WinTaske\WinTaske.exe [2016-03-15] () => Error: The entry should be fixed outside recovery mode.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon => key not found.
HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6} => key not found.
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSWebMon64.dat [2016-03-23] (Tencent) => Error: The entry should be fixed outside recovery mode.
BHO-x32: Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司) => Error: The entry should be fixed outside recovery mode.
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司) => Error: The entry should be fixed outside recovery mode.
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll [2016-03-23] (Tencent Technology (Shenzhen) Company Limited) => Error: The entry should be fixed outside recovery mode.
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=C88FAF2E2E2E58D2C5E6F1FFABD17F9F&v=20160315&ts=AHEpC3QnAXUmBU.." => Error: The entry should be fixed outside recovery mode.
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default => Error: The entry should be fixed outside recovery mode.
ggbugreport => service not found.
QQPCRTP => service removed successfully
QQRepair19e7 => service not found.
QQRepairFixSVC => service removed successfully
Winsere => service not found.
QMUdisk => service not found.
QQSysMonX64 => service removed successfully
softaal => service not found.
SRepairDrv => service removed successfully
TAOAccelerator => service not found.
TAOKernelDriver => service not found.
TFsFlt => service removed successfully
TS888x64 => service not found.
TSDefenseBt => service removed successfully
tsnethlpx64 => service removed successfully
TSSysKit => service removed successfully
RemoveProxy: => Error: The entry should be fixed outside recovery mode.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{74E592A2-4B5D-4F10-B73C-85B3DD4520EB} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FBC1B302-EB2A-4690-A11B-85AAFCF4E66E} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF7FBCDC-BEE2-4E67-AF10-77C241F699B8} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2CF58E49-DAB3-4081-B98B-35C3A73E8B0B} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6944578A-6FBB-453B-889C-F658DF699172} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A7296E56-11EF-4EC5-BBB1-48196F249C3E} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DAFBAB84-7D01-48F1-AB47-E8336522A262} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BCA7BDF5-85A3-4A26-B835-8A279CD57129} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A6DEBD30-B1B2-4A00-A1BC-3D062D3A9179} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E4F5450F-B116-4533-853F-7CCCD074AE5C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C415960-3079-4F90-91E0-826E68E0157C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F76DAA61-3109-403D-9579-A0B6D1FCA0C1} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4BE630BF-D741-4500-86BC-55D55F32FCD1} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E26B07F4-6495-4BBA-814D-347FC74B60EE} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E195FDF8-E009-4569-B8D8-21348013629C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{874E44DF-5D8B-436A-81E1-DBE9B004733A} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D8B142D2-80D0-4643-A4AD-787B413400A3} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{54BF8624-0745-4B02-B1F5-FE291221A78F} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E02C6E8A-6075-46A5-B67D-3C32EFD3D299} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A935C58E-6BE4-4B4C-BCB0-75278D9D8090} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9217BE09-40A6-4DE1-B4F4-3370D5DB4E98} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6DD2F42-EE9B-429B-8CB6-D0435219DEC6} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4A122323-EBDF-4DFB-AC63-21502E8BD507} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8A998E63-6A8D-4534-AB59-C373AE283328} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9CAFC011-6501-42C2-96D5-FC4470ED38E6} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{48118DFF-3640-416E-B0B9-867B4616A656} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{110F6641-D936-4E4D-8578-70DCDECEDD15} => value not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
TAOAccelerator => service not found.
TAOKernelDriver => service not found.
TFsFlt => service not found.
C:\Program Files (x86)\Tencent => moved successfully
"C:\Program Files (x86)\Common Files\Tencent" => not found.
C:\ProgramData\TXQMPC => moved successfully
"C:\Users\Jovana\AppData\LocalLow\TENCENT" => not found.
"C:\Program Files (x86)\SearchesToYesbnd" => not found.
"C:\Users\Jovana\AppData\Roaming\cpuminer" => not found.
"C:\Program Files (x86)\WinTaske" => not found.
"C:\Program Files (x86)\Winsere" => not found.
C:\ProgramData\Tencent => moved successfully
"C:\Users\Jovana\AppData\Roaming\Tencent" => not found.
"C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件" => not found.
EmptyTemp: => Error: This directive works only outside recovery mode.

==== End of Fixlog 18:34:29 ====


mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Svaka ti cast. Ono sto FRST nije mogao da raznese iz normal moda, sada je razneo iz recovery moda.
Ovo sada bi trebalo da izgleda mnogo bolje, no idemo da potucemo jos par ostataka...



Sve ovo radis normalno iz normal moda, sa recovery mode-om smo zavrsili nadam se.


Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt



Arrow Ponovo pokreni FRST i klik na Scan. Iskopiraj svez FRST.txt izvestaj.

offline
  • Pridružio: 23 Mar 2016
  • Poruke: 11

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Jovana (administrator) on DESKTOP-MU7BIH8 (23-03-2016 18:59:08)
Running from C:\Users\Jovana\Desktop
Loaded Profiles: Jovana (Available Profiles: Jovana)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25577864 2016-03-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-755135921-1565032832-2796582722-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [31744 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-23] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
Startup: C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-03-22]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5de0fb33-21b7-4e5b-94a9-f17250dd0225}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6be40341-419b-4fc1-8879-be152113c089}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-23] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-23] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-755135921-1565032832-2796582722-1002 -> hxxp://www.google.com/

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-22] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-02-26] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-23]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=C88FAF2E2E2E58D2C5E6F1FFABD17F9F&v=20160315&ts=AHEpC3QnAXUmBU.."
CHR Profile: C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-22]
CHR Extension: (Facebook) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2016-03-22]
CHR Extension: (Soundtrap - Make Music Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\epaknpicfmoglpinnnjckaobafganajf [2016-03-23]
CHR Extension: (Word Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2016-03-22]
CHR Extension: (Avast Online Security) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-03-23]
CHR Extension: (Excel Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljnkagajgfdmfnnidjijobijlfjfgnb [2016-03-22]
CHR Extension: (PDF Viewer) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\jccchjobcggajhnmckffhcahkkbioifn [2016-03-22]
CHR Extension: (PowerPoint Online) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdafamggmaaaginooondinjgkgcbpnhp [2016-03-22]
CHR Extension: (HUMAN 3.0) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\meefjekipolcgabfgaclcpdkbghhmoah [2016-03-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-22]
CHR Extension: (Gmail) - C:\Users\Jovana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-22]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-23]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-23] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.)
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-10-19] (Popcorn Time) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 QQRepair105b; "C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair105b" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [82664 2015-12-16] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-23] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-23] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-23] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4334240 2015-10-02] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-23 18:57 - 2016-03-23 18:57 - 00005056 _____ C:\Users\Jovana\Desktop\Prikaci fajl.txt
2016-03-23 18:50 - 2016-03-23 18:51 - 01530368 _____ C:\Users\Jovana\Desktop\AdwCleaner.exe
2016-03-23 18:50 - 2016-03-23 18:50 - 01530368 _____ C:\Users\Jovana\Downloads\Unconfirmed 988780.crdownload
2016-03-23 18:37 - 2016-03-23 18:37 - 00000000 ___HD C:\OneDriveTemp
2016-03-23 18:25 - 2016-03-23 16:51 - 00016364 _____ C:\Users\Jovana\Downloads\fixlist.txt
2016-03-23 17:38 - 2016-03-23 17:38 - 00000000 ____D C:\ProgramData\GRETECH
2016-03-23 17:36 - 2016-03-23 17:36 - 00021007 _____ C:\Users\Jovana\Downloads\229484-scorpion.220.hdtvlol_ettv_.zip
2016-03-23 17:32 - 2016-03-23 17:37 - 00000000 ____D C:\Users\Jovana\Downloads\Scorpion.S02E20.HDTV.x264-LOL[ettv]
2016-03-23 17:31 - 2016-03-23 17:31 - 00004291 _____ C:\Users\Jovana\Downloads\[kat.cr]scorpion.s02e20.hdtv.x264.lol.ettv.torrent
2016-03-23 16:55 - 2016-03-23 18:34 - 00017137 _____ C:\Users\Jovana\Desktop\Fixlog.txt
2016-03-23 15:53 - 2016-03-23 15:53 - 00040060 _____ C:\Users\Jovana\Downloads\565028_778326329_Addition.txt
2016-03-23 15:52 - 2016-03-23 18:59 - 00018030 _____ C:\Users\Jovana\Desktop\FRST.txt
2016-03-23 15:52 - 2016-03-23 15:52 - 00040060 _____ C:\Users\Jovana\Desktop\Addition.txt
2016-03-23 15:51 - 2016-03-23 15:51 - 00028794 _____ C:\Users\Jovana\Downloads\Shortcut.txt
2016-03-23 15:50 - 2016-03-23 15:51 - 00040060 _____ C:\Users\Jovana\Downloads\Addition.txt
2016-03-23 15:48 - 2016-03-23 18:59 - 00000000 ____D C:\FRST
2016-03-23 15:48 - 2016-03-23 15:52 - 00157392 _____ C:\Users\Jovana\Downloads\FRST.txt
2016-03-23 15:48 - 2016-03-23 15:48 - 02374144 _____ (Farbar) C:\Users\Jovana\Desktop\FRST64.exe
2016-03-23 15:47 - 2016-03-23 15:47 - 01725440 _____ (Farbar) C:\Users\Jovana\Desktop\FRST.exe
2016-03-23 15:32 - 2016-03-23 18:55 - 00000000 ____D C:\AdwCleaner
2016-03-23 13:22 - 2016-03-23 13:22 - 00000000 ____D C:\QMDownload
2016-03-23 13:14 - 2016-03-23 13:14 - 00001250 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-03-23 13:11 - 2016-03-23 13:09 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-23 13:10 - 2016-03-23 13:10 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-23 13:10 - 2016-03-23 13:10 - 00001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-23 13:10 - 2016-03-23 13:10 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\AVAST Software
2016-03-23 13:09 - 2016-03-23 13:12 - 00004006 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-03-23 13:09 - 2016-03-23 13:12 - 00003040 _____ C:\Windows\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-23 13:09 - 2016-03-23 13:09 - 01070904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00463744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00287016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00165344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-23 13:09 - 2016-03-23 13:09 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-23 13:09 - 2016-03-23 13:09 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-23 13:08 - 2016-03-23 13:08 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-23 13:07 - 2016-03-23 13:07 - 05207096 _____ (AVAST Software) C:\Users\Jovana\Downloads\avast_free_antivirus_setup_online.exe
2016-03-23 13:07 - 2016-03-23 13:07 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 12:43 - 2016-03-23 12:43 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Synaptics
2016-03-23 12:37 - 2016-03-23 12:37 - 00005120 _____ C:\Users\Jovana\AppData\Roaming\GiftBag.db
2016-03-23 12:36 - 2016-03-23 12:36 - 00141944 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernelEx64.sys
2016-03-23 12:34 - 2016-03-23 12:38 - 00000702 __RSH C:\ProgramData\ntuser.pol
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\Users\Public\Thunder Network
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\gplyra
2016-03-23 12:34 - 2016-03-23 12:34 - 00000000 ____D C:\ProgramData\Thunder Network
2016-03-23 12:33 - 2016-03-23 12:39 - 00000000 ____D C:\Users\Jovana\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-03-23 12:33 - 2016-03-23 12:33 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-03-23 12:28 - 2016-03-23 12:28 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\WinRAR
2016-03-23 02:32 - 2016-03-23 02:32 - 00000000 ____D C:\Windows\system32\SleepStudy
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\ATI
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Local\ATI
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\Users\Jovana\AppData\Local\AMD
2016-03-23 01:33 - 2016-03-23 01:33 - 00000000 ____D C:\ProgramData\ATI
2016-03-23 00:39 - 2016-03-23 00:39 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-03-23 00:39 - 2016-03-23 00:39 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-03-23 00:37 - 2016-03-23 00:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-23 00:32 - 2016-03-23 01:44 - 00005250 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-MU7BIH8-Jovana DESKTOP-MU7BIH8
2016-03-23 00:21 - 2016-03-23 18:30 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\qBittorrent
2016-03-23 00:21 - 2016-03-23 00:21 - 00000000 ____D C:\Users\Jovana\AppData\Local\qBittorrent
2016-03-23 00:20 - 2016-03-23 00:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2016-03-23 00:20 - 2016-03-23 00:20 - 00000000 ____D C:\Program Files (x86)\qBittorrent
2016-03-23 00:16 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\LocalLow\Adobe
2016-03-23 00:16 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Local\CEF
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\Program Files\ATI Technologies
2016-03-22 23:54 - 2016-03-22 23:54 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2016-03-22 23:53 - 2016-03-22 23:53 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
2016-03-22 23:52 - 2016-03-22 23:54 - 00000000 ____D C:\ProgramData\AMD
2016-03-22 23:51 - 2016-03-23 18:55 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2016-03-22 23:51 - 2016-03-23 00:32 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-22 23:51 - 2016-03-22 23:51 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-03-22 23:51 - 2016-03-22 23:51 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-03-22 23:51 - 2015-12-16 20:07 - 00082664 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmpfd.sys
2016-03-22 23:50 - 2016-03-22 23:53 - 00000000 ____D C:\AMD
2016-03-22 23:49 - 2016-03-22 23:50 - 00000000 ____D C:\Program Files\AMD
2016-03-22 23:49 - 2016-03-22 23:49 - 00000000 ____D C:\Windows\SysWOW64\sda
2016-03-22 23:48 - 2016-03-22 23:48 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-03-22 23:48 - 2016-03-22 23:48 - 00000000 ____D C:\Program Files\Common Files\Atheros
2016-03-22 23:13 - 2016-03-22 23:13 - 00000000 ____D C:\Users\Jovana\Documents\OneNote Notebooks
2016-03-22 22:59 - 2016-03-22 22:59 - 00003972 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-03-22 22:59 - 2016-03-22 22:59 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-22 22:59 - 2016-03-22 22:59 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-03-22 22:58 - 2016-03-22 23:58 - 00000000 ____D C:\ProgramData\Adobe
2016-03-22 22:56 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Local\Adobe
2016-03-22 22:52 - 2016-03-22 22:52 - 00000000 ____D C:\Users\Jovana\AppData\Local\Microsoft Toolkit
2016-03-22 22:36 - 2016-03-23 00:54 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-03-22 22:36 - 2016-03-22 22:36 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Windows\PCHEALTH
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2016-03-22 22:35 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2016-03-22 22:32 - 2016-03-22 22:32 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2016-03-22 22:32 - 2016-03-22 22:32 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-03-22 22:31 - 2016-03-22 22:35 - 00000000 ____D C:\Program Files\Microsoft Office
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 __RHD C:\MSOCache
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 ____D C:\Users\Jovana\AppData\Local\Microsoft Help
2016-03-22 22:31 - 2016-03-22 22:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-03-22 22:29 - 2016-03-23 14:54 - 00000000 ____D C:\Program Files\WinRAR
2016-03-22 22:02 - 2016-03-22 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2016-03-22 21:53 - 2016-03-22 21:53 - 00000000 ____D C:\Users\Jovana\AppData\Local\Conexant
2016-03-22 21:46 - 2016-03-22 21:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\PopcornTimeDesktop
2016-03-22 21:44 - 2016-03-22 22:02 - 00000000 ____D C:\Program Files (x86)\Popcorn Time
2016-03-22 18:45 - 2016-03-23 17:01 - 00000000 ____D C:\Users\Jovana\AppData\LocalLow\Temp
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\GRETECH
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
2016-03-22 18:30 - 2016-03-22 18:30 - 00000000 ____D C:\Program Files (x86)\GRETECH
2016-03-22 18:12 - 2016-03-22 18:12 - 00000000 ___RD C:\Users\Jovana\3D Objects
2016-03-22 18:02 - 2016-03-23 18:57 - 00000000 ___RD C:\Users\Jovana\Dropbox
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Users\Jovana\AppData\Local\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\ProgramData\Apple Computer
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\iTunes
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\iPod
2016-03-22 17:47 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-03-22 17:46 - 2016-03-22 17:47 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\Apple
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files\Bonjour
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-03-22 17:46 - 2016-03-22 17:46 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-03-22 17:45 - 2016-03-22 17:46 - 00000000 ____D C:\ProgramData\Apple
2016-03-22 14:40 - 2016-03-22 14:40 - 00000000 ____D C:\Users\Jovana\AppData\Local\PeerDistRepub
2016-03-22 14:40 - 2016-03-22 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-22 14:39 - 2016-03-22 14:39 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Dropbox
2016-03-22 14:38 - 2016-03-23 18:56 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-03-22 14:38 - 2016-03-23 18:43 - 00000940 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-03-22 14:38 - 2016-03-22 14:38 - 00004000 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2016-03-22 14:38 - 2016-03-22 14:38 - 00003768 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2016-03-22 14:28 - 2016-03-23 18:57 - 00000000 ____D C:\Users\Jovana\AppData\Local\Dropbox
2016-03-22 14:28 - 2016-03-22 14:40 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-03-22 14:28 - 2016-03-22 14:28 - 00000000 ____D C:\ProgramData\Dropbox
2016-03-22 13:37 - 2016-03-22 13:37 - 00000000 ____D C:\Users\Jovana\AppData\Local\ElevatedDiagnostics
2016-03-22 12:58 - 2016-03-22 12:58 - 00000000 ____D C:\Users\Jovana\Tracing
2016-03-22 12:36 - 2016-03-23 18:57 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ____D C:\ProgramData\Skype
2016-03-22 12:36 - 2016-03-22 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-22 11:26 - 2016-03-22 11:43 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome апликације
2016-03-22 11:21 - 2016-03-23 18:56 - 00000960 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-22 11:21 - 2016-03-23 18:26 - 00000964 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-22 11:21 - 2016-03-22 13:40 - 00000000 ____D C:\Users\Jovana\AppData\Local\Google
2016-03-22 11:21 - 2016-03-22 11:22 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-22 11:21 - 2016-03-22 11:21 - 00004022 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-22 11:21 - 2016-03-22 11:21 - 00003790 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-22 00:11 - 2016-03-22 00:11 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Macromedia
2016-03-21 23:47 - 2016-03-22 00:54 - 00000000 ____D C:\Users\Jovana\AppData\Local\Comms
2016-03-21 21:46 - 2016-03-21 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2016-03-21 21:44 - 2016-03-21 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2016-03-21 21:44 - 2016-03-21 21:44 - 00000000 ____D C:\Program Files\Dolby Digital Plus
2016-03-21 21:44 - 2014-12-09 20:11 - 00423128 _____ (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
2016-03-21 21:44 - 2014-10-20 14:54 - 00207576 _____ (Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
2016-03-21 21:44 - 2013-12-24 15:35 - 00001724 _____ C:\Windows\system32\Drivers\SamSfPa.dat
2016-03-21 21:43 - 2016-03-22 21:53 - 00000000 ____D C:\ProgramData\Conexant
2016-03-21 21:43 - 2016-03-21 21:44 - 00000000 ____D C:\Program Files\CONEXANT
2016-03-21 21:43 - 2016-03-21 21:43 - 00001047 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2016-03-21 21:43 - 2016-03-21 21:43 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-03-21 21:43 - 2015-10-29 19:43 - 07043584 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons081a.dll
2016-03-21 21:43 - 2015-10-29 19:41 - 07043584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsLexicons081a.dll
2016-03-21 21:43 - 2015-10-29 19:38 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\NlsData081a.dll
2016-03-21 21:43 - 2015-10-29 19:36 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData081a.dll
2016-03-21 21:43 - 2015-10-29 19:29 - 01909760 _____ (Microsoft Corporation) C:\Windows\system32\MLS2.dll
2016-03-21 21:43 - 2015-10-29 19:27 - 01870848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MLS2.dll
2016-03-21 21:29 - 2016-03-23 18:56 - 00000000 ___RD C:\Users\Jovana\OneDrive
2016-03-21 21:29 - 2016-03-21 21:42 - 00002366 _____ C:\Users\Jovana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-21 21:29 - 2016-03-21 21:29 - 00000000 ____D C:\Users\Jovana\AppData\Local\MicrosoftEdge
2016-03-21 21:28 - 2016-03-21 21:28 - 00000000 ____D C:\Users\Jovana\AppData\Local\ActiveSync
2016-03-21 21:27 - 2016-03-21 21:27 - 00000000 ____D C:\Users\Jovana\AppData\Local\Publishers
2016-03-21 21:26 - 2016-03-23 12:38 - 00000000 ____D C:\Users\Jovana\AppData\Local\VirtualStore
2016-03-21 21:26 - 2016-03-23 11:46 - 00000000 ____D C:\Users\Jovana\AppData\Local\Packages
2016-03-21 21:26 - 2016-03-23 01:26 - 00000000 ____D C:\Users\Jovana
2016-03-21 21:26 - 2016-03-23 00:16 - 00000000 ____D C:\Users\Jovana\AppData\Roaming\Adobe
2016-03-21 21:26 - 2016-03-21 21:26 - 00000020 ___SH C:\Users\Jovana\ntuser.ini
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\My Documents
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Videos
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Pictures
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 _SHDL C:\Users\Jovana\Documents\My Music
2016-03-21 21:26 - 2016-03-21 21:26 - 00000000 ____D C:\Users\Jovana\AppData\Local\TileDataLayer
2016-03-21 21:24 - 2016-03-22 21:59 - 00000000 ____D C:\Program Files\KMSpico
2016-03-21 21:24 - 2016-03-21 21:24 - 00004608 _____ C:\Windows\SECOH-QAD.exe
2016-03-21 21:24 - 2016-03-21 21:24 - 00003584 _____ C:\Windows\SECOH-QAD.dll
2016-03-09 10:26 - 2016-03-09 10:26 - 00000000 ____D C:\Windows\CSC
2016-03-09 10:22 - 2016-03-09 10:22 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files\MSBuild
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-03-09 09:50 - 2016-03-09 09:50 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-03-09 09:49 - 2015-10-24 02:47 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:47 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:47 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2016-03-09 09:49 - 2015-10-24 02:46 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2016-03-09 09:49 - 2015-10-24 02:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2016-03-09 09:49 - 2015-10-24 02:45 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-09 09:43 - 2015-12-09 04:39 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-03-09 09:41 - 2016-03-09 09:42 - 00000000 ____D C:\Windows\system32\MRT
2016-03-09 09:41 - 2016-03-09 09:41 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-03-09 09:41 - 2016-02-24 10:51 - 07474528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-03-09 09:41 - 2016-02-24 10:48 - 00713568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-03-09 09:41 - 2016-02-24 10:47 - 01173344 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-03-09 09:41 - 2016-02-24 10:40 - 00513888 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-03-09 09:41 - 2016-02-24 10:28 - 03449168 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2016-03-09 09:41 - 2016-02-24 09:46 - 06607080 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2016-03-09 09:41 - 2016-02-24 09:11 - 01997152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-03-09 09:41 - 2016-02-24 09:06 - 05242496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-03-09 09:41 - 2016-02-24 07:11 - 03593216 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-03-09 09:41 - 2016-02-24 07:00 - 02273792 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-03-09 09:41 - 2016-02-24 06:20 - 22376960 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-03-09 09:41 - 2016-02-24 06:18 - 18677760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-03-09 09:41 - 2016-02-24 06:12 - 19339776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-03-09 09:41 - 2016-02-24 06:12 - 05321728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 09:41 - 2016-02-24 06:10 - 24600576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-03-09 09:41 - 2016-02-24 06:09 - 06972416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-03-09 09:41 - 2016-02-24 06:05 - 12586496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-03-09 09:41 - 2016-02-24 06:03 - 14252544 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-03-09 09:41 - 2016-02-24 05:59 - 05661696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-03-09 09:41 - 2016-02-24 05:55 - 07835648 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-03-09 09:41 - 2016-02-23 12:25 - 01818696 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-03-09 09:41 - 2016-02-23 11:34 - 01542816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-03-09 09:41 - 2016-02-23 11:32 - 08705672 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-03-09 09:41 - 2016-02-23 11:32 - 00369912 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-03-09 09:41 - 2016-02-23 11:31 - 00536256 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-03-09 09:41 - 2016-02-23 11:31 - 00408120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-03-09 09:41 - 2016-02-23 11:21 - 22564328 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-03-09 09:41 - 2016-02-23 10:38 - 06952088 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-09 09:41 - 2016-02-23 10:30 - 02919320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-03-09 09:41 - 2016-02-23 10:27 - 21124344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-03-09 09:41 - 2016-02-23 09:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\wininetlui.dll
2016-03-09 09:41 - 2016-02-23 09:58 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-03-09 09:41 - 2016-02-23 09:28 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2016-03-09 09:41 - 2016-02-23 09:09 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-03-09 09:41 - 2016-02-23 09:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininetlui.dll
2016-03-09 09:41 - 2016-02-23 09:06 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-03-09 09:41 - 2016-02-23 09:02 - 01318912 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2016-03-09 09:41 - 2016-02-23 09:00 - 02624512 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2016-03-09 09:41 - 2016-02-23 08:58 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2016-03-09 09:41 - 2016-02-23 08:52 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2016-03-09 09:41 - 2016-02-23 08:30 - 01731584 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-03-09 09:41 - 2016-02-23 08:24 - 02755584 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-03-09 09:41 - 2016-02-23 08:22 - 01944576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-03-09 09:41 - 2016-02-23 08:21 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-03-09 09:41 - 2016-02-23 08:17 - 02635264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-03-09 09:41 - 2016-02-23 07:59 - 01500672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-03-09 09:41 - 2016-02-23 07:55 - 04894208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-03-09 09:41 - 2016-02-23 07:55 - 02229760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-03-09 09:41 - 2016-02-23 07:52 - 11545600 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-03-09 09:41 - 2016-02-23 07:50 - 09919488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-03-09 09:41 - 2016-02-23 07:39 - 13382656 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-03-09 09:41 - 2016-02-23 07:36 - 12125696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-03-09 09:41 - 2016-02-23 07:36 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-03-09 09:41 - 2016-02-23 07:35 - 07533568 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-03-09 09:41 - 2016-02-23 07:28 - 06740992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2016-03-09 09:41 - 2016-02-09 04:24 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2016-03-09 09:41 - 2016-02-09 04:07 - 01626624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2016-03-09 09:41 - 2016-02-09 04:04 - 01946624 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2016-03-09 09:40 - 2016-03-01 06:31 - 00848168 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-03-09 09:40 - 2016-03-01 06:22 - 00709688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-03-09 09:40 - 2016-02-24 10:52 - 01997328 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-03-09 09:40 - 2016-02-24 10:34 - 01613664 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-03-09 09:40 - 2016-02-24 10:15 - 01557768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-03-09 09:40 - 2016-02-24 09:58 - 00794888 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-03-09 09:40 - 2016-02-24 09:54 - 00127840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-03-09 09:40 - 2016-02-24 09:51 - 01322248 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-03-09 09:40 - 2016-02-24 09:50 - 00808800 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-03-09 09:40 - 2016-02-24 09:43 - 00625000 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2016-03-09 09:40 - 2016-02-24 09:39 - 00358752 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-03-09 09:40 - 2016-02-24 09:39 - 00141560 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2016-03-09 09:40 - 2016-02-24 09:19 - 00670928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-03-09 09:40 - 2016-02-24 09:14 - 00216416 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00957608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00703840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-03-09 09:40 - 2016-02-24 09:11 - 00652392 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2016-03-09 09:40 - 2016-02-24 09:11 - 00394080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-03-09 09:40 - 2016-02-24 09:11 - 00258280 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2016-03-09 09:40 - 2016-02-24 09:10 - 00630632 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2016-03-09 09:40 - 2016-02-24 09:10 - 00576864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-03-09 09:40 - 2016-02-24 09:09 - 00640472 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2016-03-09 09:40 - 2016-02-24 09:09 - 00147808 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2016-03-09 09:40 - 2016-02-24 08:59 - 00294752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-03-09 09:40 - 2016-02-24 08:39 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTypeHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 08:39 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\ExtrasXmlParser.dll
2016-03-09 09:40 - 2016-02-24 08:38 - 00187744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2016-03-09 09:40 - 2016-02-24 08:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2016-03-09 09:40 - 2016-02-24 08:37 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataLanguageUtil.dll
2016-03-09 09:40 - 2016-02-24 08:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenanceClient.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00540752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2016-03-09 09:40 - 2016-02-24 08:35 - 00523752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00220064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sqmapi.dll
2016-03-09 09:40 - 2016-02-24 08:35 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-03-09 09:40 - 2016-02-24 08:33 - 00538736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2016-03-09 09:40 - 2016-02-24 08:33 - 00141664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2016-03-09 09:40 - 2016-02-24 08:31 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-03-09 09:40 - 2016-02-24 08:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2016-03-09 09:40 - 2016-02-24 08:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\POSyncServices.dll
2016-03-09 09:40 - 2016-02-24 08:23 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
2016-03-09 09:40 - 2016-02-24 08:23 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-03-09 09:40 - 2016-02-24 08:23 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\UserDataPlatformHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 08:22 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00195072 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll
2016-03-09 09:40 - 2016-02-24 08:20 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2016-03-09 09:40 - 2016-02-24 08:19 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2016-03-09 09:40 - 2016-02-24 08:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2016-03-09 09:40 - 2016-02-24 08:15 - 00365568 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-03-09 09:40 - 2016-02-24 08:14 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll
2016-03-09 09:40 - 2016-02-24 08:13 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
2016-03-09 09:40 - 2016-02-24 08:12 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\cemapi.dll
2016-03-09 09:40 - 2016-02-24 08:12 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\PhoneCallHistoryApis.dll
2016-03-09 09:40 - 2016-02-24 08:10 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
2016-03-09 09:40 - 2016-02-24 08:09 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll
2016-03-09 09:40 - 2016-02-24 08:09 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll
2016-03-09 09:40 - 2016-02-24 08:07 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll
2016-03-09 09:40 - 2016-02-24 08:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2016-03-09 09:40 - 2016-02-24 08:03 - 00088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2016-03-09 09:40 - 2016-02-24 08:02 - 00161280 _____ (Microsoft Corporation) C:\Windows\system32\CallHistoryClient.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2016-03-09 09:40 - 2016-02-24 08:01 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\profext.dll
2016-03-09 09:40 - 2016-02-24 08:00 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2016-03-09 09:40 - 2016-02-24 07:59 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2016-03-09 09:40 - 2016-02-24 07:58 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\scapi.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00790528 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll
2016-03-09 09:40 - 2016-02-24 07:55 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExtrasXmlParser.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
2016-03-09 09:40 - 2016-02-24 07:54 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2016-03-09 09:40 - 2016-02-24 07:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 07:53 - 00089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2016-03-09 09:40 - 2016-02-24 07:53 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 09:40 - 2016-02-24 07:52 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2016-03-09 09:40 - 2016-02-24 07:52 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 09:40 - 2016-02-24 07:51 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-03-09 09:40 - 2016-02-24 07:49 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
2016-03-09 09:40 - 2016-02-24 07:47 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-03-09 09:40 - 2016-02-24 07:46 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 01713664 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00915456 _____ (Microsoft Corporation) C:\Windows\system32\configurationclient.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
2016-03-09 09:40 - 2016-02-24 07:44 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\POSyncServices.dll
2016-03-09 09:40 - 2016-02-24 07:43 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2016-03-09 09:40 - 2016-02-24 07:43 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2016-03-09 09:40 - 2016-02-24 07:42 - 00954368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2016-03-09 09:40 - 2016-02-24 07:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2016-03-09 09:40 - 2016-02-24 07:41 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2016-03-09 09:40 - 2016-02-24 07:41 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 01224704 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-03-09 09:40 - 2016-02-24 07:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 09:40 - 2016-02-24 07:39 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-03-09 09:40 - 2016-02-24 07:39 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2016-03-09 09:40 - 2016-02-24 07:38 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2016-03-09 09:40 - 2016-02-24 07:36 - 01847808 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2016-03-09 09:40 - 2016-02-24 07:34 - 00938496 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2016-03-09 09:40 - 2016-02-24 07:34 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-03-09 09:40 - 2016-02-24 07:32 - 00223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
2016-03-09 09:40 - 2016-02-24 07:32 - 00098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
2016-03-09 09:40 - 2016-02-24 07:31 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cemapi.dll
2016-03-09 09:40 - 2016-02-24 07:31 - 00169984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2016-03-09 09:40 - 2016-02-24 07:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll
2016-03-09 09:40 - 2016-02-24 07:25 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2016-03-09 09:40 - 2016-02-24 07:23 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CallHistoryClient.dll
2016-03-09 09:40 - 2016-02-24 07:22 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\profext.dll
2016-03-09 09:40 - 2016-02-24 07:21 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 09:40 - 2016-02-24 07:21 - 00168448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2016-03-09 09:40 - 2016-02-24 07:18 - 00184832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll
2016-03-09 09:40 - 2016-02-24 07:17 - 00369664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2016-03-09 09:40 - 2016-02-24 07:16 - 00394752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2016-03-09 09:40 - 2016-02-24 07:13 - 00540160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 01443328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRHInproc.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll
2016-03-09 09:40 - 2016-02-24 07:09 - 00228352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00949248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00890368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll
2016-03-09 09:40 - 2016-02-24 07:07 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-03-09 09:40 - 2016-02-24 07:04 - 01497088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2016-03-09 09:40 - 2016-02-24 07:03 - 00769536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2016-03-09 09:40 - 2016-02-24 07:01 - 01831936 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2016-03-09 09:40 - 2016-02-24 07:00 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2016-03-09 09:40 - 2016-02-24 06:57 - 02158592 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-03-09 09:40 - 2016-02-24 06:55 - 01996288 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-03-09 09:40 - 2016-02-24 06:43 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
2016-03-09 09:40 - 2016-02-24 06:34 - 01707520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2016-03-09 09:40 - 2016-02-24 06:22 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll
2016-03-09 09:40 - 2016-02-23 12:29 - 01030416 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-03-09 09:40 - 2016-02-23 12:29 - 00874968 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2016-03-09 09:40 - 2016-02-23 12:27 - 02654872 _____ C:\Windows\system32\CoreUIComponents.dll
2016-03-09 09:40 - 2016-02-23 12:27 - 01317640 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-03-09 09:40 - 2016-02-23 12:27 - 01141504 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-03-09 09:40 - 2016-02-23 12:25 - 02152288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-03-09 09:40 - 2016-02-23 12:25 - 00563552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2016-03-09 09:40 - 2016-02-23 12:15 - 00779384 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2016-03-09 09:40 - 2016-02-23 12:08 - 00989536 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2016-03-09 09:40 - 2016-02-23 11:34 - 01859960 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2016-03-09 09:40 - 2016-02-23 11:33 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-03-09 09:40 - 2016-02-23 11:33 - 00389992 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 02544264 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 01152328 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:32 - 00498448 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 01017032 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 00819648 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2016-03-09 09:40 - 2016-02-23 11:31 - 00476728 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2016-03-09 09:40 - 2016-02-23 11:25 - 03671888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-03-09 09:40 - 2016-02-23 11:22 - 00572272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2016-03-09 09:40 - 2016-02-23 11:17 - 00146272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-03-09 09:40 - 2016-02-23 10:45 - 02773096 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2016-03-09 09:40 - 2016-02-23 10:40 - 00430944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-03-09 09:40 - 2016-02-23 10:39 - 00502112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 02180136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00980352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00895080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00882720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00450912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2016-03-09 09:40 - 2016-02-23 10:38 - 00420928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2016-03-09 09:40 - 2016-02-23 10:37 - 00713824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2016-03-09 09:40 - 2016-02-23 10:32 - 00791744 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-03-09 09:40 - 2016-02-23 10:27 - 00376536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
2016-03-09 09:40 - 2016-02-23 10:25 - 00534368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2016-03-09 09:40 - 2016-02-23 10:20 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\XblGameSave.dll
2016-03-09 09:40 - 2016-02-23 10:20 - 00238592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
2016-03-09 09:40 - 2016-02-23 10:19 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xinputhid.sys
2016-03-09 09:40 - 2016-02-23 10:17 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2016-03-09 09:40 - 2016-02-23 10:12 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\provpackageapidll.dll
2016-03-09 09:40 - 2016-02-23 10:10 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\WiFiConfigSP.dll
2016-03-09 09:40 - 2016-02-23 10:07 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2016-03-09 09:40 - 2016-02-23 10:07 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2016-03-09 09:40 - 2016-02-23 10:06 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\flvprophandler.dll
2016-03-09 09:40 - 2016-02-23 10:01 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rasl2tp.sys
2016-03-09 09:40 - 2016-02-23 10:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-09 09:40 - 2016-02-23 10:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll
2016-03-09 09:40 - 2016-02-23 09:58 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\irmon.dll
2016-03-09 09:40 - 2016-02-23 09:57 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2016-03-09 09:40 - 2016-02-23 09:56 - 02186864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2016-03-09 09:40 - 2016-02-23 09:55 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2016-03-09 09:40 - 2016-02-23 09:53 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
2016-03-09 09:40 - 2016-02-23 09:53 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\ngckeyenum.dll
2016-03-09 09:40 - 2016-02-23 09:52 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe
2016-03-09 09:40 - 2016-02-23 09:51 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
2016-03-09 09:40 - 2016-02-23 09:50 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2016-03-09 09:40 - 2016-02-23 09:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\AppCapture.dll
2016-03-09 09:40 - 2016-02-23 09:48 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerClient.dll
2016-03-09 09:40 - 2016-02-23 09:40 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SMSRouter.dll
2016-03-09 09:40 - 2016-02-23 09:39 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2016-03-09 09:40 - 2016-02-23 09:38 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll
2016-03-09 09:40 - 2016-02-23 09:38 - 00287712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2016-03-09 09:40 - 2016-02-23 09:37 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-03-09 09:40 - 2016-02-23 09:36 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\QuickActionsDataModel.dll
2016-03-09 09:40 - 2016-02-23 09:34 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\wifiprofilessettinghandler.dll
2016-03-09 09:40 - 2016-02-23 09:34 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2016-03-09 09:40 - 2016-02-23 09:33 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2016-03-09 09:40 - 2016-02-23 09:32 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2016-03-09 09:40 - 2016-02-23 09:31 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2016-03-09 09:40 - 2016-02-23 09:29 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SmsRouterSvc.dll
2016-03-09 09:40 - 2016-02-23 09:27 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll
2016-03-09 09:40 - 2016-02-23 09:26 - 00372224 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2016-03-09 09:40 - 2016-02-23 09:23 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2016-03-09 09:40 - 2016-02-23 09:22 - 00567808 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00847360 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00606720 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00493568 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 09:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-09 09:40 - 2016-02-23 09:19 - 00948736 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
2016-03-09 09:40 - 2016-02-23 09:19 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2016-03-09 09:40 - 2016-02-23 09:18 - 00557056 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2016-03-09 09:40 - 2016-02-23 09:14 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2016-03-09 09:40 - 2016-02-23 09:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2016-03-09 09:40 - 2016-02-23 09:12 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2016-03-09 09:40 - 2016-02-23 09:11 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2016-03-09 09:40 - 2016-02-23 09:10 - 00997376 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2016-03-09 09:40 - 2016-02-23 09:10 - 00474624 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2016-03-09 09:40 - 2016-02-23 09:09 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2016-03-09 09:40 - 2016-02-23 09:09 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-03-09 09:40 - 2016-02-23 09:06 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-03-09 09:40 - 2016-02-23 09:05 - 00161280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2016-03-09 09:40 - 2016-02-23 09:04 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2016-03-09 09:40 - 2016-02-23 09:04 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2016-03-09 09:40 - 2016-02-23 09:04 - 00382464 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-03-09 09:40 - 2016-02-23 09:02 - 00755712 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2016-03-09 09:40 - 2016-02-23 09:02 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-03-09 09:40 - 2016-02-23 08:58 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll
2016-03-09 09:40 - 2016-02-23 08:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerServer.dll
2016-03-09 09:40 - 2016-02-23 08:58 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll
2016-03-09 09:40 - 2016-02-23 08:57 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TimeBrokerClient.dll
2016-03-09 09:40 - 2016-02-23 08:50 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll
2016-03-09 09:40 - 2016-02-23 08:49 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2016-03-09 09:40 - 2016-02-23 08:48 - 00838144 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2016-03-09 09:40 - 2016-02-23 08:47 - 00157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WiFiDisplay.dll
2016-03-09 09:40 - 2016-02-23 08:38 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2016-03-09 09:40 - 2016-02-23 08:37 - 01118208 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-03-09 09:40 - 2016-02-23 08:37 - 00613376 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00713728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00379392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2016-03-09 09:40 - 2016-02-23 08:36 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-09 09:40 - 2016-02-23 08:35 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2016-03-09 09:40 - 2016-02-23 08:31 - 00585216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2016-03-09 09:40 - 2016-02-23 08:30 - 00646656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-09 09:40 - 2016-02-23 08:29 - 00349696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2016-03-09 09:40 - 2016-02-23 08:28 - 00555520 _____ (Microsoft Corporation) C:\Windows\system32\SyncController.dll
2016-03-09 09:40 - 2016-02-23 08:28 - 00256512 _____ (Microsoft Corporation) C:\Windows\system32\accountaccessor.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 04827136 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 01105920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2016-03-09 09:40 - 2016-02-23 08:24 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2016-03-09 09:40 - 2016-02-23 08:21 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-09 09:40 - 2016-02-23 08:20 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll
2016-03-09 09:40 - 2016-02-23 08:14 - 00990720 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2016-03-09 09:40 - 2016-02-23 08:11 - 01390080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2016-03-09 09:40 - 2016-02-23 08:05 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2016-03-09 09:40 - 2016-02-23 08:01 - 02295808 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2016-03-09 09:40 - 2016-02-23 07:58 - 00450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncController.dll
2016-03-09 09:40 - 2016-02-23 07:56 - 04412928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-03-09 09:40 - 2016-02-23 07:53 - 01799168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2016-03-09 09:40 - 2016-02-23 07:51 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2016-03-09 09:40 - 2016-02-23 07:42 - 03425792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-03-09 09:40 - 2016-02-23 07:41 - 02912256 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2016-03-09 09:40 - 2016-02-23 07:39 - 02581504 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-03-09 09:40 - 2016-02-23 07:33 - 02604032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2016-03-09 09:40 - 2016-02-23 07:32 - 02793472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-03-09 09:40 - 2016-02-23 07:30 - 02061312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-03-09 09:40 - 2016-02-09 05:28 - 00277856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2016-03-09 09:40 - 2016-02-09 05:13 - 00185184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2016-03-09 09:40 - 2016-02-09 04:18 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2016-03-09 09:40 - 2016-02-09 04:18 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2016-03-09 09:40 - 2016-02-09 04:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2016-03-09 09:31 - 2016-03-23 18:46 - 00879220 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\My Documents
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-03-09 09:23 - 2016-03-09 09:23 - 00000000 _SHDL C:\Documents and Settings
2016-03-09 09:18 - 2016-03-09 10:24 - 00000000 ____D C:\Windows\Panther

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-23 18:56 - 2016-02-13 14:16 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-23 18:55 - 2015-10-30 07:28 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-03-23 18:46 - 2015-10-30 08:21 - 00000000 ____D C:\Windows\INF
2016-03-23 18:37 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\AppReadiness
2016-03-23 12:40 - 2016-02-13 14:12 - 00342232 _____ C:\Windows\system32\FNTCACHE.DAT
2016-03-23 12:34 - 2015-10-30 08:24 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-03-23 12:34 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2016-03-23 11:46 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-23 00:53 - 2015-10-30 08:11 - 00000000 ____D C:\Windows\CbsTemp
2016-03-23 00:52 - 2015-10-30 08:24 - 00000167 _____ C:\Windows\win.ini
2016-03-23 00:52 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System
2016-03-23 00:51 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-22 22:36 - 2016-02-13 14:04 - 00000000 ____D C:\Windows\ShellNew
2016-03-22 22:35 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-03-22 21:20 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\NDF
2016-03-22 11:14 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\appcompat
2016-03-22 00:56 - 2016-02-13 14:22 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-21 21:43 - 2016-02-13 13:55 - 00000000 ____D C:\Windows\OCR
2016-03-21 21:26 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2016-03-21 21:23 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\rescache
2016-03-09 10:20 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\Sysprep
2016-03-09 09:45 - 2016-02-13 14:04 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 __RSD C:\Windows\Media
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ___RD C:\Windows\PurchaseDialog
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\bcastdvr
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 09:45 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-09 09:45 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-03-09 09:45 - 2015-10-30 07:28 - 00000000 ____D C:\Windows\system32\Dism
2016-03-08 08:12 - 2015-10-30 08:26 - 00829944 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:12 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2016-03-23 12:37 - 2016-03-23 12:37 - 0005120 _____ () C:\Users\Jovana\AppData\Roaming\GiftBag.db
2016-03-21 21:43 - 2016-03-21 21:43 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Jovana\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-09 09:18

==================== End of FRST.txt ============================

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Preskocili smo dva drajvera ... Idemo jos jedan fix, iz normal moda pa da vidimo kako ce ovo proci. Nadam se da ce ovo moci biti uklonjeno iz normal moda ...



______________________________
1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

Reboot:
S2 QQRepair105b; "C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair105b" [X]
C:\Windows\system32\Drivers\TAOAccelerator64.sys
C:\Windows\system32\Drivers\TAOKernelEx64.sys


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.
______________________________




Postavi mi izvestaje pa nastavljamo sutra cim stignem. Mozda ti odgovorim i veceras posle ~ 10h

Ko je trenutno na forumu
 

Ukupno su 876 korisnika na forumu :: 4 registrovanih, 3 sakrivenih i 869 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: pacika, TBF1D, Tila Painen, vathra